url Shortener 4eq Security & Risk Analysis

wordpress.org/plugins/url-shortener-4eq

url Shortener 4eq is a quick, modern, and open-source link shortener. This plugin allows you to use 4eq service in WordPress.

0 active installs v0.1 PHP 5.2.4+ WP 3.0.1+ Updated Unknown
link-shortenersocial-mediaurl-shortener
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is url Shortener 4eq Safe to Use in 2026?

Generally Safe

Score 100/100

url Shortener 4eq has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "url-shortener-4eq" plugin v0.1 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs, critical taint flows, and dangerous functions is a strong positive indicator. The use of prepared statements for all SQL queries and the presence of a nonce check are commendable security practices. However, there are areas for improvement. The plugin has a limited attack surface, with only one shortcode identified, and importantly, no unprotected entry points. The main concern lies in the output escaping, where only 50% of outputs are properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. The lack of capability checks for the shortcode is also a point of concern, as it implies that any logged-in user could potentially interact with the shortcode's functionality. The absence of vulnerability history suggests a lack of past issues, but this could also be due to the plugin's limited adoption or development history, rather than a proven track record of security.

Key Concerns

  • Only 50% of outputs properly escaped
  • Shortcode without capability checks
Vulnerabilities
None known

url Shortener 4eq Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

url Shortener 4eq Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
joomir_addform_us4eq (urlshortener.php:45)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

url Shortener 4eq Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[us4eq] urlshortener.php:126
WordPress Hooks 1
actionadmin_menuurlshortener.php:31
Maintenance & Trust

url Shortener 4eq Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedUnknown
PHP min version5.2.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

url Shortener 4eq Developer Profile

saeedmoh031

3 plugins · 40 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect url Shortener 4eq

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/url-shortener-4eq/css1.css

HTML / DOM Fingerprints

CSS Classes
part-leadfish_us4eqformgroup_us4eqwaterform_us4eqid="fish_us4eq"id="fish_us4eq2"id="waterform_us4eq"id="name-form_us4eq"+4 more
Data Attributes
name="name_us4eq"name="nonce_us4eq"name="email_us4eq"value="'
Shortcode Output
<div class="part-lead"><div id="form_us4eq"><div class="fish_us4eq" id="fish_us4eq"></div><div class="fish_us4eq" id="fish_us4eq2"></div>
FAQ

Frequently Asked Questions about url Shortener 4eq