
Mavis HTTPS to HTTP Redirection Security & Risk Analysis
wordpress.org/plugins/mavis-https-to-http-redirectProvides page redirection back to non-secured pages (https: to http:)
Is Mavis HTTPS to HTTP Redirection Safe to Use in 2026?
Use With Caution
Score 63/100Mavis HTTPS to HTTP Redirection has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "mavis-https-to-http-redirect" plugin, version 1.4.3, presents a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are positive indicators. However, the analysis also flags a critical concern: 100% of output is not properly escaped, indicating a significant risk of Cross-Site Scripting (XSS) vulnerabilities if any dynamic content is displayed to users. The taint analysis also shows flows with unsanitized paths, although these did not reach a critical or high severity in this assessment, they warrant further investigation.
The plugin has a history of known vulnerabilities, with one medium severity CVE currently unpatched. This historical pattern, especially with a recent vulnerability dating to late 2025, suggests a recurring issue with security flaws. While the absence of obvious entry points for direct attacks is a strength, the unescaped output and historical vulnerability pattern are significant weaknesses. The overall risk is elevated due to the potential for XSS and the unaddressed past CVE, despite the absence of a large, exposed attack surface.
Key Concerns
- Unpatched CVE
- Output not properly escaped
- Taint flows with unsanitized paths
Mavis HTTPS to HTTP Redirection Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mavis HTTPS to HTTP Redirection <= 1.4.3 - Cross-Site Request Forgery
Mavis HTTPS to HTTP Redirection Code Analysis
Output Escaping
Data Flow Analysis
Mavis HTTPS to HTTP Redirection Attack Surface
WordPress Hooks 2
Maintenance & Trust
Mavis HTTPS to HTTP Redirection Maintenance & Trust
Maintenance Signals
Community Trust
Mavis HTTPS to HTTP Redirection Alternatives
Easy HTTPS Redirection (SSL)
https-redirection
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
Simple SSL Redirects
simple-ssl-redirects
Lightweight plugin to ensure access via SSL/HTTPS. Uses 301 (permanent) redirects for SEO benefits. Optionally sets HSTS and forces canonical domain.
Advanced Https Redirection
advanced-https-redirection
Redirect your whole domain from/to http to/from https, or redirect just certain pages without any technical knowledge.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
really-simple-ssl
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
Mavis HTTPS to HTTP Redirection Developer Profile
5 plugins · 140 total installs
How We Detect Mavis HTTPS to HTTP Redirection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapoptionseditformname='mavis_update'name='secured_page_tag'