Loft404 Security & Risk Analysis

wordpress.org/plugins/loft404

A toolkit to redirect 404 page to your custom page.

10 active installs v1.2.2 PHP + WP 3.4+ Updated Jun 10, 2016
404404-pageredirect-404
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Loft404 Safe to Use in 2026?

Generally Safe

Score 85/100

Loft404 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin 'loft404' v1.2.2, based on the provided static analysis, exhibits a strong security posture regarding its attack surface and data sanitization for SQL operations. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the plugin's adherence to prepared statements for all SQL queries is a positive indicator of preventing SQL injection vulnerabilities. The lack of file operations and external HTTP requests also reduces the risk of common web attack vectors.

However, a significant concern arises from the 'Output escaping' metric, which shows 0% properly escaped outputs. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content, if not properly escaped before being displayed in the browser, can be manipulated by attackers to inject malicious scripts. The 'Taint Analysis' and 'Vulnerability History' sections are clean, showing no critical or high-severity flows and no recorded vulnerabilities, which is a positive sign. Despite these strengths, the lack of output escaping is a critical weakness that needs immediate attention.

Key Concerns

  • Output escaping is not used
Vulnerabilities
None known

Loft404 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Loft404 Release Timeline

v1.2.2Current
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Loft404 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Loft404 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actiontemplate_redirectclass-loft-404-front.php:22
actionwpclass-loft-404-front.php:23
filterbody_classclass-loft-404-front.php:24
actionadmin_initclass-loft-404-settings.php:22
actionadmin_menuclass-loft-404-settings.php:23
actioninitloft404.php:54
Maintenance & Trust

Loft404 Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 10, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Loft404 Developer Profile

loftocean

5 plugins · 70K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Loft404

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/loft404/assets/css/backend.css/wp-content/plugins/loft404/assets/css/frontend.css/wp-content/plugins/loft404/assets/js/backend.js/wp-content/plugins/loft404/assets/js/frontend.js
Script Paths
/wp-content/plugins/loft404/assets/js/backend.js/wp-content/plugins/loft404/assets/js/frontend.js
Version Parameters
loft404/assets/css/backend.css?ver=loft404/assets/css/frontend.css?ver=loft404/assets/js/backend.js?ver=loft404/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
loft404-notice
HTML Comments
Loft404 main file Update the plugin version for initial version Do nothing for initial version Define the constant used in this plugin +4 more
FAQ

Frequently Asked Questions about Loft404