
Shorten2PingNG Security & Risk Analysis
wordpress.org/plugins/shorten2ping-ngSends status updates to Ping.fm or Twitter everytime you publish a post, using own domain or others for shortened permalinks.
Is Shorten2PingNG Safe to Use in 2026?
Generally Safe
Score 85/100Shorten2PingNG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of shorten2ping-ng v1.3.1 reveals a plugin with a very small attack surface, exhibiting no direct entry points via AJAX, REST API, shortcodes, or cron events. Furthermore, it demonstrates good practices by exclusively using prepared statements for its SQL queries and not involving file operations or bundled libraries. However, a significant concern arises from the complete absence of output escaping for all identified output points. This means any data processed by the plugin and then displayed to the user or injected into the page could be vulnerable to cross-site scripting (XSS) attacks. The plugin also makes external HTTP requests, which could be a vector for other vulnerabilities if not handled securely. The vulnerability history is clean, with no recorded CVEs, suggesting a potentially well-maintained codebase or simply a lack of past exploitation. Despite the lack of historical vulnerabilities and a minimal attack surface, the critical oversight in output escaping presents a tangible security risk that cannot be ignored. The absence of nonce and capability checks, while not immediately exploitable due to the lack of entry points, would become a significant weakness if any were introduced in future versions without proper security considerations.
Key Concerns
- 100% of outputs not properly escaped
- No nonce checks
- No capability checks
Shorten2PingNG Security Vulnerabilities
Shorten2PingNG Code Analysis
Output Escaping
Shorten2PingNG Attack Surface
WordPress Hooks 8
Maintenance & Trust
Shorten2PingNG Maintenance & Trust
Maintenance Signals
Community Trust
Shorten2PingNG Alternatives
Shorten2Ping
shorten2ping
Sends status updates to Ping.fm everytime you publish a post, using your own domain, bit.ly, wp.me, su.pr, is.gd and others for shortened permalinks.
Ping.fm Status Widget
pingfm-status
Ping.fm (http://ping.fm) is a simple service that makes updating your social networks a snap. You can use AIM, GTalk, iGoogle, Windows Live Messenger …
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
woo-product-feed-pro
Most popular WooCommerce product feed plugin supporting Google shopping feed, meta/facebook feed, bing product feed & more.
Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels
webappick-product-feed-for-woocommerce
Create WooCommerce product feeds for Google Shopping, Facebook, TikTok & 220+ channels. 2026 compliant. 6 formats. Trusted by 70,000+ stores.
Shorten2PingNG Developer Profile
8 plugins · 150 total installs
How We Detect Shorten2PingNG
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shorten2ping-ng/css/shorten2ping.css/wp-content/plugins/shorten2ping-ng/js/shorten2ping.js/wp-content/plugins/shorten2ping-ng/js/shorten2ping.jsshorten2ping-ng/css/shorten2ping.css?ver=shorten2ping-ng/js/shorten2ping.js?ver=HTML / DOM Fingerprints
<!-- Shorturl added by shorten2ping --><!-- Img for Facebook thumbnail added by Shorten2Ping -->rel="shorturl"<a href="$short_permalink" rel="shorturl" title="$post_title">