
URL Shortener by ShortUrlsEZ. Security & Risk Analysis
wordpress.org/plugins/shorturlsWhat is ShortUrlsEZ?
Is URL Shortener by ShortUrlsEZ. Safe to Use in 2026?
Generally Safe
Score 85/100URL Shortener by ShortUrlsEZ. has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shorturls" plugin v1.0.0 presents a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs), and the plugin avoids direct SQL queries by exclusively using prepared statements. It also has a seemingly small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication.
However, significant concerns arise from the static analysis. The most critical issue is that 100% of the 5 identified output operations are not properly escaped, representing a major risk for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals 3 flows with unsanitized paths. While no critical or high severity issues were flagged by the taint analysis, the presence of unsanitized paths, especially in conjunction with unescaped output, strongly suggests potential for XSS or other injection attacks. The complete absence of nonce and capability checks across all components also means that even if an entry point were to exist in the future, it would likely be unprotected.
Given the lack of historical vulnerabilities, the plugin might appear safe, but the current static analysis findings indicate a fragile security foundation. The absence of basic security checks like output escaping and sanitization for paths is a serious oversight. Therefore, while the plugin currently has no known external exploits, its internal code quality and susceptibility to common attack vectors are high.
Key Concerns
- Unescaped output (0% escaped)
- Unsanitized paths in taint analysis (3 flows)
- Missing nonce checks
- Missing capability checks
URL Shortener by ShortUrlsEZ. Security Vulnerabilities
URL Shortener by ShortUrlsEZ. Code Analysis
Output Escaping
Data Flow Analysis
URL Shortener by ShortUrlsEZ. Attack Surface
WordPress Hooks 2
Maintenance & Trust
URL Shortener by ShortUrlsEZ. Maintenance & Trust
Maintenance Signals
Community Trust
URL Shortener by ShortUrlsEZ. Alternatives
URL Shortener by Shortez.
shortez-url-shortener
What is Shortez?
Short Links for M8C — لینک کوتاه
short-links-for-m8c
Create short links from WordPress using the M8C link shortener service (m8c.ir). Not affiliated with M8C; for use with the M8C API.
BetterLinks – URL Shortener, Link Tracking, Analytics & Affiliate Link Manager
betterlinks
Ultimate plugin to create, shorten, track and manage any URL. Gather analytics reports and run successful marketing campaigns easily.
URL Shortify – Simple and Easy URL Shortener
url-shortify
URL Shortify helps you beautify, manage, share & cloak any links on or off your WordPress website. Create links using your domain name!
Bitly URL Shortener
codehaveli-bitly-url-shortener
Bitly URL Shortener uses the functionality of Bitly API to generate Bitly short link without leaving your WordPress site.
URL Shortener by ShortUrlsEZ. Developer Profile
1 plugin · 0 total installs
How We Detect URL Shortener by ShortUrlsEZ.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shorturls/megaurl.phpHTML / DOM Fingerprints
hashedtoken