
Shortlink & File URL Column Security & Risk Analysis
wordpress.org/plugins/shortlink-columnAdds a shortlink column in post/page, taxonomy and media manage screens. Also retrieves inner post shortlink button as for WP earlier than 4.4.
Is Shortlink & File URL Column Safe to Use in 2026?
Generally Safe
Score 85/100Shortlink & File URL Column has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortlink-column" plugin version 1.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a complete lack of critical or high-severity vulnerabilities in its history are positive indicators. The code analysis reveals a minimal attack surface with no apparent entry points like AJAX handlers, REST API routes, or shortcodes. Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and performing no file operations or external HTTP requests, which inherently reduces attack vectors.
However, a significant concern arises from the output escaping, where only 19% of the 32 total outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities, as unsanitized user-supplied data could be rendered directly in the browser. The absence of nonce checks and capability checks on its (currently zero) entry points, while less concerning due to the zero attack surface, could become a risk if new entry points are added without proper security measures. The lack of taint analysis data is noted, but given the other findings, the primary focus should be on the output escaping.
In conclusion, while the plugin benefits from a clean vulnerability history and a limited attack surface, the poor output escaping is a notable weakness that requires attention. Addressing this would significantly improve the plugin's overall security. The absence of explicit authentication checks on its existing entry points (though currently zero) is a minor concern that should be monitored if the plugin evolves.
Key Concerns
- Poor output escaping (19% proper)
Shortlink & File URL Column Security Vulnerabilities
Shortlink & File URL Column Code Analysis
Output Escaping
Shortlink & File URL Column Attack Surface
WordPress Hooks 10
Maintenance & Trust
Shortlink & File URL Column Maintenance & Trust
Maintenance Signals
Community Trust
Shortlink & File URL Column Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Admin Columns
codepress-admin-columns
Customise columns on the administration screens for post(types), pages, media, comments, links and users with an easy to use drag-and-drop interface.
Make Column Clickable for Elementor
make-column-clickable-elementor
Make entire columns, sections and containers clickable in Elementor — improve navigation and user experience with just one link.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Shortlink & File URL Column Developer Profile
3 plugins · 220 total installs
How We Detect Shortlink & File URL Column
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
slc79_btnslc79_ponclickslc79_copyToClipboard