
Loft404 Security & Risk Analysis
wordpress.org/plugins/loft404A toolkit to redirect 404 page to your custom page.
Is Loft404 Safe to Use in 2026?
Generally Safe
Score 85/100Loft404 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'loft404' v1.2.2, based on the provided static analysis, exhibits a strong security posture regarding its attack surface and data sanitization for SQL operations. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the plugin's adherence to prepared statements for all SQL queries is a positive indicator of preventing SQL injection vulnerabilities. The lack of file operations and external HTTP requests also reduces the risk of common web attack vectors.
However, a significant concern arises from the 'Output escaping' metric, which shows 0% properly escaped outputs. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content, if not properly escaped before being displayed in the browser, can be manipulated by attackers to inject malicious scripts. The 'Taint Analysis' and 'Vulnerability History' sections are clean, showing no critical or high-severity flows and no recorded vulnerabilities, which is a positive sign. Despite these strengths, the lack of output escaping is a critical weakness that needs immediate attention.
Key Concerns
- Output escaping is not used
Loft404 Security Vulnerabilities
Loft404 Release Timeline
Loft404 Code Analysis
Output Escaping
Loft404 Attack Surface
WordPress Hooks 6
Maintenance & Trust
Loft404 Maintenance & Trust
Maintenance Signals
Community Trust
Loft404 Alternatives
Redirect 404 Error Page to Homepage or Custom Page with Logs
redirect-404-error-page-to-homepage-or-custom-page
Redirect the 404 error page to the homepage or any other page with logs. Supports permanent (301), temporary (302) redirects & not found (404).
Redirect 404 to Home Page – Custom URL
redirect-404-to-home-page-custom-url
This Wordpress Plugin fixes 404 Errors in Google Webmasters by Redirecting all 404 URLs to Home Page or a Custom URL.
404 to 301 – Redirect, Log and Notify 404 Errors
404-to-301
Automatically redirect, log and notify all 404 page errors to any page using 301 redirect for SEO. No more 404 Errors in WebMaster tool.
Smart Custom 404 Error Page
404page
Create a custom 404 error page the easy way! No coding, and no redirects.
Custom 404 Pro
custom-404-pro
Override the default 404 page with any page from the Admin Panel or a Custom URL.
Loft404 Developer Profile
5 plugins · 70K total installs
How We Detect Loft404
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/loft404/assets/css/backend.css/wp-content/plugins/loft404/assets/css/frontend.css/wp-content/plugins/loft404/assets/js/backend.js/wp-content/plugins/loft404/assets/js/frontend.js/wp-content/plugins/loft404/assets/js/backend.js/wp-content/plugins/loft404/assets/js/frontend.jsloft404/assets/css/backend.css?ver=loft404/assets/css/frontend.css?ver=loft404/assets/js/backend.js?ver=loft404/assets/js/frontend.js?ver=HTML / DOM Fingerprints
loft404-notice Loft404 main file Update the plugin version for initial version Do nothing for initial version Define the constant used in this plugin +4 more