
ShortLink Analytics by SVS-Websoft Security & Risk Analysis
wordpress.org/plugins/svs-shortlink-analyticsShortLink Analytics WordPress plugin generate short link and track visitors
Is ShortLink Analytics by SVS-Websoft Safe to Use in 2026?
Generally Safe
Score 85/100ShortLink Analytics by SVS-Websoft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'svs-shortlink-analytics' plugin exhibits a generally positive security posture concerning its attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, indicating a stable and potentially well-maintained codebase in the past.
However, the static analysis reveals several critical areas of concern. The plugin's handling of SQL queries is a major weakness, with all six queries lacking prepared statements. This exposes the plugin to significant SQL injection risks. Additionally, the complete absence of output escaping for all 37 identified outputs is alarming, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while limited, did identify one flow with unsanitized paths, reinforcing the XSS concerns. The lack of nonce and capability checks on any potential entry points (though none are explicitly identified as unprotected) further compounds these risks, as even if an entry point were to be introduced in future versions, it would likely be unprotected.
In conclusion, while the plugin's limited attack surface and clean vulnerability history are strengths, the pervasive lack of secure coding practices in SQL query handling and output escaping presents substantial security risks. These vulnerabilities are severe and require immediate attention. The plugin's overall security is compromised by these fundamental oversights.
Key Concerns
- All SQL queries use raw SQL, no prepared statements
- No output escaping for any output
- Taint flow with unsanitized path
- No nonce checks found
- No capability checks found
ShortLink Analytics by SVS-Websoft Security Vulnerabilities
ShortLink Analytics by SVS-Websoft Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ShortLink Analytics by SVS-Websoft Attack Surface
WordPress Hooks 1
Maintenance & Trust
ShortLink Analytics by SVS-Websoft Maintenance & Trust
Maintenance Signals
Community Trust
ShortLink Analytics by SVS-Websoft Alternatives
AmazoLinkenator
amazolinkenator
Automatically adds your Amazon Affiliate code to any Amazon product URLs on posts, pages, & comments. Optionally shortens URLs.
Export All URLs
export-all-urls
This plugin enables you to extract information such as Title, URL, Categories, Tags, Author, as well as Published and Modified dates for built-in post …
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links
update-urls
Quick and Easy way to search all URLS, Content and replace them with new links and content in WordPress website.
URL Shortify – Simple and Easy URL Shortener
url-shortify
URL Shortify helps you beautify, manage, share & cloak any links on or off your WordPress website. Create links using your domain name!
Export Media URLs
export-media-urls
An efficient media information extraction utility with CSV export option, suitable for several use-cases including migration and SEO.
ShortLink Analytics by SVS-Websoft Developer Profile
2 plugins · 20 total installs
How We Detect ShortLink Analytics by SVS-Websoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/svs-shortlink-analytics/css/admin.css/wp-content/plugins/svs-shortlink-analytics/css/default.css/wp-content/plugins/svs-shortlink-analytics/js/admin.js/wp-content/plugins/svs-shortlink-analytics/js/admin.jssvs-shortlink-analytics/css/admin.css?ver=svs-shortlink-analytics/css/default.css?ver=svs-shortlink-analytics/js/admin.js?ver=