
Media Post Permalink Security & Risk Analysis
wordpress.org/plugins/media-post-permalinkMedia Post Permalink is simply the easiest solution to separate your media/attachment Permalinks.
Is Media Post Permalink Safe to Use in 2026?
Generally Safe
Score 85/100Media Post Permalink has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "media-post-permalink" plugin v0.1 exhibits a mixed security posture. While the static analysis indicates a very small attack surface with zero identified entry points and no known vulnerabilities historically, there are significant concerns within the code itself. The presence of the "unserialize" function is a critical red flag, as unserialization of untrusted data is a common vector for remote code execution. Furthermore, all SQL queries are executed without prepared statements, which opens the door to SQL injection vulnerabilities. The lack of proper output escaping on all identified outputs suggests a high risk of cross-site scripting (XSS) attacks. Despite the lack of known vulnerabilities and a minimal attack surface, these code-level weaknesses represent substantial inherent risks that could be easily exploited if an attacker can influence the data being unserialized or injected into SQL queries, or if user-controlled data is outputted without sanitization. Developers should prioritize addressing these immediate code security issues.
Key Concerns
- Uses unserialize without proper checks
- SQL queries not using prepared statements
- No output escaping on any outputs
- No nonce checks found
- Only one capability check found
Media Post Permalink Security Vulnerabilities
Media Post Permalink Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Media Post Permalink Attack Surface
WordPress Hooks 3
Maintenance & Trust
Media Post Permalink Maintenance & Trust
Maintenance Signals
Community Trust
Media Post Permalink Alternatives
Disable Media Permalink by Hardweb.it
disable-media-permalink-by-hardweb-it
Completely disable the Media Permalink generated by WP.
Auto URL
auto-url
Auto URL generates customized permalinks according to post types, categories and tags
Disable Media Pages
disable-media-pages
Completely remove "attachment" pages for WordPress media. Improve SEO and prevent conflicts between page and image permalinks.
Media Deduper
media-deduper
Save disk space and bring some order to the chaos of your media library by removing and preventing duplicate files.
DX Delete Attached Media
dx-delete-attached-media
Automatically deletes attached media from posts and custom post types added via the Media button.
Media Post Permalink Developer Profile
7 plugins · 116K total installs
How We Detect Media Post Permalink
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-post-permalink/css/admin-style.min.cssmedia-post-permalink/style.css?ver=media-post-permalink/script.js?ver=HTML / DOM Fingerprints
media-post-admin-tableid="media-post-permalink"id="post_prefic_name"