YOURLS Link Creator Security & Risk Analysis

wordpress.org/plugins/yourls-link-creator

Creates a custom short URL when saving posts. Requires your own YOURLS install.

600 active installs v2.1.1 PHP + WP 3.6+ Updated Feb 25, 2016
custom-urlshortlinkyourls
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YOURLS Link Creator Safe to Use in 2026?

Generally Safe

Score 85/100

YOURLS Link Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "yourls-link-creator" v2.1.1 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped. There are no file operations, external HTTP requests, or vulnerable taint flows detected. The absence of any known CVEs and the plugin's clean vulnerability history further reinforce its secure design. This indicates a development team that prioritizes secure coding practices.

While the plugin demonstrates excellent internal security, the static analysis does highlight a complete absence of capability checks and nonce checks across all identified entry points. Although the attack surface is currently zero, any future addition of AJAX handlers, REST API routes, or shortcodes without these essential security checks would introduce significant vulnerabilities. The lack of recorded vulnerabilities is a positive indicator, but it's crucial to remember that this only reflects past activity and doesn't guarantee future immunity. Therefore, the plugin is fundamentally secure in its current state, but future development must incorporate robust authentication and authorization mechanisms to maintain this high standard.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

YOURLS Link Creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

YOURLS Link Creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

YOURLS Link Creator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedyourls-link-creator.php:58
actionplugins_loadedyourls-link-creator.php:59
actionplugins_loadedyourls-link-creator.php:62

Scheduled Events 2

yourls_cron
yourls_test
Maintenance & Trust

YOURLS Link Creator Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 25, 2016
PHP min version
Downloads27K

Community Trust

Rating90/100
Number of ratings13
Active installs600
Developer Profile

YOURLS Link Creator Developer Profile

Andrew Norcross

18 plugins · 2K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YOURLS Link Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yourls-link-creator/css/admin.css/wp-content/plugins/yourls-link-creator/css/front.css/wp-content/plugins/yourls-link-creator/js/admin.js/wp-content/plugins/yourls-link-creator/js/front.js
Script Paths
/wp-content/plugins/yourls-link-creator/js/admin.js/wp-content/plugins/yourls-link-creator/js/front.js
Version Parameters
yourls-link-creator/css/admin.css?ver=yourls-link-creator/css/front.css?ver=yourls-link-creator/js/admin.js?ver=yourls-link-creator/js/front.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about YOURLS Link Creator