Hikari Category Permalink Security & Risk Analysis

wordpress.org/plugins/hikari-category-permalink

For each post, author can choose which category is used in permalink.

300 active installs v1.00.08 PHP + WP 3.0+ Updated Oct 17, 2010
categorycustompermalinkpermalinksseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hikari Category Permalink Safe to Use in 2026?

Generally Safe

Score 85/100

Hikari Category Permalink has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "hikari-category-permalink" plugin v1.00.08 presents a mixed security posture. On the positive side, the plugin demonstrates strong practices regarding database interactions, with all SQL queries utilizing prepared statements and no identified external HTTP requests or file operations. The absence of known CVEs and a history of vulnerabilities is also a good sign. However, a significant concern arises from the static analysis, specifically the "Output escaping" signal, where 100% of the 63 identified outputs are not properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress dashboard or on the frontend, depending on where these outputs are displayed.

Furthermore, the "Taint analysis" reveals two flows with unsanitized paths. While these are not classified as critical or high severity, they still represent potential pathways for malicious input to influence application behavior without proper sanitization. The plugin also lacks any apparent nonce or capability checks, and its attack surface, while reported as zero entry points, is a point of scrutiny given the other identified code quality issues. The combination of unescaped output and unsanitized input flows, despite the absence of known CVEs, warrants careful attention and remediation to prevent potential security compromises.

Key Concerns

  • 100% of outputs not properly escaped
  • Unsanitized paths found in taint flows
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

Hikari Category Permalink Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Hikari Category Permalink Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
63
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped63 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
debugRequestParameters (hikari-tools.php:847)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Hikari Category Permalink Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_print_styles-post.phphikari-category-permalink-core.php:35
actionadmin_print_styles-post-new.phphikari-category-permalink-core.php:36
actionadmin_footer-post.phphikari-category-permalink-core.php:38
actionadmin_footer-post-new.phphikari-category-permalink-core.php:39
actionadmin_noticeshikari-category-permalink-core.php:41
actiontransition_post_statushikari-category-permalink-core.php:44
filterpost_rewrite_ruleshikari-category-permalink-core.php:47
filterpre_post_linkhikari-category-permalink-core.php:48
filterpost_linkhikari-category-permalink-core.php:49
actioninithikari-tools.php:33
actionadmin_inithikari-tools.php:374
actionadmin_menuhikari-tools.php:375
Maintenance & Trust

Hikari Category Permalink Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedOct 17, 2010
PHP min version
Downloads16K

Community Trust

Rating100/100
Number of ratings5
Active installs300
Developer Profile

Hikari Category Permalink Developer Profile

shidouhikari

6 plugins · 350 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hikari Category Permalink

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hikari-category-permalink/scategory_permalink.js
Script Paths
/wp-content/plugins/hikari-category-permalink/scategory_permalink.js
Version Parameters
hikari-category-permalink/scategory_permalink.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="categorydiv"
JS Globals
jQuery
FAQ

Frequently Asked Questions about Hikari Category Permalink