HTTPS for WordPress Security & Risk Analysis

wordpress.org/plugins/https-for-wordpress

Check to see if SSL is used. This will update any template functions which require SSL to be used.

40 active installs v.2 PHP + WP 2.1.2+ Updated Jun 3, 2008
encryptedhttphttpsssl
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is HTTPS for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

HTTPS for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The 'https-for-wordpress' v.2 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no discernible attack surface, no dangerous functions, and no file operations or external HTTP requests, all of which are positive indicators. Furthermore, the complete absence of SQL injection vulnerabilities due to 100% prepared statements and the 100% proper output escaping demonstrate a commitment to secure coding practices. The taint analysis also shows no identified flows with unsanitized paths, reinforcing the perception of a secure codebase. The plugin's vulnerability history is equally impressive, with zero known CVEs, indicating a lack of previously identified security flaws. This combination of robust code practices and a clean vulnerability record suggests a highly secure plugin. However, the complete lack of nonces and capability checks across all entry points (though there are zero entry points detected) presents a theoretical weakness. If any entry points were to be introduced or discovered in the future, their lack of these fundamental security mechanisms would be a significant concern.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

HTTPS for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

HTTPS for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

HTTPS for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filteroption_siteurlhttps-for-wordpress.php:11
filteroption_homehttps-for-wordpress.php:12
filteroption_urlhttps-for-wordpress.php:13
filteroption_wpurlhttps-for-wordpress.php:14
filteroption_stylesheet_urlhttps-for-wordpress.php:15
filteroption_template_urlhttps-for-wordpress.php:16
Maintenance & Trust

HTTPS for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested2.5
Last updatedJun 3, 2008
PHP min version
Downloads13K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

HTTPS for WordPress Developer Profile

blackc2004

5 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HTTPS for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about HTTPS for WordPress