
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing Security & Risk Analysis
wordpress.org/plugins/shortlinksproShorten, track, manage and share any URL using your own domain name!
Is ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing Safe to Use in 2026?
Generally Safe
Score 99/100ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing has a strong security track record. Known vulnerabilities have been patched promptly.
The "shortlinkspro" v1.2.0 plugin exhibits a generally good security posture with several positive indicators. A high percentage of outputs are properly escaped, and a significant portion of SQL queries utilize prepared statements. The plugin also demonstrates a strong adherence to security best practices with numerous nonce and capability checks in place, and it lacks dangerous functions and direct file operations. The attack surface, while present with AJAX handlers, is protected by authentication, and there are no exposed REST API routes or shortcodes.
However, the taint analysis reveals a notable concern: 5 out of 8 analyzed flows have unsanitized paths, with 4 of them being of high severity. This indicates a potential for vulnerabilities if user-supplied data is not handled correctly before being used in sensitive operations. Although there is only one past CVE recorded, which is now patched, the history of an SQL Injection vulnerability is a reminder of the potential risks associated with database interactions.
In conclusion, while "shortlinkspro" v1.2.0 demonstrates considerable effort in implementing security controls, the presence of high-severity unsanitized taint flows warrants careful attention and investigation. The plugin's strengths lie in its robust use of escaping, prepared statements, and authentication checks. The weakness lies in potential mishandling of unsanitized data in critical paths, suggesting a need for more rigorous input validation.
Key Concerns
- High severity unsanitized taint flows
- Unsanitized paths in taint flows
- Bundled outdated library: Select2 v1.0.2
- History of SQL Injection vulnerability
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ShortLinks Pro <= 1.0.7 - Authenticated (Administrator+) SQL Injection
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing Attack Surface
AJAX Handlers 5
WordPress Hooks 90
Scheduled Events 1
Maintenance & Trust
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing Maintenance & Trust
Maintenance Signals
Community Trust
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing Alternatives
LinkFiliate – Advanced Affiliate Link Management, Branded Short Links, Click Tracking & Analytics
linkfiliate
Create pretty branded URLs, cloak affiliate links, and track clicks in real time — giving you better control of all your marketing links in WordPress.
LinkCentral – URL shortener, Custom Links & Affiliate Link Shortener with Link Tracking
linkcentral
The easiest URL shortener, short links manager, and link tracking plugin. Fast and optimised for better short links, redirects and affiliate links.
LinkAlert
codirun-linkalert
Link management and click tracking plugin for WordPress. Monitor clicks in real time, manage short links, and receive instant notifications.
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
thirstyaffiliates
🔗 Affiliate link management & cloaker tool. Easily manage, shrink and track your affiliate links in WordPress. 🔥
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing Developer Profile
30 plugins · 25K total installs
How We Detect ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortlinkspro/assets/css/admin.css/wp-content/plugins/shortlinkspro/assets/css/shortlinkspro.css/wp-content/plugins/shortlinkspro/assets/js/admin.js/wp-content/plugins/shortlinkspro/assets/js/shortlinkspro.js/wp-content/plugins/shortlinkspro/assets/js/vendors/moment.min.js/wp-content/plugins/shortlinkspro/assets/js/vendors/moment-timezone-with-data.min.js/wp-content/plugins/shortlinkspro/assets/js/admin.js/wp-content/plugins/shortlinkspro/assets/js/shortlinkspro.js/wp-content/plugins/shortlinkspro/assets/js/vendors/moment.min.js/wp-content/plugins/shortlinkspro/assets/js/vendors/moment-timezone-with-data.min.jsshortlinkspro/assets/css/admin.css?ver=shortlinkspro/assets/css/shortlinkspro.css?ver=shortlinkspro/assets/js/admin.js?ver=shortlinkspro/assets/js/shortlinkspro.js?ver=shortlinkspro/assets/js/vendors/moment.min.js?ver=shortlinkspro/assets/js/vendors/moment-timezone-with-data.min.js?ver=HTML / DOM Fingerprints
shortlinkspro-wrappershortlinkspro-listshortlinkspro-tableshortlinkspro-actionsdata-shortlinkspro-idshortlinkspro_params/wp-json/shortlinkspro/v1/links[shortlinkspro_list][shortlinkspro_analytics]