
Add or Remove Www Security & Risk Analysis
wordpress.org/plugins/add-or-remove-wwwAdd or Remove Www lets you easily configure your WordPress site to always (or never) use the www. subdomain in all links of the posts and pages.
Is Add or Remove Www Safe to Use in 2026?
Generally Safe
Score 85/100Add or Remove Www has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'add-or-remove-www' plugin v1.01 exhibits a generally strong security posture based on the static analysis. It boasts a remarkably small attack surface with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, significantly reducing common attack vectors. The presence of a nonce check is also a positive sign for input validation. However, a significant concern arises from the taint analysis, which revealed two flows with unsanitized paths. This indicates a potential weakness where user-supplied or external data might be processed in a way that could lead to unintended actions or information disclosure, even if the severity of these flows wasn't classified as critical or high. The lack of output escaping on all four identified outputs is another notable weakness, potentially exposing the site to Cross-Site Scripting (XSS) vulnerabilities if any of these outputs contain user-controlled data.
The plugin's vulnerability history is a strong positive, showing zero known CVEs and no historical vulnerabilities. This suggests a well-maintained codebase or a lack of exploitation in the past. Combined with the minimal attack surface, this historical data contributes to a perception of safety. Despite the absence of historical vulnerabilities, the identified taint flows and the complete lack of output escaping are real, evidence-backed concerns that should not be overlooked. Therefore, while the plugin demonstrates good practices in many areas, the identified taint flow issues and unescaped output warrant attention to ensure a robust security profile.
Key Concerns
- Unsanitized paths in taint flows
- No output escaping
Add or Remove Www Security Vulnerabilities
Add or Remove Www Code Analysis
Output Escaping
Data Flow Analysis
Add or Remove Www Attack Surface
WordPress Hooks 4
Maintenance & Trust
Add or Remove Www Maintenance & Trust
Maintenance Signals
Community Trust
Add or Remove Www Alternatives
Subdomains
subdomains
Subdomains allows users to setup there main categories as subdomains. It's a lite and fast code.
WP Super Subdomains
wp-super-subdomains
This plugin allow you create subdomain without using Wordpress Multisite ! Setup your main categories, tag, pages, and authors as subdomains !
WP Subdomains (Revisited)
wp-subdomains-revisited
Setup your main categories, pages, and authors as subdomains with custom themes. Surely will come for more options...
Automatic Subdomains
automatic-subdomains
Automatically maps subdomains to page and post permalinks based on post slug.
html in author bios
html-in-author-bios
html in autor bios
Add or Remove Www Developer Profile
9 plugins · 8K total installs
How We Detect Add or Remove Www
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.