
Custom Permalinks for Custom Post Types Security & Risk Analysis
wordpress.org/plugins/custom-permalinks-for-custom-post-typesRemove base slug of Custom Post Types and change the permalink structure of Custom Post Types.
Is Custom Permalinks for Custom Post Types Safe to Use in 2026?
Generally Safe
Score 85/100Custom Permalinks for Custom Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-permalinks-for-custom-post-types" plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and has no recorded vulnerabilities or CVEs. The absence of external HTTP requests, file operations, and bundled libraries further reduces its attack surface. However, there are significant concerns regarding output escaping and taint analysis. The fact that only 33% of outputs are properly escaped suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, particularly since the taint analysis found two flows with unsanitized paths, albeit without critical or high severity flags.
The plugin's vulnerability history, showing zero recorded issues, is a positive indicator of past security diligence. However, this historical data, combined with the current static analysis findings, presents a nuanced view. While the lack of historical vulnerabilities is reassuring, the identified issues with output escaping and unsanitized taint flows in the current version indicate potential weaknesses that could be exploited. The plugin has a low attack surface with no direct entry points needing authentication, but the unescaped output remains a critical area of concern that could lead to security incidents if exploited.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized paths in taint flows
Custom Permalinks for Custom Post Types Security Vulnerabilities
Custom Permalinks for Custom Post Types Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Permalinks for Custom Post Types Attack Surface
WordPress Hooks 5
Maintenance & Trust
Custom Permalinks for Custom Post Types Maintenance & Trust
Maintenance Signals
Community Trust
Custom Permalinks for Custom Post Types Alternatives
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Permalink Manager Lite
permalink-manager
Permalink Manager enhances WordPress’s built-in URL system, allowing you to change the URLs of native and custom post types and taxonomies.
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
Remove CPT base
remove-cpt-base
Remove custom post type base slug from url
Simple Post Type Permalinks
simple-post-type-permalinks
Easy to change Permalink of custom post type.
Custom Permalinks for Custom Post Types Developer Profile
1 plugin · 100 total installs
How We Detect Custom Permalinks for Custom Post Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-permalinks-for-custom-post-types/css/options-permalink.css/wp-content/plugins/custom-permalinks-for-custom-post-types/js/options-permalink.js/wp-content/plugins/custom-permalinks-for-custom-post-types/js/options-permalink.jscustom-permalinks-for-custom-post-types/css/options-permalink.css?ver=custom-permalinks-for-custom-post-types/js/options-permalink.js?ver=HTML / DOM Fingerprints
p105_permalink_structure_cptlinks_cached