
Permalink Editor Security & Risk Analysis
wordpress.org/plugins/permalink-editorFully customise the permalink for an individual page or post and globally set the permalink structure for pages, categories, tags or authors.
Is Permalink Editor Safe to Use in 2026?
Generally Safe
Score 85/100Permalink Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'permalink-editor' plugin version 0.2.12 presents a mixed security posture. On one hand, the static analysis reveals no direct entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, file operations, and external HTTP requests are all positive indicators. Furthermore, the presence of one nonce check and one capability check suggests an attempt at securing some operations.
However, a significant concern arises from the output escaping. With 22 total outputs and 0% properly escaped, there's a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data that is displayed to users, especially if it originates from user input or external sources, could be exploited to inject malicious scripts. The taint analysis also shows a single flow analyzed, but without any sanitization issues, which is good, but the lack of extensive taint analysis could mean other unanalyzed flows exist.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This could indicate robust development practices or simply a lack of targeted attacks or discovery. Nevertheless, the outstanding issue with output escaping remains a critical weakness that needs immediate attention. While the plugin has strengths in its limited attack surface and use of prepared statements, the unescaped output is a significant liability.
Key Concerns
- Unescaped output detected
Permalink Editor Security Vulnerabilities
Permalink Editor Code Analysis
Output Escaping
Data Flow Analysis
Permalink Editor Attack Surface
WordPress Hooks 9
Maintenance & Trust
Permalink Editor Maintenance & Trust
Maintenance Signals
Community Trust
Permalink Editor Alternatives
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Admin Slug Column
admin-slug-column
Adds a URL path column to all admin post type edit screens. Works with posts, pages, and any custom post type including WooCommerce products.
Custom Fields Permalink 2
custom-fields-permalink-redux
Plugin allows to use post's custom fields values in permalink structure by adding %field_fieldname%, for posts, pages and custom post types.
WP Permastructure
wp-permastructure
Adds the ability to configure permalinks for custom post types using rewrite tags like %post_id% and %author%.
Add Hierarchy (parent) to post
add-hierarchy-parent-to-post
PLUGIN IS DISCONTINUED!
Permalink Editor Developer Profile
1 plugin · 1K total installs
How We Detect Permalink Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/permalink-editor/css/admin.css/wp-content/plugins/permalink-editor/css/style.css/wp-content/plugins/permalink-editor/js/admin.js/wp-content/plugins/permalink-editor/js/admin.jspermalink-editor/css/admin.css?ver=permalink-editor/css/style.css?ver=permalink-editor/js/admin.js?ver=HTML / DOM Fingerprints
custom_permalink_inputdata-permalink-editor-idpermalink_editor_admin