
Legacy URL Suffix & SEO Preserver Security & Risk Analysis
wordpress.org/plugins/php-to-pagesMaintain SEO rankings with custom URL suffixes like .php or .html. Perfect for legacy site migrations, fixing 404s, and preserving link juice.
Is Legacy URL Suffix & SEO Preserver Safe to Use in 2026?
Generally Safe
Score 100/100Legacy URL Suffix & SEO Preserver has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "php-to-pages" v2.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities, including critical or high severity ones, is a significant positive indicator. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which contribute to a reduced attack surface. The plugin also has no registered AJAX handlers, REST API routes, shortcodes, or cron events, further limiting potential entry points for attackers.
However, a notable concern lies in the output escaping. With 38% of outputs properly escaped, there's a significant portion (62%) that remains unescaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without proper sanitization. The lack of any capability checks or nonce checks across its (albeit small) attack surface also means that if any entry points were to be introduced in the future, they might lack essential authorization and integrity checks.
In conclusion, "php-to-pages" v2.1 demonstrates a commendable effort in avoiding common pitfalls like vulnerable SQL queries and dangerous functions. Its vulnerability history is clean, suggesting responsible development practices. The primary area requiring attention is the incomplete output escaping, which represents a tangible risk. Addressing this would significantly bolster the plugin's security.
Key Concerns
- Insufficient output escaping
Legacy URL Suffix & SEO Preserver Security Vulnerabilities
Legacy URL Suffix & SEO Preserver Release Timeline
Legacy URL Suffix & SEO Preserver Code Analysis
Output Escaping
Legacy URL Suffix & SEO Preserver Attack Surface
WordPress Hooks 16
Maintenance & Trust
Legacy URL Suffix & SEO Preserver Maintenance & Trust
Maintenance Signals
Community Trust
Legacy URL Suffix & SEO Preserver Alternatives
301 Redirects – Redirect Manager
eps-301-redirects
Manage 301 & 302 redirects. Simple redirection & redirects validation. Includes redirect stats & 404 error log.
Nginx Helper
nginx-helper
Cleans nginx's fastcgi/proxy cache or redis-cache whenever a post is edited/published. Also does a few more things.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Permalink Manager Lite
permalink-manager
Permalink Manager enhances WordPress’s built-in URL system, allowing you to change the URLs of native and custom post types and taxonomies.
Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More
simple-301-redirects
Simple 301 Redirects provides an easy method of redirecting requests to another page on your site or elsewhere on the web.
Legacy URL Suffix & SEO Preserver Developer Profile
3 plugins · 810 total installs
How We Detect Legacy URL Suffix & SEO Preserver
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.