
LH Better Slugs Security & Risk Analysis
wordpress.org/plugins/lh-better-slugsImprove your post and page slugs by removing too short unhelpful stopwords automatically.
Is LH Better Slugs Safe to Use in 2026?
Generally Safe
Score 85/100LH Better Slugs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'lh-better-slugs' plugin v1.00 exhibits an exceptionally strong security posture based on the provided static analysis. The complete absence of any identified attack surface, dangerous functions, unescaped output, file operations, external requests, or taint flows with unsanitized paths is a significant strength. Furthermore, the plugin's sole SQL queries are secured with prepared statements, and the lack of any recorded vulnerability history, including CVEs, reinforces this positive assessment. This suggests a development process that prioritizes secure coding practices.
However, the most notable concern arises from the complete lack of any security checks, including nonce and capability checks, across all potential entry points. While the current static analysis shows zero entry points, this indicates that if any entry points were to be introduced in future versions, they would likely be unprotected. This leaves a potential future vulnerability that is not addressed by current code.
In conclusion, 'lh-better-slugs' v1.00 is currently a very secure plugin due to its minimal attack surface and absence of known vulnerabilities. The primary weakness is the lack of any inherent security controls, which, while not an immediate issue given the current state, represents a significant future risk if the plugin is extended without proper security considerations. The plugin's strength lies in its current minimal footprint and clean code, but its weakness is its undeveloped security framework for future growth.
Key Concerns
- No nonce checks detected
- No capability checks detected
LH Better Slugs Security Vulnerabilities
LH Better Slugs Release Timeline
LH Better Slugs Code Analysis
LH Better Slugs Attack Surface
WordPress Hooks 2
Maintenance & Trust
LH Better Slugs Maintenance & Trust
Maintenance Signals
Community Trust
LH Better Slugs Alternatives
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Permalink Manager for WooCommerce
permalink-manager-for-woocommerce
Permalink Manager for WooCommerce improves your store permalinks and remove product, product_category and product_tag slugs from the URL.
Admin Slug Column
admin-slug-column
Adds a URL path column to all admin post type edit screens. Works with posts, pages, and any custom post type including WooCommerce products.
Wenprise Pinyin Slug
wenprise-pinyin-slug
自动转换 WordPress 中的中文文章别名、分类项目别名、图片文件名称为汉语拼音或英文翻译。
Automatically Update Permalinks
automatically-update-permalinks
Automatically updates the permalink (slug) of a post or page when its title is changed.
LH Better Slugs Developer Profile
89 plugins · 15K total installs
How We Detect LH Better Slugs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-better-slugs/HTML / DOM Fingerprints
_lh-better_slugs_postcheck