
URL Shortener by Shortez. Security & Risk Analysis
wordpress.org/plugins/shortez-url-shortenerWhat is Shortez?
Is URL Shortener by Shortez. Safe to Use in 2026?
Generally Safe
Score 85/100URL Shortener by Shortez. has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortez-url-shortener" v1.0.0 plugin presents a mixed security posture. On the positive side, it demonstrates excellent practice regarding SQL query security by exclusively using prepared statements and has no recorded historical vulnerabilities. It also has a minimal attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without authentication. This indicates a deliberate effort to limit potential entry points.
However, a significant concern arises from the static analysis revealing that 100% of its 5 output operations are not properly escaped. This is a critical weakness, as it opens the door to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while not reporting critical or high severity flows, did identify 3 flows with unsanitized paths, which, when combined with the unescaped output, can lead to dangerous outcomes if user-supplied data reaches these flows.
Given the lack of historical vulnerabilities, it's possible these issues have not been exploited. Nevertheless, the complete absence of output escaping for all identified outputs is a severe flaw that dramatically increases the risk of XSS attacks. The plugin's strengths lie in its controlled attack surface and SQL hygiene, but its weakness in output sanitization is a major security concern that requires immediate attention.
Key Concerns
- All output is unescaped (XSS risk)
- Taint flows with unsanitized paths detected
- No nonce checks implemented
- No capability checks implemented
URL Shortener by Shortez. Security Vulnerabilities
URL Shortener by Shortez. Code Analysis
Output Escaping
Data Flow Analysis
URL Shortener by Shortez. Attack Surface
WordPress Hooks 2
Maintenance & Trust
URL Shortener by Shortez. Maintenance & Trust
Maintenance Signals
Community Trust
URL Shortener by Shortez. Alternatives
URL Shortener by ShortUrlsEZ.
shorturls
What is ShortUrlsEZ?
Short Links for M8C — لینک کوتاه
short-links-for-m8c
Create short links from WordPress using the M8C link shortener service (m8c.ir). Not affiliated with M8C; for use with the M8C API.
BetterLinks – URL Shortener, Link Tracking, Analytics & Affiliate Link Manager
betterlinks
Ultimate plugin to create, shorten, track and manage any URL. Gather analytics reports and run successful marketing campaigns easily.
URL Shortify – Simple and Easy URL Shortener
url-shortify
URL Shortify helps you beautify, manage, share & cloak any links on or off your WordPress website. Create links using your domain name!
Bitly URL Shortener
codehaveli-bitly-url-shortener
Bitly URL Shortener uses the functionality of Bitly API to generate Bitly short link without leaving your WordPress site.
URL Shortener by Shortez. Developer Profile
1 plugin · 0 total installs
How We Detect URL Shortener by Shortez.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortez-url-shortener/shortez-url-shortener.phpHTML / DOM Fingerprints
hashedtokendata