WPIntell

Source evidence

Linking Through Wrong URL

PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin · support · 2026-04-01T16:01:00+00:00

complaintsentiment
highseverity
0.82relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

9 / 39 rows with source links

23.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

30 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
melodys2412 resolved
Sometime in the last few days, our pro version of the Pretty Link plugin started redirecting all of our links through ushort.com , rather than our website, so all our links are broken. For example, one redirect now displays as https://urshort.com/zsqsyYtTy0r8/coachkit rather than https://ekithub.com/zsqsyYtTy0r8/coachkit ….if I paste the ekithub url into the search bar, it redirects as it should. However, if someone clicks the link we put into an email, it goes through the ushort.com redirect and ends up in a blank white page. Our hosting company says there’s been no breach/hack that they’ve found. We’re waiting for the results from an independent security scan to ensure there’s been no hack. This topic was modified 1 month, 3 weeks ago by melodys2412 . This topic was modified 1 month, 3 weeks ago by melodys2412 . The page I need help with: [ log in to see the link] Hey there, Thanks for reaching out! What you’re seeing doesn’t match how PrettyLinks normally behaves: redirects are meant to run on your own domain, so if clicks are ending up on ushort.com instead of your site, something outside the plugin is likely rewriting or intercepting the URL. That can sometimes be a compromised site, but it can also come from email link tracking, a security filter, or something else in the path between the click and your server. The detail that pasting the URL into the address bar works while a click from email does not is especially useful, because it suggests the problem might not be only on the WordPress side. To narrow it down, could you send one specific Pretty Link that does this, plus where you’re clicking it from? It would help to know whether it only happens from email or also when the same link is clicked from a normal webpage. In the meantime, running a deeper scan with something like Wordfence or Sucuri is still a reasonable step, and it’s worth checking common places where unwanted redirects get injected, such as .htaccess , wp-config.php , and the database, for anything that references that third-party domain. Once we have a concrete example and a bit more context on how the link is being opened, we can point you in a clearer direction. Looking forward to your reply. Thanks! All the best, It actually changed within the plugin itself. See here: https://www.dropbox.com/scl/fi/o9ci077is71syl5r75er9/prettylink.png?rlkey=34uk6qip68vsb3zljk6kv968n&st=vwf2yeg7&dl=0 I may have found the hack using a deep scan with Wordfence. It looks like a rank-math xml was uploaded which has the ushort code in it. Thank you! Hi there, Glad to hear you sorted this out! I am closing here then, but please feel free to contact us anytime if you need assistance with our product. Kind regards,

Comments

3 shown
oiler 2026-04-01T22:25:00+00:00

Hey there, Thanks for reaching out! What you’re seeing doesn’t match how PrettyLinks normally behaves: redirects are meant to run on your own domain, so if clicks are ending up on ushort.com instead of your site, something outside the plugin is likely rewriting or intercepting the URL. That can sometimes be a compromised site, but it can also come from email link tracking, a security filter, or something else in the path between the click and your server. The detail that pasting the URL into the address bar works while a click from email does not is especially useful, because it suggests the problem might not be only on the WordPress side. To narrow it down, could you send one specific Pretty Link that does this, plus where you’re clicking it from? It would help to know whether it only happens from email or also when the same link is clicked from a normal webpage. In the meantime, running a deeper scan with something like Wordfence or Sucuri is still a reasonable step, and it’s worth checking common places where unwanted redirects get injected, such as .htaccess , wp-config.php , and the database, for anything that references that third-party domain. Once we have a concrete example and a bit more context on how the link is being opened, we can point you in a clearer direction. Looking forward to your reply. Thanks! All the best,

melodys2412 2026-04-01T23:25:00+00:00

It actually changed within the plugin itself. See here: https://www.dropbox.com/scl/fi/o9ci077is71syl5r75er9/prettylink.png?rlkey=34uk6qip68vsb3zljk6kv968n&st=vwf2yeg7&dl=0 I may have found the hack using a deep scan with Wordfence. It looks like a rank-math xml was uploaded which has the ushort code in it. Thank you!

oiler 2026-04-01T23:52:00+00:00

Hi there, Glad to hear you sorted this out! I am closing here then, but please feel free to contact us anytime if you need assistance with our product. Kind regards,