ShortLink Analytics by SVS-Websoft Security & Risk Analysis

wordpress.org/plugins/svs-shortlink-analytics

ShortLink Analytics WordPress plugin generate short link and track visitors

10 active installs v1.0.1 PHP + WP 3.8+ Updated Sep 14, 2015
affiliatelinklinksurlurls
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ShortLink Analytics by SVS-Websoft Safe to Use in 2026?

Generally Safe

Score 85/100

ShortLink Analytics by SVS-Websoft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'svs-shortlink-analytics' plugin exhibits a generally positive security posture concerning its attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, indicating a stable and potentially well-maintained codebase in the past.

However, the static analysis reveals several critical areas of concern. The plugin's handling of SQL queries is a major weakness, with all six queries lacking prepared statements. This exposes the plugin to significant SQL injection risks. Additionally, the complete absence of output escaping for all 37 identified outputs is alarming, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while limited, did identify one flow with unsanitized paths, reinforcing the XSS concerns. The lack of nonce and capability checks on any potential entry points (though none are explicitly identified as unprotected) further compounds these risks, as even if an entry point were to be introduced in future versions, it would likely be unprotected.

In conclusion, while the plugin's limited attack surface and clean vulnerability history are strengths, the pervasive lack of secure coding practices in SQL query handling and output escaping presents substantial security risks. These vulnerabilities are severe and require immediate attention. The plugin's overall security is compromised by these fundamental oversights.

Key Concerns

  • All SQL queries use raw SQL, no prepared statements
  • No output escaping for any output
  • Taint flow with unsanitized path
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

ShortLink Analytics by SVS-Websoft Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ShortLink Analytics by SVS-Websoft Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
0 prepared
Unescaped Output
37
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared6 total queries

Output Escaping

0% escaped37 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<statistics> (views\statistics.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ShortLink Analytics by SVS-Websoft Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuShortlinkAnalyticsMain.php:67
Maintenance & Trust

ShortLink Analytics by SVS-Websoft Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.0
Last updatedSep 14, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

ShortLink Analytics by SVS-Websoft Developer Profile

SVS WebSoft

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ShortLink Analytics by SVS-Websoft

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/svs-shortlink-analytics/css/admin.css/wp-content/plugins/svs-shortlink-analytics/css/default.css/wp-content/plugins/svs-shortlink-analytics/js/admin.js
Script Paths
/wp-content/plugins/svs-shortlink-analytics/js/admin.js
Version Parameters
svs-shortlink-analytics/css/admin.css?ver=svs-shortlink-analytics/css/default.css?ver=svs-shortlink-analytics/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ShortLink Analytics by SVS-Websoft