TRUST & SAFETY

Short links require strong trust.

Because a short URL can hide its destination, abuse prevention is treated as a core product requirement.

Baseline protections

  • HTTPS-only production traffic
  • Blocking localhost, private, and reserved IP destinations
  • Blocking unsupported URL schemes
  • Request rate limiting
  • Secret-key management for guest links
  • Stored abuse reports and operator blocking for phishing, malware, fraud, and spam

What happens after a report?

Reported links and destinations can be reviewed and blocked when risk is confirmed. Repeated abuse patterns may later be handled with domain-level restrictions or external reputation services.

Security reports

If you discover a vulnerability in URLTO itself, use the Contact page and choose Security. Include clear reproduction steps and likely impact, and avoid testing that unnecessarily affects real users or data.

URL Analysis network protections

URLTO's public analysis tools perform server-side fetching and therefore share a dedicated SSRF boundary. Only standard HTTP/HTTPS ports are allowed; localhost, private, and reserved addresses are blocked; every DNS answer and redirect target is revalidated. Connections are pinned to validated public IPs, with limits on response size, redirects, total time, concurrency, and request rate.

Website Quick Audit, SEO Check, Link Check, and Response Speed Check share the same application concurrency controls and Nginx edge request budget so adding entry tools does not multiply anonymous outbound-fetch capacity.

Social sign-in protection

Each sign-in attempt uses a random state value stored briefly in a Secure, HttpOnly cookie and verified on callback. Provider access tokens are used transiently to confirm the account identifier and are not stored as long-lived URLTO session credentials.

Report abuse Report abuse