
ezRedirect Security & Risk Analysis
wordpress.org/plugins/ezredirectAllows the creation of redirections to internal pages and posts, and external addresses.
Is ezRedirect Safe to Use in 2026?
Generally Safe
Score 100/100ezRedirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ezredirect" v1.1.0 plugin presents a mixed security picture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively. The absence of known CVEs and a clean vulnerability history suggest a relatively stable and well-maintained codebase in the past. The plugin also shows an effort towards security with a single nonce check, indicating awareness of common WordPress attack vectors.
However, significant concerns arise from the static analysis. The "taint analysis" reveals one flow with an unsanitized path, specifically flagged as high severity. This is a critical finding as it points to a potential pathway for malicious input to be processed without proper sanitization, which could lead to various vulnerabilities depending on how this unsanitized data is used. Furthermore, the "output escaping" is only 59% proper, meaning a substantial portion of output may be vulnerable to cross-site scripting (XSS) attacks, especially if user-provided data is involved in these unescaped outputs.
While the plugin boasts a small attack surface with no apparent unprotected entry points, the identified high-severity taint flow and the low rate of proper output escaping are substantial weaknesses. The lack of capability checks on the limited entry points is also a concern, though the absence of entry points without authentication mitigates this risk to some degree. The conclusion is that while the plugin has a clean past and uses prepared statements, the current version has high-severity risks related to unsanitized input and XSS vulnerabilities due to insufficient output escaping that require immediate attention.
Key Concerns
- High severity taint flow with unsanitized path
- Low proper output escaping rate (59%)
- No capability checks on entry points
ezRedirect Security Vulnerabilities
ezRedirect Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ezRedirect Attack Surface
WordPress Hooks 3
Maintenance & Trust
ezRedirect Maintenance & Trust
Maintenance Signals
Community Trust
ezRedirect Alternatives
Automatic Domain Changer
automatic-domain-changer
Automatically detects a domain name change, and updates all the WordPress tables in the database to reflect this change.
Nofollow Case by Case
nofollow-case-by-case
"Dofollow" but Nofollow Case by Case allows you to selectively apply nofollow to your comments as well.
Auto Copyright
auto-copyright-1
Automatically generates a copyright notice based on the first and last post published in the WordPress database.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Adminimize
adminimize
Adminimize that lets you hide 'unnecessary' items from the WordPress backend
ezRedirect Developer Profile
3 plugins · 10K total installs
How We Detect ezRedirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ezredirect/js/ezredirect.js/wp-content/plugins/ezredirect/css/ezredirect.css/wp-content/plugins/ezredirect/js/ezredirect.jsezredirect/js/ezredirect.js?ver=ezredirect/css/ezredirect.css?ver=HTML / DOM Fingerprints
ezredirect-admin-notice<!-- ezRedirect Admin Notice -->data-ezredirect-nonceezredirect