Custom .htaccess rules manager Security & Risk Analysis

wordpress.org/plugins/custom-htaccess-rules

Manage custom .htaccess rules (top and bottom blocks) with shell-mode syntax highlighting and auto-expanding editor.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Jul 24, 2025
backupcustom-ruleseditorhtaccesssecurity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom .htaccess rules manager Safe to Use in 2026?

Generally Safe

Score 100/100

Custom .htaccess rules manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The custom-htaccess-rules plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points, coupled with the lack of dangerous functions and the universal use of prepared statements for SQL queries, indicates excellent defensive coding practices. Furthermore, all output is properly escaped, and the presence of nonce and capability checks on the limited entry points further reinforces this. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a stable and well-maintained codebase. The taint analysis showing no unsanitized paths is also a positive indicator.

Despite these strengths, the presence of four file operations without further context could potentially represent a minor area of concern. While not flagged as problematic by the static analysis (e.g., no unsanitized paths related to file operations), the nature and permissions of these operations would warrant a deeper dive in a more comprehensive review. However, based solely on the data provided, the plugin appears to be very secure. The lack of any documented vulnerabilities reinforces this confidence.

Vulnerabilities
None known

Custom .htaccess rules manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Custom .htaccess rules manager Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Custom .htaccess rules manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
49 escaped
Nonce Checks
3
Capability Checks
1
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped49 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
pd_cht_settings_page (custom-htaccess-rules.php:170)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Custom .htaccess rules manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menucustom-htaccess-rules.php:104
actionadmin_enqueue_scriptscustom-htaccess-rules.php:122
Maintenance & Trust

Custom .htaccess rules manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 24, 2025
PHP min version7.4
Downloads301

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Custom .htaccess rules manager Developer Profile

Peter Duchnovsky

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom .htaccess rules manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-htaccess-rules/js/admin.js/wp-content/plugins/custom-htaccess-rules/css/admin.css
Script Paths
/wp-content/plugins/custom-htaccess-rules/js/admin.js
Version Parameters
custom-htaccess-rules/js/admin.js?ver=custom-htaccess-rules/css/admin.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Settings page for Custom .htaccess rules manager -->
Data Attributes
data-editor-id="custom_htaccess_top"data-editor-id="custom_htaccess_bottom"
JS Globals
wp.codeEditor.initialize
FAQ

Frequently Asked Questions about Custom .htaccess rules manager