Yourls Link Creator Bulk Generate Security & Risk Analysis

wordpress.org/plugins/yourls-link-creator-bulk-generate

Bulk generate Yourls URLS when using the Yourls Link Creator plugin.

10 active installs v1.0.0 PHP + WP 3.6.0+ Updated Unknown
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yourls Link Creator Bulk Generate Safe to Use in 2026?

Generally Safe

Score 100/100

Yourls Link Creator Bulk Generate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "yourls-link-creator-bulk-generate" v1.0.0 plugin exhibits a strong security posture in several key areas, with no identified vulnerabilities in its history and a promising static analysis report. The absence of known CVEs and unpatched vulnerabilities is a significant strength, indicating a generally secure development history or limited exposure to past security issues. The code analysis reveals a clean slate regarding dangerous functions, raw SQL queries (all using prepared statements), file operations, and external HTTP requests, which are all positive indicators. The presence of a nonce check is also a good practice.

However, there are areas of concern that temper the overall good assessment. A significant weakness is the low percentage of properly escaped output (38%). This implies a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data might be rendered directly in the browser without proper sanitization, potentially allowing malicious scripts to execute. Furthermore, the complete absence of capability checks and the zero unprotected entry points in the attack surface analysis might suggest that the plugin's functionality is not deeply integrated into sensitive WordPress actions or user roles, which could be a double-edged sword. While it limits the attack surface, it also means that any future expansion without proper capability checks could introduce significant risks.

In conclusion, while the plugin demonstrates good practices by avoiding common pitfalls like raw SQL and dangerous functions, the high rate of unescaped output presents a substantial risk that needs immediate attention. The lack of historical vulnerabilities is encouraging, but the current static analysis highlights a critical area for improvement to prevent potential XSS attacks. The limited attack surface and lack of capability checks warrant further investigation if the plugin is intended for complex or sensitive operations.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Yourls Link Creator Bulk Generate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yourls Link Creator Bulk Generate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped21 total outputs
Attack Surface

Yourls Link Creator Bulk Generate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninityourls-link-creator-bulk-generate.php:93
actionadmin_menuyourls-link-creator-bulk-generate.php:94
actionload-tools_page_yourls-link-creator-bulk-generateyourls-link-creator-bulk-generate.php:95
actionyourls_link_creator_bulk_generate_noticeyourls-link-creator-bulk-generate.php:328
actionyourls_link_creator_bulk_generate_noticeyourls-link-creator-bulk-generate.php:334
Maintenance & Trust

Yourls Link Creator Bulk Generate Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.0
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Yourls Link Creator Bulk Generate Alternatives

No alternatives data available yet.

Developer Profile

Yourls Link Creator Bulk Generate Developer Profile

Dustin Filippini

5 plugins · 530 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yourls Link Creator Bulk Generate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yourls-link-creator-bulk-generate/js/ylcbg.js/wp-content/plugins/yourls-link-creator-bulk-generate/css/ylcbg.css
Script Paths
/wp-content/plugins/yourls-link-creator-bulk-generate/js/ylcbg.js
Version Parameters
yourls-link-creator-bulk-generate/js/ylcbg.js?ver=yourls-link-creator-bulk-generate/css/ylcbg.css?ver=

HTML / DOM Fingerprints

CSS Classes
ylcbg_post_types
Data Attributes
ylcbg_post_types[]ylcbg_submitylcbg_nonce
FAQ

Frequently Asked Questions about Yourls Link Creator Bulk Generate