Auto URL Security & Risk Analysis

wordpress.org/plugins/auto-url

Auto URL generates customized permalinks according to post types, categories and tags

10 active installs v1.4 PHP + WP 3.1+ Updated Unknown
attachmentmediapermalinkrewriteurl
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto URL Safe to Use in 2026?

Generally Safe

Score 100/100

Auto URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "auto-url" v1.4 plugin exhibits a concerning security posture despite having no known CVEs and a small attack surface. While the plugin demonstrates good practice by using prepared statements for all its SQL queries and avoiding file operations and external HTTP requests, several critical weaknesses were identified. The complete lack of output escaping across all identified outputs is a significant concern, as it leaves the plugin vulnerable to cross-site scripting (XSS) attacks. Additionally, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities related to how user-supplied data is handled, which could lead to unexpected behavior or security breaches if exploited. The absence of nonce and capability checks, even with a seemingly limited attack surface, further exacerbates these risks by allowing unauthenticated or improperly authenticated users to potentially trigger sensitive actions.

Key Concerns

  • 0% output escaping
  • High severity taint flows (2)
  • 0 nonce checks
  • 0 capability checks
Vulnerabilities
None known

Auto URL Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Auto URL Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
11 prepared
Unescaped Output
24
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared11 total queries

Output Escaping

0% escaped24 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
auto_url_admin_template_pattern (auto-url.php:297)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Auto URL Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedauto-url.php:139
actionadmin_menuauto-url.php:177
filterattachment_linkauto-url.php:869
filterpage_linkauto-url.php:871
filterpost_linkauto-url.php:873
filterrequestauto-url.php:979
Maintenance & Trust

Auto URL Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedUnknown
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Auto URL Developer Profile

dexxaye

3 plugins · 30 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto URL

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-url/css/auto_url_admin.css/wp-content/plugins/auto-url/css/jquery-ui-1.8.16.custom.css
Script Paths
/wp-content/plugins/auto-url/js/jquery-ui-1.8.16.custom.min.js/wp-content/plugins/auto-url/js/auto_url.js
Version Parameters
auto-url/js/jquery-ui-1.8.16.custom.min.js?ver=auto-url/js/auto_url.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Auto URL