
Change OG URL To HTTP Security & Risk Analysis
wordpress.org/plugins/change-og-url-to-httpChanges OG URL tag added by Yoast, Aioseo and other plugins from HTTPS to HTTP to retain facebook like count for posts and pages.
Is Change OG URL To HTTP Safe to Use in 2026?
Generally Safe
Score 85/100Change OG URL To HTTP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "change-og-url-to-http" v1.0 plugin exhibits a strong security posture based on the provided static analysis. There are no identified attack surface entry points that lack proper authentication or permission checks, including AJAX handlers, REST API routes, shortcodes, and cron events. The code also demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and properly escaping all output. The absence of file operations and external HTTP requests further reduces potential vulnerabilities.
The plugin's vulnerability history is clean, with no known CVEs recorded, regardless of severity. This, coupled with the zero taint flow findings, suggests a low likelihood of critical or high-severity vulnerabilities being present. The plugin's reliance on capability checks, even with no identified specific entry points requiring them in this analysis, is a positive sign of intended security awareness.
Overall, the plugin appears to be developed with security in mind, adhering to common best practices. The lack of any identified vulnerabilities or significant risks in the static analysis, coupled with a spotless historical record, makes this plugin appear very safe to use. The primary weakness identified is the absence of nonce checks, which while not directly exploitable given the lack of AJAX/REST entry points, is a general security practice that is missing.
Key Concerns
- No nonce checks found
Change OG URL To HTTP Security Vulnerabilities
Change OG URL To HTTP Release Timeline
Change OG URL To HTTP Code Analysis
Output Escaping
Change OG URL To HTTP Attack Surface
WordPress Hooks 4
Maintenance & Trust
Change OG URL To HTTP Maintenance & Trust
Maintenance Signals
Community Trust
Change OG URL To HTTP Alternatives
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
really-simple-ssl
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
Easy HTTPS Redirection (SSL)
https-redirection
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
SSL Insecure Content Fixer
ssl-insecure-content-fixer
Clean up WordPress website HTTPS insecure content
WP Force SSL & HTTPS SSL Redirect
wp-force-ssl
Enable SSL & HTTPS redirect with 1 click! Add SSL certificate & WP Force SSL to redirect site from HTTP to HTTPS & fix SSL errors.
Change OG URL To HTTP Developer Profile
4 plugins · 140 total installs
How We Detect Change OG URL To HTTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.