
Change Core Slugs Security & Risk Analysis
wordpress.org/plugins/change-core-slugsSet custom permalink slugs instead of default ones.
Is Change Core Slugs Safe to Use in 2026?
Generally Safe
Score 85/100Change Core Slugs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "change-core-slugs" plugin v1.0.0 reveals a strong adherence to secure coding practices. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the plugin's attack surface. Furthermore, the code demonstrates excellent signal hygiene, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The lack of file operations, external HTTP requests, and the absence of sensitive code signals like nonces or capability checks, when combined with the lack of identified taint flows, indicates a well-contained and secure codebase from a static analysis perspective. The plugin's vulnerability history is also remarkably clean, with zero known CVEs, unpatched vulnerabilities, or recorded common vulnerability types. This suggests a history of stability and a lack of previously exploited weaknesses.
Despite the overwhelmingly positive static analysis and vulnerability history, the complete absence of any capability checks or nonce checks is a notable, albeit minor, point of concern, especially if the plugin were to evolve and introduce new functionalities that might require access control or state manipulation. However, given the current state of the plugin with zero identified entry points and a clean history, the overall security posture is exceptionally good. The plugin's strengths lie in its minimal attack surface and diligent secure coding practices, while its only potential weakness, which is currently theoretical due to its limited functionality, is the lack of explicit capability enforcement for potential future features.
Key Concerns
- No capability checks found
- No nonce checks found
Change Core Slugs Security Vulnerabilities
Change Core Slugs Code Analysis
Output Escaping
Change Core Slugs Attack Surface
WordPress Hooks 10
Maintenance & Trust
Change Core Slugs Maintenance & Trust
Maintenance Signals
Community Trust
Change Core Slugs Alternatives
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Admin Slug Column
admin-slug-column
Adds a URL path column to all admin post type edit screens. Works with posts, pages, and any custom post type including WooCommerce products.
Automatically Update Permalinks
automatically-update-permalinks
Automatically updates the permalink (slug) of a post or page when its title is changed.
German Slugs
german-slugs
German Slugs properly transliterates umlauts and the letter ß appearing in titles for slugs (i.e. for pretty permalinks).
DKA More clean permalinks
dka-more-clean-permalinks
More sanitized permalinks
Change Core Slugs Developer Profile
20 plugins · 48K total installs
How We Detect Change Core Slugs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.