URL Smasher Security & Risk Analysis

wordpress.org/plugins/url-smasher

Automatically shortens URLs in posts, pages, and comments using goo.gl.

10 active installs v3.10 PHP + WP 4.0.1+ Updated Apr 10, 2024
url-shortener-automatic-goo-gl
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is URL Smasher Safe to Use in 2026?

Generally Safe

Score 92/100

URL Smasher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "url-smasher" v3.10 plugin exhibits a generally strong security posture with no known vulnerabilities in its history and a clean static analysis report regarding dangerous functions, SQL queries, and taint flows. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly those without authentication or permission checks, significantly limits its attack surface. However, a notable concern is the low percentage of properly escaped output (25%), indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without adequate sanitization. While the plugin makes external HTTP requests, the lack of specific details makes it difficult to assess the risk associated with this without further analysis. The absence of nonce and capability checks, while not directly tied to exposed entry points in this version, represents a missed opportunity for defense-in-depth, especially if functionality is added in future updates.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

URL Smasher Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

URL Smasher Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

25% escaped8 total outputs
Attack Surface

URL Smasher Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuurl-smasher.php:61
actionadmin_initurl-smasher.php:62
filterpreprocess_commenturl-smasher.php:279
filterwp_insert_post_dataurl-smasher.php:283
Maintenance & Trust

URL Smasher Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 10, 2024
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Alternatives

URL Smasher Alternatives

No alternatives data available yet.

Developer Profile

URL Smasher Developer Profile

Rick Hellewell

16 plugins · 1K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect URL Smasher

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/url-smasher/css/urlsmasher_settings.css
Version Parameters
url-smasher/css/urlsmasher_settings.css?ver=

HTML / DOM Fingerprints

CSS Classes
urlsmasher_optionsurlsmasher_sidebar
Data Attributes
name="url_smasher_options[url_smasher_bitly_token]"name="url_smasher_options[url_smasher_enable_content]"name="url_smasher_options[url_smasher_enable_comment]"
FAQ

Frequently Asked Questions about URL Smasher