unfake.it URL shortener for Twitter Tools Security & Risk Analysis

wordpress.org/plugins/url-shortener-for-twitter-tools

unfake.it URL shortener Plugin for Twitter Tools works as a WordPress plugin and (hopefully) gets an URL as inbound parameter, shortens it by using un …

10 active installs v1.4 PHP + WP 2.3+ Updated Aug 21, 2010
digestnotifyposttweettwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is unfake.it URL shortener for Twitter Tools Safe to Use in 2026?

Generally Safe

Score 85/100

unfake.it URL shortener for Twitter Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "url-shortener-for-twitter-tools" plugin v1.4 presents a mixed security posture. While it has no recorded vulnerabilities and a seemingly small attack surface based on the static analysis of entry points, significant concerns arise from the code analysis. The lack of any capability checks or nonce checks is a major red flag, as is the fact that 100% of output is unescaped. The taint analysis reveals two high-severity flows with unsanitized paths, indicating potential for injection attacks if these flows are reachable and exploited. The SQL query analysis also shows that 60% of queries are not using prepared statements, increasing the risk of SQL injection. Despite the absence of historical CVEs, the current code's weaknesses suggest a medium to high risk, particularly for sites handling sensitive data or those exposed to external user input that could interact with these unsanitized paths.

Key Concerns

  • Capability checks missing
  • Nonce checks missing
  • High severity taint flows
  • Unescaped output
  • Raw SQL queries
Vulnerabilities
None known

unfake.it URL shortener for Twitter Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

unfake.it URL shortener for Twitter Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
6 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

40% prepared15 total queries

Output Escaping

0% escaped4 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
uf_menu (tt_unfake_it.php:79)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

unfake.it URL shortener for Twitter Tools Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionurl-shortener-for-twitter-tools/tt_unfake_it.phptt_unfake_it.php:77
actionadmin_menutt_unfake_it.php:158
filtertweet_blog_post_urltt_unfake_it.php:182
actionadmin_headtt_unfake_it.php:224
Maintenance & Trust

unfake.it URL shortener for Twitter Tools Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedAug 21, 2010
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

unfake.it URL shortener for Twitter Tools Developer Profile

thomasgericke

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect unfake.it URL shortener for Twitter Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
url-shortener-for-twitter-tools/tt_unfake_it.php?ver=

HTML / DOM Fingerprints

CSS Classes
wrap
HTML Comments
use facebook? begin of plugin output added by WordPress plugin: unfake.it URL shortener - end of plugin output from: unfake.it URL shortener
JS Globals
window.open
FAQ

Frequently Asked Questions about unfake.it URL shortener for Twitter Tools