
Custom Shortlink Domain Security & Risk Analysis
wordpress.org/plugins/shortlink-domainCustomise the domain name used to generate shortlink URLs.
Is Custom Shortlink Domain Safe to Use in 2026?
Generally Safe
Score 85/100Custom Shortlink Domain has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortlink-domain" plugin v0.1.3 demonstrates a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, and crucially, there are no entry points found without proper authentication checks. The code also shows a commitment to security by exclusively using prepared statements for its SQL queries. However, the analysis does reveal a critical weakness: 100% of its output is not properly escaped. This means that any data displayed by the plugin could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if that data originates from user input or other untrusted sources.
The vulnerability history is clean, with no known CVEs recorded for this plugin. This is a positive indicator, suggesting that the plugin's developers have a good track record or that the plugin is not a frequent target. However, the lack of any recorded vulnerabilities should not be interpreted as an absolute guarantee of future safety, especially given the identified output escaping issue. The clean history, coupled with the missing output escaping, suggests that while the plugin might not have been historically exploited for its vulnerabilities, the potential for XSS remains a significant concern.
In conclusion, "shortlink-domain" v0.1.3 exhibits a small attack surface and responsible SQL handling, which are commendable. Nevertheless, the complete lack of output escaping represents a serious security deficiency that could expose the WordPress site to XSS vulnerabilities. While the plugin has no known vulnerabilities, this specific coding practice warrants immediate attention and remediation.
Key Concerns
- Output is not properly escaped
Custom Shortlink Domain Security Vulnerabilities
Custom Shortlink Domain Code Analysis
Output Escaping
Custom Shortlink Domain Attack Surface
WordPress Hooks 2
Maintenance & Trust
Custom Shortlink Domain Maintenance & Trust
Maintenance Signals
Community Trust
Custom Shortlink Domain Alternatives
Bitly's WordPress Plugin
wp-bitly
Create short links to your content with Bitly’s WordPress Plugin.
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts
tinypress
Create custom links for your posts. These links are brandable, trackable, and can have custom view permissions.
Link Shortner
link-shortener
Link Shortner allows you to easily create clean, branded short permalink links for your posts custom URL.
YOURLS Link Creator
yourls-link-creator
Creates a custom short URL when saving posts. Requires your own YOURLS install.
Better YOURLS
better-yourls
Integrate your blog with YOURLS custom URL generator.
Custom Shortlink Domain Developer Profile
4 plugins · 3K total installs
How We Detect Custom Shortlink Domain
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
regular-textcodename="shortlink_domain"id="shortlink_domain"