
Custom 404 Pro Security & Risk Analysis
wordpress.org/plugins/custom-404-proTake control of every 404 on your site — redirect visitors to a custom page or URL, log what broke, and get notified when it matters.
Is Custom 404 Pro Safe to Use in 2026?
Use With Caution
Score 50/100Custom 404 Pro has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "custom-404-pro" plugin v3.12.8 exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices in several areas, notable concerns arise from its vulnerability history and specific taint analysis findings. The plugin boasts a lack of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events without authentication, and generally uses prepared statements for SQL queries and proper output escaping. This suggests a good foundation for preventing common web attacks.
However, the presence of 3 unsanitized flows identified during taint analysis, all rated as high severity, is a significant concern. These flows represent potential vulnerabilities that could be exploited, even if the attack surface appears limited on the surface. Furthermore, the plugin's history of 12 known CVEs, including 2 critical and 2 high-severity ones, with one still unpatched, points to a recurring pattern of security weaknesses. The common vulnerability types (CSRF, XSS, SQL Injection) further emphasize the types of risks this plugin has historically presented.
In conclusion, while "custom-404-pro" has implemented some robust security measures, the identified high-severity taint flows and its substantial history of critical and high-severity vulnerabilities, particularly the unpatched one, indicate a significant ongoing risk. Users should be cautious and prioritize addressing the unpatched vulnerability and investigating the high-severity taint flows.
Key Concerns
- Currently unpatched CVE
- High severity taint flows (3)
- Critical CVEs in history (2)
- High severity CVEs in history (2)
Custom 404 Pro Security Vulnerabilities
CVEs by Year
Severity Breakdown
12 total CVEs
Custom 404 Pro <= 3.12.0 - Authenticated (Administrator+) SQL Injection via `path` Parameter
Custom 404 Pro <= 3.12.0 - Cross-Site Request Forgery
Custom 404 Pro <= 3.11.1 - Reflected Cross-Site Scripting
Custom 404 Pro <= 3.10.0 - Unauthenticated Stored Cross-Site Scripting via logging
Custom 404 Pro <= 3.8.1 - Reflected Cross-Site Scripting via 'page'
Custom 404 Pro <= 3.7.2 - Reflected Cross-Site Scripting via 's'
Custom 404 Pro <= 3.7.2 - Unauthenticated SQL Injection
Custom 404 Pro <= 3.8.0 - Unauthenticated SQL Injection via 's'
Custom 404 Pro <= 3.7.1 - Cross-Site Request Forgery
Custom 404 Pro <= 3.7.0 - Authenticated (Administrator+) SQL Injection
Custom 404 Pro <= 3.2.8 - Reflected Cross-Site Scripting
Custom 404 Pro <= 3.2.7 - Reflected Cross-Site Scripting
Custom 404 Pro Release Timeline
Custom 404 Pro Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom 404 Pro Attack Surface
WordPress Hooks 9
Maintenance & Trust
Custom 404 Pro Maintenance & Trust
Maintenance Signals
Community Trust
Custom 404 Pro Alternatives
Custom 404 Handler
custom-404-handler
Customized 404 page, error logging with analysis, automatic redirects and export functionality.
Redirect 404 to Homepage (with Logging)
redirect-404-to-homepage-with-logging
Redirects 404 errors to the homepage and logs the details for review.
Simple Redirect 404 to Homepage
simple-redirect-404-to-homepage
Redirect 404 error pages to your homepage with configurable options. Improve user experience and SEO with flexible redirect rules.
404 Redirect to Homepage or Custom URL
404-redirect-to-homepage-or-custom-url
Automatically redirect 404 errors to your homepage or any custom URL.
Axon 404
axon-404
A simple and easy to use custom 404 page, or basic 404 to home page redirect.
Custom 404 Pro Developer Profile
1 plugin · 7K total installs
How We Detect Custom 404 Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-404-pro/admin/css/custom-404-pro-admin.css/wp-content/plugins/custom-404-pro/admin/js/custom-404-pro-admin.js/wp-content/plugins/custom-404-pro/admin/js/custom-404-pro-admin.jscustom-404-pro/admin/css/custom-404-pro-admin.css?ver=custom-404-pro/admin/js/custom-404-pro-admin.js?ver=