
jadedcoder Sticky Permalinks Security & Risk Analysis
wordpress.org/plugins/jadedcoder-sticky-permalinksKeeps a history of your permalinks no matter what changes you make on your site, and redirects old links to the new ones.
Is jadedcoder Sticky Permalinks Safe to Use in 2026?
Generally Safe
Score 85/100jadedcoder Sticky Permalinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The jadedcoder-sticky-permalinks plugin, in its v0.1beta version, exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding output escaping, with 100% of analyzed outputs being properly escaped, and it has no known vulnerability history, suggesting a potentially stable codebase. It also reports no dangerous functions or file operations, and importantly, no external HTTP requests.
However, there are significant concerns arising from the static analysis. The plugin has a complete lack of any authentication or capability checks for its entry points, meaning any user, regardless of their role, could potentially interact with its functionality if any were exposed. While the attack surface is currently reported as zero, the absence of these checks is a major architectural flaw that would become a critical risk if functionality were added or exposed. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data could be manipulated in unintended ways. The SQL query usage is also a concern, with only 87% of queries utilizing prepared statements, leaving 13% vulnerable to SQL injection if not properly handled elsewhere.
In conclusion, while the plugin currently has a low apparent attack surface and a clean vulnerability history, the high-severity taint flows and the complete absence of authentication/capability checks are significant weaknesses. The SQL query practice is also suboptimal. These factors present a considerable risk, especially if the plugin's functionality is expanded or if the unsanitized paths are exploitable.
Key Concerns
- High severity taint flows with unsanitized paths
- SQL queries not using prepared statements
- No nonce checks on potential entry points
- No capability checks on potential entry points
jadedcoder Sticky Permalinks Security Vulnerabilities
jadedcoder Sticky Permalinks Code Analysis
SQL Query Safety
Data Flow Analysis
jadedcoder Sticky Permalinks Attack Surface
WordPress Hooks 4
Maintenance & Trust
jadedcoder Sticky Permalinks Maintenance & Trust
Maintenance Signals
Community Trust
jadedcoder Sticky Permalinks Alternatives
Hide Author Archive
hide-author-archive
Hide author archive URL of WordPress.
PTAPS – Post Type Archive Pages and Permalink Settings
post-type-archive-pages-and-permalink-settings
Use archive pages for custom post types and improve WordPress SEO by managing permalinks for custom post types and taxonomies.
Post Archive
post-archive
Add archive page for "Post".
Google News Unique Permalink ID
google-news-unique-permalink-id
This Plugin automatically adds 5 Digit Unique IDs to Permalinks ready for use with Google News.
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
jadedcoder Sticky Permalinks Developer Profile
1 plugin · 10 total installs
How We Detect jadedcoder Sticky Permalinks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jadedcoder-sticky-permalinks/css/style.css/wp-content/plugins/jadedcoder-sticky-permalinks/js/script.js/wp-content/plugins/jadedcoder-sticky-permalinks/js/script.jsjadedcoder-sticky-permalinks/css/style.css?ver=jadedcoder-sticky-permalinks/js/script.js?ver=