
JMS URL Rewrite Rule Security & Risk Analysis
wordpress.org/plugins/jms-url-rewrite-ruleHelp to create 301 permanent redirection URL rewrite rules for .htaccess.
Is JMS URL Rewrite Rule Safe to Use in 2026?
Generally Safe
Score 85/100JMS URL Rewrite Rule has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jms-url-rewrite-rule" plugin v1.0.0 presents a generally positive security posture based on the provided static analysis. The absence of any reported CVEs and the fact that all SQL queries utilize prepared statements are strong indicators of good security practices. Furthermore, the plugin doesn't appear to expose a broad attack surface through AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, which is commendable. The presence of nonce and capability checks, even if limited in number, suggests an awareness of common WordPress security mechanisms.
However, a significant concern arises from the low percentage (29%) of properly escaped output. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is not consistently sanitized before being displayed to users. While no taint flows were identified in this analysis, a high rate of unescaped output can still be a precursor to such issues, especially if the plugin evolves or integrates with other components. The lack of identified dangerous functions and file operations is a positive sign, but the output escaping remains a notable weakness that requires attention.
In conclusion, the plugin demonstrates a good foundation in avoiding direct vulnerabilities like raw SQL or exposed entry points. Its vulnerability history is clean, which is a positive sign. The primary area for improvement and a source of potential risk lies in the inconsistent handling of output escaping. Addressing this weakness will be crucial for strengthening the plugin's overall security.
Key Concerns
- Low percentage of properly escaped output
JMS URL Rewrite Rule Security Vulnerabilities
JMS URL Rewrite Rule Code Analysis
Output Escaping
JMS URL Rewrite Rule Attack Surface
WordPress Hooks 1
Maintenance & Trust
JMS URL Rewrite Rule Maintenance & Trust
Maintenance Signals
Community Trust
JMS URL Rewrite Rule Alternatives
Redirection
redirection
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Custom Permalinks
custom-permalinks
A powerful WordPress plugin for full URL control. Set custom permalinks, auto-redirects, and use dynamic tags for ideal site structure and SEO.
Nginx Helper
nginx-helper
Cleans nginx's fastcgi/proxy cache or redis-cache whenever a post is edited/published. Also does a few more things.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
JMS URL Rewrite Rule Developer Profile
2 plugins · 20 total installs
How We Detect JMS URL Rewrite Rule
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jms-url-rewrite-rule/assets/css/bootstrap.min.css/wp-content/plugins/jms-url-rewrite-rule/assets/css/font-awesome.min.css/wp-content/plugins/jms-url-rewrite-rule/assets/css/style.css/wp-content/plugins/jms-url-rewrite-rule/assets/js/bootstrap.min.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/jquery-3.1.1.min.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/script.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/jquery-3.1.1.min.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/bootstrap.min.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/script.jsjms-url-rewrite-rule/assets/css/style.css?ver=jms-url-rewrite-rule/assets/js/script.js?ver=HTML / DOM Fingerprints
jms-post-url-rewrite-formjms-fixed-url-rewrite-formdata-toggle="tooltip"title="Copy to clipboard"jms_global_vars