URL Short tool by Shorterm – Simple, Fast & Private Security & Risk Analysis

wordpress.org/plugins/shorterm

Lightweight WordPress URL Shortener. Create custom slugs, cloak affiliate links & track clicks without slowing down your site.

0 active installs v1.1.1 PHP 7.4+ WP 5.0+ Updated Feb 3, 2026
affiliate-linkscustom-slugredirectshort-urlurl-shortener
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is URL Short tool by Shorterm – Simple, Fast & Private Safe to Use in 2026?

Generally Safe

Score 100/100

URL Short tool by Shorterm – Simple, Fast & Private has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'shorterm' v1.1.1 plugin exhibits a generally strong security posture, adhering to many best practices. It boasts a complete absence of known CVEs and impressively achieves 100% output escaping and a high percentage of prepared statements for its SQL queries. Furthermore, all identified entry points (AJAX handlers) are protected with nonce and capability checks, indicating a proactive approach to preventing unauthorized access and actions. The lack of file operations and external HTTP requests further reduces potential attack vectors.

However, the static analysis reveals a critical concern: three taint flows were identified with unsanitized paths, all flagged as high severity. While there are no explicit dangerous functions or raw SQL queries without prepared statements, these unsanitized paths represent a significant risk. This could lead to vulnerabilities such as path traversal or arbitrary file reads/writes if an attacker can manipulate the input leading to these flows. The absence of vulnerability history is positive, but it doesn't negate the immediate risks presented by the identified taint flows.

In conclusion, 'shorterm' v1.1.1 has a solid foundation with robust input sanitization for most operations and secure handling of its entry points. Nevertheless, the three high-severity taint flows with unsanitized paths are a critical weakness that requires immediate attention. Addressing these specific flow vulnerabilities is paramount to mitigating potential security risks, despite the otherwise positive security indicators and lack of historical vulnerabilities.

Key Concerns

  • High severity unsanitized taint flows (3)
Vulnerabilities
None known

URL Short tool by Shorterm – Simple, Fast & Private Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

URL Short tool by Shorterm – Simple, Fast & Private Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
8 prepared
Unescaped Output
0
16 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

89% prepared9 total queries

Output Escaping

100% escaped16 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
shorterm_delete_link (shorterm.php:278)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

URL Short tool by Shorterm – Simple, Fast & Private Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_shorterm_create_linkshorterm.php:263
authwp_ajax_shorterm_refresh_tableshorterm.php:273
authwp_ajax_shorterm_delete_linkshorterm.php:304
WordPress Hooks 4
actionplugins_loadedshorterm.php:68
actioninitshorterm.php:195
actionadmin_menushorterm.php:312
actionadmin_enqueue_scriptsshorterm.php:405
Maintenance & Trust

URL Short tool by Shorterm – Simple, Fast & Private Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version7.4
Downloads320

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

URL Short tool by Shorterm – Simple, Fast & Private Developer Profile

dimitrisevis

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect URL Short tool by Shorterm – Simple, Fast & Private

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
shorterm-bulk-checkboxshort-url-cellshort-url-linkoriginal-url-celloriginal-url-textaction-cell
Data Attributes
data-id
FAQ

Frequently Asked Questions about URL Short tool by Shorterm – Simple, Fast & Private