
Nomore404 404 Redirection and Firewall Security & Risk Analysis
wordpress.org/plugins/nomore404-404-redirection-and-firewallNoMore404 is a free WordPress plugin for redirection of 404 pages and simple firewall to block malicious hosts and URLs.
Is Nomore404 404 Redirection and Firewall Safe to Use in 2026?
Generally Safe
Score 85/100Nomore404 404 Redirection and Firewall has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nomore404-404-redirection-and-firewall" plugin v2.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having a limited attack surface with no exposed AJAX handlers, REST API routes, or shortcodes without authentication checks. The plugin also utilizes prepared statements for a high percentage of its SQL queries and incorporates nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities. The vulnerability history is also a strong point, with no recorded CVEs, suggesting a generally stable and secure codebase.
However, several concerns arise from the static analysis. The presence of dangerous functions like `shell_exec` and `exec` is a significant red flag, as these can be exploited for remote code execution if not handled with extreme care and robust input sanitization. The taint analysis reveals that all analyzed flows have unsanitized paths, with one flow identified as high severity. This, combined with only 71% of output being properly escaped, suggests potential avenues for cross-site scripting (XSS) or other injection vulnerabilities.
In conclusion, while the plugin has a clean vulnerability history and good foundational security practices, the identified dangerous functions and unsanitized taint flows present notable risks. Further investigation into how these functions are used and the specifics of the high-severity taint flow is crucial to fully assess the plugin's security. The low percentage of properly escaped output also warrants attention.
Key Concerns
- Presence of dangerous functions (shell_exec, exec)
- All analyzed flows have unsanitized paths
- High severity taint flow found
- Only 71% of output properly escaped
- Bundled library Guzzle
Nomore404 404 Redirection and Firewall Security Vulnerabilities
Nomore404 404 Redirection and Firewall Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Nomore404 404 Redirection and Firewall Attack Surface
WordPress Hooks 17
Scheduled Events 1
Maintenance & Trust
Nomore404 404 Redirection and Firewall Maintenance & Trust
Maintenance Signals
Community Trust
Nomore404 404 Redirection and Firewall Alternatives
301 Redirects – Redirect Manager
eps-301-redirects
Manage 301 & 302 redirects. Simple redirection & redirects validation. Includes redirect stats & 404 error log.
Redirection
redirect-redirection
Redirection
Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More
simple-301-redirects
Simple 301 Redirects provides an easy method of redirecting requests to another page on your site or elsewhere on the web.
301 Redirects & 404 Error Log
301-redirects
Create & manage 301 redirects. Easily test redirects. Includes 404 error log.
SEO Redirection Plugin – 301 Redirect Manager
seo-redirection
SEO Redirection is a powerful redirect manager to manage 301 redirects without requiring knowledge of Apache .htaccess files.
Nomore404 404 Redirection and Firewall Developer Profile
1 plugin · 10 total installs
How We Detect Nomore404 404 Redirection and Firewall
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nomore404-404-redirection-and-firewall/css//wp-content/plugins/nomore404-404-redirection-and-firewall/js//wp-content/plugins/nomore404-404-redirection-and-firewall/js/nomore404.js/wp-content/plugins/nomore404-404-redirection-and-firewall/js/nomore404-admin.jsnomore404-404-redirection-and-firewall/css/nomore404.css?ver=nomore404-404-redirection-and-firewall/js/nomore404.js?ver=nomore404-404-redirection-and-firewall/js/nomore404-admin.js?ver=HTML / DOM Fingerprints
nomore404-status-oknomore404-status-warningnomore404-status-errornomore404-status-criticaldata-urldata-idnomore404_global_varnomore404_arr_obj