PLUGIN SECURITY
Is Url Shortify safe?
URL Shortify helps you beautify, manage, share & cloak any links on or off your WordPress website. Create links using your domain name!
What this plugin does
- Slug:
url-shortify - Author: KaizenCoders
- 10000+ active installs
- 94/100 rating (164 reviews on wordpress.org)
- 620358 all-time downloads
- On WordPress.org since 2020-05-07
affiliate linkscloakinglink brandingshort linksurl shortener
Maintenance status
- Latest known version: 2.5.0
- Last updated: 2026-08-24 5:50am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
12 known CVEs on file for Url Shortify.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-13362 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.10.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.10.5.1 | 1.10.5.1 | 2026-04-30 | ✓ fixed in latest |
| CVE-2026-73362 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 2.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.5.1 | 2.5.1 | 2026-04-30 | ⚠ update needed |
| CVE-2026-25385 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.12.4 | Server-Side Request Forgery (SSRF) | Medium 5.5 | < 1.12.4 | 1.12.4 | 2026-02-19 | ✓ fixed in latest |
| CVE-2025-12684 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.11.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.11.3 | 1.11.3 | 2025-11-24 | ✓ fixed in latest |
| CVE-2025-13355 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.11.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.11.4 | 1.11.4 | 2025-11-24 | ✓ fixed in latest |
| CVE-2025-32134 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.10.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 1.10.6 | 1.10.6 | 2025-04-04 | ✓ fixed in latest |
| CVE-2023-5605 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.7.9.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 1.7.9.1 | 1.7.9.1 | 2023-11-06 | ✓ fixed in latest |
| CVE-2023-4294 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.7.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.7.6 | 1.7.6 | 2023-08-21 | ✓ fixed in latest |
+ 9 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-33999 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.7.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.7.4 | 1.7.4 | 2023-07-18 | ✓ fixed in latest |
| CVE-2023-3129 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.7.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 1.7.0 | 1.7.0 | 2023-06-19 | ✓ fixed in latest |
| — | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.5.11 | Missing Authorization | Medium 6.3 | < 1.5.11 | 1.5.11 | 2022-03-04 | ✓ fixed in latest |
| — | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.5.11 | — | Unknown | < 1.5.11 | 1.5.11 | 2022-02-28 | ✓ fixed in latest |
| — | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.5.11 | — | Unknown | < 1.5.11 | 1.5.11 | 2022-02-28 | ✓ fixed in latest |
| CVE-2021-24749 | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.5.11 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.5.11 | 1.5.11 | 2021-10-28 | ✓ fixed in latest |
| — | URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.12.2 | — | Unknown | < 1.12.2 | 1.12.2 | 0000-00-00 | ✓ fixed in latest |
| — | Unauthorised AJAX Calls via Freemius | — | Unknown | < 1.5.11 | 1.5.11 | — | ✓ fixed in latest |
| CVE-2026-1277 | URL Shortify < 1.12.2 - Unauthenticated Open Redirect via 'redirect_to' Parameter | — | Unknown | < 1.12.2 | 1.12.2 | — | ✓ fixed in latest |
How to fix it
Keep Url Shortify updated — 2.5.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links — 200000+ active installs — 96/100 (1317) — max PHP 8.4
- ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin — 30000+ active installs — 92/100 (251) — max PHP 8.4
- BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP — 20000+ active installs — 96/100 (85) — max PHP 8.4
- Content Egg – Affiliate Product Importer & Price Comparison — 10000+ active installs — 78/100 (54)
- AffiliateX – Amazon Affiliate Plugin, Product Boxes, Comparison Tables & Affiliate Link Tracking — 9000+ active installs — 90/100 (34)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.