
HTTPS Domain Alias Security & Risk Analysis
wordpress.org/plugins/https-domain-aliasEnable your site to have a different domains for HTTP and HTTPS.
Is HTTPS Domain Alias Safe to Use in 2026?
Generally Safe
Score 85/100HTTPS Domain Alias has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "https-domain-alias" plugin v1.4.3 exhibits a strong security posture based on the provided static analysis. The absence of any detected entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good security practices with 100% of SQL queries using prepared statements and all detected outputs being properly escaped, with no dangerous functions, file operations, or external HTTP requests observed.
However, the taint analysis does reveal two flows with unsanitized paths. While these are not flagged as critical or high severity, they still represent a potential concern that could be exploited under specific circumstances, especially if the input sources for these paths are not rigorously validated. The plugin also has no recorded vulnerability history, which is a positive indicator of its past security, but this does not entirely negate the risks identified in the current analysis.
In conclusion, the plugin is generally well-secured with a minimal attack surface and adherence to secure coding principles. The primary concern lies with the two identified taint flows that have unsanitized paths, which warrants attention and potential remediation to achieve a more robust security profile. The lack of historical vulnerabilities is a strength, but vigilance is still required for the identified code signals.
Key Concerns
- Flows with unsanitized paths found
HTTPS Domain Alias Security Vulnerabilities
HTTPS Domain Alias Code Analysis
Data Flow Analysis
HTTPS Domain Alias Attack Surface
WordPress Hooks 18
Maintenance & Trust
HTTPS Domain Alias Maintenance & Trust
Maintenance Signals
Community Trust
HTTPS Domain Alias Alternatives
Simple HTTPS
simple-https
Correct your SSL/HTTPS issue within few clicks and enable HTTP Strict Transport Security for your website.
Domain Check
domain-check
Domain Check lets you search domain names, check SSL certificates and HTTPS, set email alerts for domain and SSL expiration, and get daily coupons.
HTTPS Mixed Content Detector
https-mixed-content-detector
Detects and logs content that will cause mixed content warnings.
Easy HTTPS Redirection (SSL)
https-redirection
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
SSL Insecure Content Fixer
ssl-insecure-content-fixer
Clean up WordPress website HTTPS insecure content
HTTPS Domain Alias Developer Profile
4 plugins · 6K total installs
How We Detect HTTPS Domain Alias
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/https-domain-alias/css/admin-style.css/wp-content/plugins/https-domain-alias/js/admin-script.jsHTML / DOM Fingerprints
Copyright 2015-2018 Seravo Oy This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License, version 3, as published by the Free Software Foundation.+30 moredata-https-domain-alias-debugwindow.https_domain_alias_admin_script