JMS URL Rewrite Rule Security & Risk Analysis

wordpress.org/plugins/jms-url-rewrite-rule

Help to create 301 permanent redirection URL rewrite rules for .htaccess.

0 active installs v1.0.0 PHP + WP 4.0.0+ Updated Mar 28, 2018
htaccesspermalinkurl-rewrite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JMS URL Rewrite Rule Safe to Use in 2026?

Generally Safe

Score 85/100

JMS URL Rewrite Rule has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "jms-url-rewrite-rule" plugin v1.0.0 presents a generally positive security posture based on the provided static analysis. The absence of any reported CVEs and the fact that all SQL queries utilize prepared statements are strong indicators of good security practices. Furthermore, the plugin doesn't appear to expose a broad attack surface through AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, which is commendable. The presence of nonce and capability checks, even if limited in number, suggests an awareness of common WordPress security mechanisms.

However, a significant concern arises from the low percentage (29%) of properly escaped output. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is not consistently sanitized before being displayed to users. While no taint flows were identified in this analysis, a high rate of unescaped output can still be a precursor to such issues, especially if the plugin evolves or integrates with other components. The lack of identified dangerous functions and file operations is a positive sign, but the output escaping remains a notable weakness that requires attention.

In conclusion, the plugin demonstrates a good foundation in avoiding direct vulnerabilities like raw SQL or exposed entry points. Its vulnerability history is clean, which is a positive sign. The primary area for improvement and a source of potential risk lies in the inconsistent handling of output escaping. Addressing this weakness will be crucial for strengthening the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

JMS URL Rewrite Rule Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

JMS URL Rewrite Rule Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
4 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped14 total outputs
Attack Surface

JMS URL Rewrite Rule Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menujms-urlrewrite-rule.php:28
Maintenance & Trust

JMS URL Rewrite Rule Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.0
Last updatedMar 28, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

JMS URL Rewrite Rule Developer Profile

James

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JMS URL Rewrite Rule

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jms-url-rewrite-rule/assets/css/bootstrap.min.css/wp-content/plugins/jms-url-rewrite-rule/assets/css/font-awesome.min.css/wp-content/plugins/jms-url-rewrite-rule/assets/css/style.css/wp-content/plugins/jms-url-rewrite-rule/assets/js/bootstrap.min.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/jquery-3.1.1.min.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/script.js
Script Paths
/wp-content/plugins/jms-url-rewrite-rule/assets/js/jquery-3.1.1.min.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/bootstrap.min.js/wp-content/plugins/jms-url-rewrite-rule/assets/js/script.js
Version Parameters
jms-url-rewrite-rule/assets/css/style.css?ver=jms-url-rewrite-rule/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
jms-post-url-rewrite-formjms-fixed-url-rewrite-form
Data Attributes
data-toggle="tooltip"title="Copy to clipboard"
JS Globals
jms_global_vars
FAQ

Frequently Asked Questions about JMS URL Rewrite Rule