404s Security & Risk Analysis

wordpress.org/plugins/404s

fix all kinds of 404s, fix broken link & images automatically,log each 404,redirect each broken link to specific URL,404 mail alert,export 404s,re …

10 active installs v3.5.9 PHP + WP 3.2+ Updated Feb 7, 2024
404404-redirectbroken-linkpage-not-found-errorredirect
85
A · Safe
CVEs total1
Unpatched0
Last CVEJun 22, 2022
Safety Verdict

Is 404s Safe to Use in 2026?

Generally Safe

Score 85/100

404s has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jun 22, 2022Updated 2yr ago
Risk Assessment

The '404s' plugin v3.5.9 exhibits a generally positive security posture, with no apparent critical or high-severity vulnerabilities detected in the static analysis. The absence of common entry points like AJAX handlers, REST API routes, and shortcodes, coupled with a lack of dangerous function usage and file operations, significantly reduces the potential attack surface. The presence of a nonce check, though not tied to a specific capability check, is a good practice. However, concerns arise from the taint analysis, which identified two flows with unsanitized paths. While these did not escalate to critical or high severity, they represent potential vectors for unexpected behavior or injection if an attacker can manipulate the inputs involved. The plugin's vulnerability history, featuring one medium-severity Cross-Site Scripting (XSS) vulnerability patched in 2022, indicates a past susceptibility to input sanitization issues. Although currently unpatched, this history suggests the need for continued vigilance in input handling and output escaping. The plugin's strengths lie in its limited attack surface and the general use of prepared statements for SQL. The primary weakness is the presence of unsanitized input paths, which warrants careful review to ensure these do not lead to exploitable conditions, especially in light of its past XSS vulnerability.

Key Concerns

  • Flows with unsanitized paths identified in taint analysis
  • Medium severity XSS vulnerability in history
  • SQL queries not using prepared statements (37% of 8)
  • Output escaping not properly implemented (33% of 69)
Vulnerabilities
1 published

404s Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-2118medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

404s <= 3.4.9 - Administrator+ Cross-Site Scripting

Jun 22, 2022 Patched in 3.5.1 (580d)
Version History

404s Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

404s Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
5 prepared
Unescaped Output
23
46 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

63% prepared8 total queries

Output Escaping

67% escaped69 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
tomas_404s_setitngs (404s.php:433)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

404s Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actiontemplate_redirect404s.php:233
actionadmin_menu404s.php:388
actionadmin_footer404s.php:1071
actionadmin_head404s.php:1090
actioninitrules\404export.php:100
actionadd_meta_boxesrules\404sassignredirect.php:63
actionsave_postrules\404sassignredirect.php:64
actionplugins_loadedrules\loadtextdomain.php:9
actioninitrules\register404post.php:43
Maintenance & Trust

404s Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 7, 2024
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

404s Developer Profile

Tomas

12 plugins · 7K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
526 days
View full developer profile
Detection Fingerprints

How We Detect 404s

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/404s/
Version Parameters
404s/style.css?ver=404sinstall.php?ver=404paginate.php?ver=404toemail.php?ver=rules/register404post.php?ver=rules/404sassignredirect.php?ver=rules/404export.php?ver=rules/loadtextdomain.php?ver=

HTML / DOM Fingerprints

CSS Classes
bpmotable
HTML Comments
Copyright 2016-2024 TomasThis program comes with ABSOLUTELY NO WARRANTY;start 3.4.1
Data Attributes
id="bpmotable"style="table-layout: fixed;"
FAQ

Frequently Asked Questions about 404s