wp shortcut link and advertisement baner Security & Risk Analysis

wordpress.org/plugins/wp-shortcut-link

An plugin to create a shortcut link and advertisement baner

10 active installs v1.2.0 PHP + WP 3.0.1+ Updated Unknown
advertisementbanerlinkshortcut
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is wp shortcut link and advertisement baner Safe to Use in 2026?

Generally Safe

Score 100/100

wp shortcut link and advertisement baner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wp-shortcut-link plugin v1.2.0 exhibits a concerning security posture primarily due to its significant number of unprotected entry points and a lack of prepared statements for its SQL queries. With 4 out of 7 total entry points lacking authentication checks, this plugin presents a substantial attack surface that could be exploited by unauthenticated users. The taint analysis further exacerbates this concern, revealing 5 high-severity flows with unsanitized paths, strongly suggesting potential for code injection or data manipulation vulnerabilities. While the plugin has no known CVEs, this historical lack of reported issues does not negate the immediate risks identified in the static and taint analysis. The absence of dangerous function calls and file operations is a positive sign, but it is overshadowed by the critical need for proper input validation and authorization mechanisms.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
  • High severity taint flows with unsanitized paths
  • Low output escaping coverage
  • Limited capability checks
Vulnerabilities
None known

wp shortcut link and advertisement baner Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

wp shortcut link and advertisement baner Code Analysis

Dangerous Functions
0
Raw SQL Queries
13
0 prepared
Unescaped Output
15
10 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared13 total queries

Output Escaping

40% escaped25 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

7 flows6 with unsanitized paths
wpslab_redirect_function (menueadmin.php:15)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

wp shortcut link and advertisement baner Attack Surface

Entry Points7
Unprotected4

AJAX Handlers 6

authwp_ajax_save_wpslab_dataclientclient.php:4
authwp_ajax_wpslab_get_list_cat_clientclient.php:5
noprivwp_ajax_wpslab_get_list_cat_clientclient.php:6
authwp_ajax_remove_wpslab_dataclientclient.php:7
authwp_ajax_save_wpslab_datamenueadmin.php:11
authwp_ajax_save_wpslab_get_list_catmenueadmin.php:13

Shortcodes 1

[wpslab] shortcode.php:7
WordPress Hooks 9
actionwp_enqueue_scriptsclient.php:2
actionwp_footerclient.php:3
actionadmin_menumenueadmin.php:9
actionadmin_enqueue_scriptsmenueadmin.php:10
actionwp_loadedmenueadmin.php:12
actionwp_enqueue_scriptsshortcode.php:6
actionenqueue_block_editor_assetswp-block.php:8
filterblock_categorieswp-block.php:9
actionplugins_loadedwp-shortcut-link-advertisement.php:21
Maintenance & Trust

wp shortcut link and advertisement baner Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

wp shortcut link and advertisement baner Developer Profile

behzadrohizadeh

5 plugins · 190 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect wp shortcut link and advertisement baner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-shortcut-link/css/style.css/wp-content/plugins/wp-shortcut-link/js/client.js/wp-content/plugins/wp-shortcut-link/js/wpslab.js
Script Paths
/wp-content/plugins/wp-shortcut-link/js/client.js/wp-content/plugins/wp-shortcut-link/js/wpslab.js

HTML / DOM Fingerprints

CSS Classes
wpslabdata
Data Attributes
data-urleditnonce
JS Globals
the_in_url
REST Endpoints
/wp-json/wp/v2/posts/wp-json/wp/v2/pages/wp-json/wp/v2/media/wp-json/wp/v2/categories/wp-json/wp/v2/tags/wp-json/wp/v2/users/wp-json/wp/v2/comments
Shortcode Output
<div class="wpslabdata data-url=" edit=" nonce="
FAQ

Frequently Asked Questions about wp shortcut link and advertisement baner