
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts Security & Risk Analysis
wordpress.org/plugins/tinypressCreate custom links for your posts. These links are brandable, trackable, and can have custom view permissions.
Is PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts Safe to Use in 2026?
Generally Safe
Score 100/100PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tinypress" v1.3.0 plugin exhibits a generally good security posture with strong adherence to prepared statements for SQL queries and a high percentage of properly escaped output. The plugin also makes good use of nonce and capability checks for most of its entry points. The lack of known vulnerabilities in its history further contributes to a positive security impression.
However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This directly exposes a potential entry point for malicious actors. Additionally, the taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, represent a latent risk of path traversal or arbitrary file access vulnerabilities that could be exploited under certain conditions.
Overall, while the plugin demonstrates a commitment to secure coding practices, the identified unprotected AJAX handler and unsanitized path flows are areas that require immediate attention. The vulnerability history suggests a mature and likely well-maintained codebase, but these specific findings introduce exploitable surface. Addressing these points would significantly bolster the plugin's security.
Key Concerns
- AJAX handler without auth checks
- Flows with unsanitized paths (taint analysis)
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts Security Vulnerabilities
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts Attack Surface
AJAX Handlers 9
WordPress Hooks 73
Maintenance & Trust
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts Maintenance & Trust
Maintenance Signals
Community Trust
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts Alternatives
WP 301 Redirects by WPBranch
redirects-for-wp
WP 301 Redirects is easy to use, and provides an easy method for redirecting requests to another page on your site or elsewhere on the web.
Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More
simple-301-redirects
Simple 301 Redirects provides an easy method of redirecting requests to another page on your site or elsewhere on the web.
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
thirstyaffiliates
🔗 Affiliate link management & cloaker tool. Easily manage, shrink and track your affiliate links in WordPress. 🔥
BetterLinks – URL Shortener, Link Tracking, Analytics & Affiliate Link Manager
betterlinks
Ultimate plugin to create, shorten, track and manage any URL. Gather analytics reports and run successful marketing campaigns easily.
Linker – URL shortener & track outbound link clicks
linker
Track Outbound Link Clicks Easily: Shorten & track your site links by using your own domain name. e.g. "your-domain.com/go/link"
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts Developer Profile
11 plugins · 272K total installs
How We Detect PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tinypress/assets/admin/js/apexcharts.js/wp-content/plugins/tinypress/assets/admin/js/qrcode.min.js/wp-content/plugins/tinypress/assets/admin/js/scripts.js/wp-content/plugins/tinypress/assets/admin/css/style.css/wp-content/plugins/tinypress/assets/hint.min.css/assets/admin/js/apexcharts.js/assets/admin/js/qrcode.min.js/assets/admin/js/scripts.jstinypress/assets/admin/js/scripts.js?ver=tinypress/assets/admin/css/style.css?ver=HTML / DOM Fingerprints
tinypress-autolist-toggledata-tinypress-autolist-settingstinypress