Attachment Pages Redirect Security & Risk Analysis

wordpress.org/plugins/attachment-pages-redirect

Redirect attachment pages or return a 404 error for them based on the parent post status.

20K active installs v1.1.2 PHP 5.6+ WP 4.8+ Updated Jan 16, 2026
301302attachmentimagesredirect
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Attachment Pages Redirect Safe to Use in 2026?

Generally Safe

Score 100/100

Attachment Pages Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of the attachment-pages-redirect plugin v1.1.2 indicates a generally strong security posture. The absence of any identified dangerous functions, SQL injection vulnerabilities through prepared statements, and proper output escaping are significant strengths. Furthermore, the lack of file operations, external HTTP requests, and the very limited attack surface (zero entry points) suggest a well-contained plugin. The vulnerability history is also clean, with no recorded CVEs, which further reinforces the impression of a secure plugin.

However, a notable concern arises from the complete absence of nonce checks and capability checks. While the current analysis shows no unprotected entry points, this lack of access control mechanisms means that if any entry points were introduced or discovered in the future, they would be inherently vulnerable to unauthorized access or manipulation. This represents a significant weakness in the plugin's defensive strategy, as it relies solely on the lack of exposed functionality rather than robust permission validation. In conclusion, the plugin exhibits excellent coding practices in many areas, but the omission of essential security checks like nonces and capability checks presents a potential, albeit currently unexploited, risk.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Attachment Pages Redirect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Attachment Pages Redirect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Attachment Pages Redirect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actiontemplate_redirectattachment-pages-redirect.php:82
Maintenance & Trust

Attachment Pages Redirect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 16, 2026
PHP min version5.6
Downloads181K

Community Trust

Rating98/100
Number of ratings47
Active installs20K
Developer Profile

Attachment Pages Redirect Developer Profile

Samuel Aguilera

14 plugins · 98K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Attachment Pages Redirect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Attachment Pages Redirect