Shortlinks Security & Risk Analysis

wordpress.org/plugins/shortlinks

Shortlinks allows you to easily retrieve the shortlink for your WordPress posts, pages, categories, post_tags, attachments, custom post types, and cus …

20 active installs v0.1 PHP + WP 3+ Updated Apr 15, 2010
categorypagepagespostposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shortlinks Safe to Use in 2026?

Generally Safe

Score 85/100

Shortlinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the 'shortlinks' plugin v0.1 exhibits a strong initial security posture. The absence of any identified dangerous functions, SQL queries without prepared statements, or unescaped output is highly encouraging. Furthermore, the plugin has no recorded vulnerabilities, including critical or high severity ones, and no known CVEs. This suggests a development process that prioritizes secure coding practices.

However, a significant concern arises from the complete lack of security checks in all identified entry points. With zero AJAX handlers, REST API routes, shortcodes, or cron events, and zero nonces or capability checks, any existing or future functionality within these areas would be entirely unprotected. While the current attack surface is stated as zero, the absence of these fundamental security measures indicates a potential for severe vulnerabilities should the plugin evolve to include user-facing features or data processing. The taint analysis showing zero flows is positive but may also be a reflection of a limited attack surface or insufficient analysis depth.

In conclusion, while the current state of 'shortlinks' v0.1 appears secure due to the lack of exploitable code and a clean vulnerability history, the absence of basic security checks like nonces and capability checks on *any* potential entry points presents a substantial latent risk. Future development must incorporate these essential security mechanisms to prevent potential exploits.

Key Concerns

  • Missing nonce checks on any entry points
  • Missing capability checks on any entry points
Vulnerabilities
None known

Shortlinks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shortlinks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Shortlinks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterget_shortlinkshortlinks.php:12
filterget_shortlinkshortlinks.php:13
filterpost_row_actionsshortlinks.php:14
filtermedia_row_actionsshortlinks.php:15
filterpage_row_actionsshortlinks.php:16
filtertag_row_actionsshortlinks.php:17
Maintenance & Trust

Shortlinks Maintenance & Trust

Maintenance Signals

WordPress version tested3
Last updatedApr 15, 2010
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Shortlinks Developer Profile

aizatto

7 plugins · 1K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shortlinks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
Get Shortlink
FAQ

Frequently Asked Questions about Shortlinks