Permalinks to Category/Permalinks Security & Risk Analysis

wordpress.org/plugins/permalinks-to-categorypermalinks

The plugin automatically redirects users who have accessed a blog post link without the category to the one which has the category and therefore avoid …

100 active installs v1.0.2 PHP + WP 2.6+ Updated Dec 3, 2014
404permalinkpermalinksredirectionsearch
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Permalinks to Category/Permalinks Safe to Use in 2026?

Generally Safe

Score 85/100

Permalinks to Category/Permalinks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "permalinks-to-categorypermalinks" plugin version 1.0.2 exhibits a generally positive security posture based on the provided static analysis. There are no identified attack surface entry points, no dangerous functions are used, and all SQL queries are properly prepared. The absence of file operations and external HTTP requests further reduces potential risks. However, a significant concern lies in the output escaping, where only 42% of the outputs are properly escaped, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks.

Furthermore, the plugin lacks nonce checks and capability checks, which are fundamental security mechanisms for validating user actions and permissions. While the taint analysis shows no identified flows with unsanitized paths, the lack of proper output escaping and missing authorization checks can still lead to vulnerabilities. The plugin also has no recorded vulnerability history, suggesting a lack of past exploitation or discovery, which could be due to its small footprint or effective security practices in the past. However, this absence of history should not be interpreted as guaranteed future security, especially given the identified weaknesses.

In conclusion, while the plugin avoids common pitfalls like raw SQL queries and large attack surfaces, the critical deficiency in output escaping and the absence of nonce and capability checks represent significant security risks that require immediate attention. The potential for XSS vulnerabilities due to improper output handling is a substantial weakness that outweighs the strengths observed in other areas of the static analysis.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Permalinks to Category/Permalinks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Permalinks to Category/Permalinks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped12 total outputs
Attack Surface

Permalinks to Category/Permalinks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actiontemplate_redirectplugin.php:29
actionadmin_menuplugin.php:30
actionwp_footerplugin.php:31
filterplugin_action_linksplugin.php:34
Maintenance & Trust

Permalinks to Category/Permalinks Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedDec 3, 2014
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings9
Active installs100
Developer Profile

Permalinks to Category/Permalinks Developer Profile

Svetoslav Marinov

26 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
722 days
View full developer profile
Detection Fingerprints

How We Detect Permalinks to Category/Permalinks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Permalinks to Category/Permalinks