Skip to main content

Trust and safety

Security at UrlShorter

UrlShorter combines destination restrictions, ownership checks, rate limits, and a documented abuse workflow. These controls reduce risk; they cannot guarantee that every external destination is safe or remains unchanged.

Security overview reviewed August 29, 2026

Safeguards in the current service

Destination validation

Submitted destinations must use public HTTP or HTTPS URLs. Explicit local, private, loopback, link-local, and reserved network destinations are rejected.

Ownership and authorization

Signed-in sessions and signed guest claims identify who may manage a link or hosted page. Sensitive writes are checked again by the server rather than trusting browser state.

Rate limits and optional screening

Creation and reporting workflows use rate limits. Turnstile and an external URL-reputation check can add screening when those providers are configured.

Recorded abuse review

The dedicated abuse form creates a case ID. Administrators can review reports, quarantine a link during investigation, and revoke a confirmed harmful redirect.

A short link is not a security boundary

  • Anyone who receives a public short URL may be able to open it. Protect confidential files at the destination with appropriate authentication and permissions.
  • A valid redirect does not prove that the destination is accurate, authorized, endorsed, or safe. Check the surrounding context and final hostname before entering information.
  • Automated reputation checks can miss new threats or later destination changes. They complement human reports and review; they do not replace them.
  • UrlShorter does not claim a formal security certification, independent audit, continuous malware guarantee, or bug-bounty program unless one is published here.

Report a suspicious link

Submit the UrlShorter link, category, and useful evidence through the abuse-reporting form. Do not open a suspected destination merely to collect more evidence. For general security or privacy questions, use the contact form and never send passwords, session tokens, or private keys.

Security claims on this page describe controls represented in the current application, not a guarantee against every misuse or external threat.