
Auto URL Security & Risk Analysis
wordpress.org/plugins/auto-urlAuto URL generates customized permalinks according to post types, categories and tags
Is Auto URL Safe to Use in 2026?
Generally Safe
Score 100/100Auto URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "auto-url" v1.4 plugin exhibits a concerning security posture despite having no known CVEs and a small attack surface. While the plugin demonstrates good practice by using prepared statements for all its SQL queries and avoiding file operations and external HTTP requests, several critical weaknesses were identified. The complete lack of output escaping across all identified outputs is a significant concern, as it leaves the plugin vulnerable to cross-site scripting (XSS) attacks. Additionally, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities related to how user-supplied data is handled, which could lead to unexpected behavior or security breaches if exploited. The absence of nonce and capability checks, even with a seemingly limited attack surface, further exacerbates these risks by allowing unauthenticated or improperly authenticated users to potentially trigger sensitive actions.
Key Concerns
- 0% output escaping
- High severity taint flows (2)
- 0 nonce checks
- 0 capability checks
Auto URL Security Vulnerabilities
Auto URL Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Auto URL Attack Surface
WordPress Hooks 6
Maintenance & Trust
Auto URL Maintenance & Trust
Maintenance Signals
Community Trust
Auto URL Alternatives
Disable Media Permalink by Hardweb.it
disable-media-permalink-by-hardweb-it
Completely disable the Media Permalink generated by WP.
WP Permastructure
wp-permastructure
Adds the ability to configure permalinks for custom post types using rewrite tags like %post_id% and %author%.
Permalinks with ID for bbPress
bbpress-permalinks-with-id
Transforms default bbPress permalinks (URLs) that use slugs into permalinks that use numeric IDs.
Media Post Permalink
media-post-permalink
Media Post Permalink is simply the easiest solution to separate your media/attachment Permalinks.
Taxonomic SEO Permalink
taxonomic-seo-permalinks
This plugin helps you to set your permalinks by using custom taxonomies just like you use %category% or %postname% in your permalink structure.
Auto URL Developer Profile
3 plugins · 30 total installs
How We Detect Auto URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-url/css/auto_url_admin.css/wp-content/plugins/auto-url/css/jquery-ui-1.8.16.custom.css/wp-content/plugins/auto-url/js/jquery-ui-1.8.16.custom.min.js/wp-content/plugins/auto-url/js/auto_url.jsauto-url/js/jquery-ui-1.8.16.custom.min.js?ver=auto-url/js/auto_url.js?ver=