Simple Redirection Security & Risk Analysis

wordpress.org/plugins/eelv-redirection

Simply redirect all pages off your blogs to a specified URL

200 active installs v1.6.1 PHP + WP 4.6+ Updated Dec 9, 2025
301302httpredirectredirection
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 4, 2024
Safety Verdict

Is Simple Redirection Safe to Use in 2026?

Generally Safe

Score 99/100

Simple Redirection has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 4, 2024Updated 3mo ago
Risk Assessment

The eelv-redirection plugin v1.6.1 exhibits a strong security posture based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests, coupled with 100% proper output escaping and the use of prepared statements, indicates a well-coded and defensive approach. Furthermore, the presence of nonce and capability checks, even with a limited attack surface, is a positive sign. The vulnerability history shows only one past medium-severity CVE related to CSRF, which is also currently patched. This suggests the developers have addressed past issues promptly.

Despite these strengths, the analysis does not reveal any critical or high-severity risks within the current code. The minimal attack surface and lack of critical taint flows are reassuring. However, the sole past medium vulnerability, while patched, highlights the importance of continued vigilance, especially for plugins dealing with redirections which can sometimes be leveraged for various attacks if not secured properly. The overall risk is low, but ongoing monitoring and regular updates are always recommended for any plugin.

Key Concerns

  • One past medium severity CVE
Vulnerabilities
1

Simple Redirection Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11341medium · 4.3Cross-Site Request Forgery (CSRF)

Simple Redirection <= 1.5 - Cross-Site Request Forgery to Arbitrary Site Redirect

Dec 4, 2024 Patched in 1.5.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

Simple Redirection Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
27 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped27 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_page (eelv_redirection.php:88)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple Redirection Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Simple Redirection Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Simple Redirection Developer Profile

NOUS Open Usefull & Simple

5 plugins · 410 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Simple Redirection

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- redirection -->
JS Globals
document.location.href
FAQ

Frequently Asked Questions about Simple Redirection