
Force non-SSL Security & Risk Analysis
wordpress.org/plugins/force-non-sslRedirects all HTTPS traffic to HTTP, except for specific exceptions
Is Force non-SSL Safe to Use in 2026?
Generally Safe
Score 85/100Force non-SSL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "force-non-ssl" v0.4 plugin exhibits a generally strong security posture based on the static analysis. The plugin has a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points. The code further demonstrates good practices by utilizing prepared statements for all SQL queries, properly escaping all outputs, and avoiding risky operations like file manipulation or external HTTP requests. There are no reported vulnerabilities or CVEs associated with this plugin, indicating a consistent history of secure development.
However, there are a couple of concerning findings. The taint analysis reveals two flows with unsanitized paths. While these did not reach critical or high severity in this static analysis, unsanitized paths can be a precursor to vulnerabilities if data is not handled correctly downstream. Furthermore, the complete absence of nonce checks and capability checks across all entry points is a significant concern. While the current attack surface is small, any future addition of features or modification that introduces new entry points without these fundamental security checks would immediately create exploitable weaknesses.
Key Concerns
- Unsanitized paths in taint analysis
- Missing nonce checks
- Missing capability checks
Force non-SSL Security Vulnerabilities
Force non-SSL Release Timeline
Force non-SSL Code Analysis
Output Escaping
Data Flow Analysis
Force non-SSL Attack Surface
WordPress Hooks 4
Maintenance & Trust
Force non-SSL Maintenance & Trust
Maintenance Signals
Community Trust
Force non-SSL Alternatives
Easy HTTPS Redirection (SSL)
https-redirection
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
SSL Insecure Content Fixer
ssl-insecure-content-fixer
Clean up WordPress website HTTPS insecure content
WP Force SSL & HTTPS SSL Redirect
wp-force-ssl
Enable SSL & HTTPS redirect with 1 click! Add SSL certificate & WP Force SSL to redirect site from HTTP to HTTPS & fix SSL errors.
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan
wp-letsencrypt-ssl
Lifetime SSL solution - Free SSL certificate & HTTPS redirect, resolve insecure site, fix SSL errors, SSL score, Easiest SSL & Security plugin.
One Click SSL
one-click-ssl
Enable SSL/TLS (https://) to redirect all pages to SSL/TLS and load all resources over SSL/TLS.
Force non-SSL Developer Profile
9 plugins · 5K total installs
How We Detect Force non-SSL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
FNSSL_exceptions