A minimal and secure URL shortener built with PHP, MariaDB, HTML, CSS, and JavaScript.
- 🔗 Fast URL shortening — Shorten long URLs with one click
- ✨ Custom short codes — Choose your own short code (optional)
- 📊 Statistics — View click counts and referrer data
- 📱 QR codes — Generate QR codes for any short URL
- 🔒 Admin panel — Password-protected management with secure authentication
- 🛡️ Security — Rate limiting, CSRF protection, secure password hashing
- 🔐 GDPR compliant — IP addresses are anonymized by default
- 📱 Responsive design — Works on all devices
- PHP 7.4+
- MariaDB 10.3+ or MySQL 5.7+
- Apache with mod_rewrite (or nginx)
- PDO PHP extension
- Upload files to your web server
- Open
https://your-domain.com/install.php - Follow the installation wizard
- Delete
install.phpimmediately after installation!
- Import
database/schema.sqlinto MariaDB/MySQL - Copy
api/config.php.exampletoapi/config.phpand edit settings - Generate a password hash:
php -r "echo password_hash('your-password', PASSWORD_DEFAULT);" - Update
ADMIN_PASSWORD_HASHinapi/admin.php
This version includes several security improvements:
- Password hashing — Admin passwords are stored using
password_hash()with bcrypt - Secure tokens — Authentication tokens are cryptographically secure random strings
- Rate limiting — Protects against brute-force attacks and DoS
- IP anonymization — Last octet of IP addresses is removed (GDPR compliance)
- Security headers — X-Frame-Options, X-Content-Type-Options, etc.
- Secure sessions — httpOnly, secure, and SameSite cookie flags
- Delete
install.phpfrom server - Set
CORS_ORIGINto your specific domain inconfig.php - Ensure HTTPS is enabled
- Review rate limit settings
URL: https://your-domain.com/admin.html
Features:
- Shorten URLs
- View all links with statistics
- Edit or delete links
- Generate QR codes
- View referrer statistics
POST /api/shorten.php
Content-Type: application/json
{
"url": "https://example.com/long-url",
"custom_code": "optional"
}GET /api/stats.php?code=abc123Returns only aggregated statistics (total clicks, creation date). Detailed statistics require admin authentication.
A migration script is included. See migrate_yourls.php for instructions.
- Backup your database and files
- Upload all new files except
api/config.phpandinstall.php - Upload
upgrade.phpto your installation folder - Open
https://your-domain.com/upgrade.phpin your browser - Follow the upgrade wizard
- Delete
upgrade.phpimmediately after upgrade!
- Backup your database
- Run
database/upgrade.sqlagainst your database - Manually update
api/config.phpwith new constants and functions - Generate a password hash:
php -r "echo password_hash('your-password', PASSWORD_DEFAULT);" - Update
ADMIN_PASSWORD_HASHinapi/admin.php
See the upgrade guide for detailed instructions.
- Allowed characters:
a-z,A-Z,0-9,_,- - Length: 1-100 characters
- Reserved codes:
admin,api,stats,login,logout,install
This project is licensed under the GNU General Public License v3.0 - see the LICENSE file for details.
Snip - URL Shortener
Copyright (C) 2025 Martin Bekkelund
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
- Martin Bekkelund - GitHub
Contributions are welcome! Please feel free to submit a Pull Request.