
Hikari Category Permalink Security & Risk Analysis
wordpress.org/plugins/hikari-category-permalinkFor each post, author can choose which category is used in permalink.
Is Hikari Category Permalink Safe to Use in 2026?
Generally Safe
Score 85/100Hikari Category Permalink has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hikari-category-permalink" plugin v1.00.08 presents a mixed security posture. On the positive side, the plugin demonstrates strong practices regarding database interactions, with all SQL queries utilizing prepared statements and no identified external HTTP requests or file operations. The absence of known CVEs and a history of vulnerabilities is also a good sign. However, a significant concern arises from the static analysis, specifically the "Output escaping" signal, where 100% of the 63 identified outputs are not properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress dashboard or on the frontend, depending on where these outputs are displayed.
Furthermore, the "Taint analysis" reveals two flows with unsanitized paths. While these are not classified as critical or high severity, they still represent potential pathways for malicious input to influence application behavior without proper sanitization. The plugin also lacks any apparent nonce or capability checks, and its attack surface, while reported as zero entry points, is a point of scrutiny given the other identified code quality issues. The combination of unescaped output and unsanitized input flows, despite the absence of known CVEs, warrants careful attention and remediation to prevent potential security compromises.
Key Concerns
- 100% of outputs not properly escaped
- Unsanitized paths found in taint flows
- No nonce checks detected
- No capability checks detected
Hikari Category Permalink Security Vulnerabilities
Hikari Category Permalink Code Analysis
Output Escaping
Data Flow Analysis
Hikari Category Permalink Attack Surface
WordPress Hooks 12
Maintenance & Trust
Hikari Category Permalink Maintenance & Trust
Maintenance Signals
Community Trust
Hikari Category Permalink Alternatives
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
sCategory Permalink
scategory-permalink
Plugin allows to select category which will be used to generate permalink on post edit page. Use custom permalink option %scategory%.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Permalink Manager Lite
permalink-manager
Permalink Manager enhances WordPress’s built-in URL system, allowing you to change the URLs of native and custom post types and taxonomies.
Simple Post Type Permalinks
simple-post-type-permalinks
Easy to change Permalink of custom post type.
Hikari Category Permalink Developer Profile
6 plugins · 350 total installs
How We Detect Hikari Category Permalink
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hikari-category-permalink/scategory_permalink.js/wp-content/plugins/hikari-category-permalink/scategory_permalink.jshikari-category-permalink/scategory_permalink.js?ver=HTML / DOM Fingerprints
id="categorydiv"jQuery