Easy Bouncer – Redirect by IP Security & Risk Analysis

wordpress.org/plugins/easy-redirect-by-ip

Redirect visitors to another web address if their IP address is not on a safe list. Give users access via a passkey url.

10 active installs v1.1 PHP + WP 3.5+ Updated Unknown
beforesiteredirectredirection-by-ip-addresssite-redirectionwebsite-redirection
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Bouncer – Redirect by IP Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Bouncer – Redirect by IP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "easy-redirect-by-ip" v1.1 plugin exhibits a seemingly strong security posture at first glance, with no identified entry points that are immediately exploitable without authentication. The absence of dangerous functions, SQL injection vulnerabilities (due to prepared statements), and external HTTP requests is commendable. Furthermore, the plugin's vulnerability history is clean, with no known CVEs, suggesting a history of responsible development and patching.

However, a significant concern arises from the output escaping analysis. With one total output and 0% properly escaped, this indicates a high likelihood of cross-site scripting (XSS) vulnerabilities. Any dynamic data displayed to users, if not properly escaped, could be manipulated by attackers to inject malicious scripts. The lack of nonce checks and the presence of only one capability check, while not directly indicating a vulnerability, suggests that the plugin might have limited input validation beyond basic capability checks, which could be a weakness if more complex input is handled.

In conclusion, while the plugin avoids common pitfalls like SQL injection and direct unauthenticated access, the glaring lack of output escaping presents a serious XSS risk. This weakness, combined with a minimal number of security checks, means that despite a clean history, the plugin's current implementation poses a notable security threat that needs immediate attention.

Key Concerns

  • Unescaped output detected
  • Minimal capability checks
  • No nonce checks
Vulnerabilities
None known

Easy Bouncer – Redirect by IP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy Bouncer – Redirect by IP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Easy Bouncer – Redirect by IP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_noticeseasy-redirect-by-ip.php:69
actionplugins_loadedeasy-redirect-by-ip.php:101
Maintenance & Trust

Easy Bouncer – Redirect by IP Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating80/100
Number of ratings2
Active installs10
Developer Profile

Easy Bouncer – Redirect by IP Developer Profile

Greenweb

8 plugins · 330 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Bouncer – Redirect by IP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
eri-message
FAQ

Frequently Asked Questions about Easy Bouncer – Redirect by IP