
YOURLS: WordPress to Twitter Security & Risk Analysis
wordpress.org/plugins/yourls-wordpress-to-twitterUse YOURLS (a free GPL URL shortener service) to create short URLs of your posts, or for your BuddyPress groups and users
Is YOURLS: WordPress to Twitter Safe to Use in 2026?
Generally Safe
Score 85/100YOURLS: WordPress to Twitter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yourls-wordpress-to-twitter" plugin version 1.6.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has a clean vulnerability history with no recorded CVEs. The absence of file operations and external HTTP requests also reduces potential attack vectors. However, significant concerns arise from the attack surface analysis. All three identified AJAX handlers lack authentication checks, creating direct entry points for unauthorized actions. Furthermore, while the plugin uses nonce checks, the complete absence of capability checks for these AJAX handlers means that any authenticated user, regardless of their role or permissions, could potentially trigger these actions.
The static analysis also reveals issues with output escaping, with only 13% of outputs being properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with care. The taint analysis did not reveal any unsanitized flows, which is a positive sign. Despite the lack of past vulnerabilities, the presence of unprotected AJAX endpoints and potential for XSS due to insufficient output escaping represent real, exploitable risks that should be addressed to improve the plugin's overall security.
Key Concerns
- 3 AJAX handlers without auth checks
- 0 Capability checks on entry points
- Low percentage of properly escaped output
YOURLS: WordPress to Twitter Security Vulnerabilities
YOURLS: WordPress to Twitter Code Analysis
SQL Query Safety
Output Escaping
YOURLS: WordPress to Twitter Attack Surface
AJAX Handlers 3
WordPress Hooks 34
Maintenance & Trust
YOURLS: WordPress to Twitter Maintenance & Trust
Maintenance Signals
Community Trust
YOURLS: WordPress to Twitter Alternatives
Ozh' Tweet Archiver
ozh-tweet-archiver
Import and archive your tweets with WordPress
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Custom Twitter Feeds – A Tweets Widget or X Feed Widget
custom-twitter-feeds
Display X posts (Twitter tweets) from any public user account in a clean, attractive looking feed that updates weekly.
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
YOURLS: WordPress to Twitter Developer Profile
27 plugins · 5K total installs
How We Detect YOURLS: WordPress to Twitter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yourls-wordpress-to-twitter/css/style.css/wp-content/plugins/yourls-wordpress-to-twitter/js/admin.js/wp-content/plugins/yourls-wordpress-to-twitter/js/script.js/wp-content/plugins/yourls-wordpress-to-twitter/js/admin.js/wp-content/plugins/yourls-wordpress-to-twitter/js/script.jsyourls-wordpress-to-twitter/css/style.css?ver=yourls-wordpress-to-twitter/js/admin.js?ver=yourls-wordpress-to-twitter/js/script.js?ver=HTML / DOM Fingerprints
<!-- YOURLS: WordPress to Twitter Settings --><!-- YOURLS: Create your short url --><!-- YOURLS: If you have a custom keyword for this post -->data-yourls-reset-urldata-yourls-promote-urldata-yourls-reset-noncedata-yourls-promote-noncedata-yourls-check-nonceozh_yourls_ajax_nonceozh_yourls_opts<a href="" rel="nofollow alternate shorturl shortlink" title="Short URL"></a>