
Decategorizer Security & Risk Analysis
wordpress.org/plugins/decategorizer"Decategorizer" removes 'category base' from your permalinks. Quick setup and no editing required. 301 redirections are added aut …
Is Decategorizer Safe to Use in 2026?
Generally Safe
Score 85/100Decategorizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The decategorizer plugin version 0.7.1.2 exhibits several concerning security practices despite having no publicly known vulnerabilities. The static analysis reveals a significant lack of security checks, including zero capability checks and zero nonce checks. Furthermore, 100% of its SQL queries are not using prepared statements, which is a critical vulnerability that could lead to SQL injection. The presence of the `create_function` dangerous function, while not explicitly linked to a vulnerability in this analysis, is a known source of potential security issues and should be avoided. The taint analysis shows that all analyzed flows involve unsanitized paths, indicating a high risk of handling user-supplied data insecurely, even though no critical or high severity issues were flagged directly. The absence of a vulnerability history is positive, but it does not negate the significant risks identified in the code itself. The plugin's overall security posture is weak due to these fundamental security flaws.
Key Concerns
- Raw SQL queries without prepared statements
- Taint analysis: Unsanitized paths found
- Dangerous function: create_function
- No nonce checks
- No capability checks
- Output escaping: 60% not properly escaped
Decategorizer Security Vulnerabilities
Decategorizer Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Decategorizer Attack Surface
WordPress Hooks 17
Maintenance & Trust
Decategorizer Maintenance & Trust
Maintenance Signals
Community Trust
Decategorizer Alternatives
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
WP Remove Category Base
wp-remove-category-base
Removes the category base slug from the category archive permalinks (URL's).
No category parents
no-category-parents
This plugin will completely remove the mandatory 'Category Base' and all the parents from your category permalinks (e.g.
Awesome Widgets for SiteOrigin Page Builder
awesome-widgets-for-siteorigin-page-builder
Easy & quick to install high-end Awesome Widgets for SiteOrigin Page Builder help you add Featured Collection, New Arrival, Sale Off, Best Seller, …
Decategorizer Developer Profile
1 plugin · 10 total installs
How We Detect Decategorizer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
decategorizer/style.css?ver=decategorizer/script.js?ver=