
WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Security & Risk Analysis
wordpress.org/plugins/wp-shortifyShortify allows you to track, in real-time, the clicks and referrers on any shortened URL Within Wordpress dashboard.
Is WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Safe to Use in 2026?
Generally Safe
Score 85/100WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-shortify" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it boasts a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and notably, all SQL queries utilize prepared statements. The absence of any recorded vulnerabilities in its history is also a strong indicator of a well-maintained or less complex plugin.
However, significant concerns arise from the static analysis. The presence of the `unserialize()` function is a critical security risk, especially if its input is not strictly controlled or sanitized. Furthermore, the overwhelmingly low percentage of properly escaped output (6%) suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as data is likely being outputted directly to the browser without adequate sanitization. The taint analysis revealing two unsanitized paths, while not rated critical or high, still points to potential data leakage or manipulation if these paths are exploitable.
While the plugin's history is clean, the code analysis reveals inherent weaknesses. The lack of nonce checks is particularly concerning, given the potential for Cross-Site Request Forgery (CSRF) if any of the limited entry points were to become exploitable. In conclusion, despite a clean vulnerability history and a minimal attack surface, the presence of `unserialize()`, widespread unescaped output, and the absence of nonce checks present substantial security risks that require immediate attention. The strengths in SQL handling and lack of CVEs are overshadowed by these critical coding practices.
Key Concerns
- Dangerous function: unserialize
- Low percentage of properly escaped output (6%)
- Taint flows with unsanitized paths
- No nonce checks
- File operations present
- External HTTP requests present
WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Security Vulnerabilities
WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Release Timeline
WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Attack Surface
WordPress Hooks 11
Maintenance & Trust
WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Maintenance & Trust
Maintenance Signals
Community Trust
WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Alternatives
Advanced Views Counter – Post Views Counter Analytics & Popular Posts Tracker
advanced-views-counter
Track and display post views with detailed stats. Exclude bots, set intervals, and see top posts and referrers.
PostTally
posttally
A plugin that adds a [post_count] shortcode to display the total number of published posts.
PostViews Insights
postviews-insights
Display post view insights and provide a shortcode to list posts based on view count.
Simple Post View Count
simple-post-view-count
Track and display post view counts. Includes shortcode support, customizable settings, and view logs with CSV export.
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
WP URLs Shortener 2015 + Social icons + Analytics[goo.gl] Developer Profile
2 plugins · 20 total installs
How We Detect WP URLs Shortener 2015 + Social icons + Analytics[goo.gl]
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-shortify/js/script.js/wp-content/plugins/wp-shortify/js/admin-script.js/wp-content/plugins/wp-shortify/css/style.css/wp-content/plugins/wp-shortify/css/admin-style.css/wp-content/plugins/wp-shortify/js/script.js/wp-content/plugins/wp-shortify/js/admin-script.jswp-shortify/js/script.js?ver=wp-shortify/js/admin-script.js?ver=wp-shortify/css/style.css?ver=wp-shortify/css/admin-style.css?ver=HTML / DOM Fingerprints
data-clientiddata-clientsecretdata-redirectdata-scopedata-apikeyWP_Shortify_Ajax