Premmerce Redirect Manager Security & Risk Analysis

wordpress.org/plugins/premmerce-redirect-manager

The Premmerce Redirect Manager enables you to create 301 and 302 redirects and to set up the automatic redirects for the deleted products in the WooCo …

600 active installs v1.0.13 PHP 5.6+ WP 4.8+ Updated Feb 18, 2026
301-redirects-managerwoocommerce-redirect-managerwordpress-redirect-manager
95
A · Safe
CVEs total4
Unpatched0
Last CVEMar 20, 2026
Safety Verdict

Is Premmerce Redirect Manager Safe to Use in 2026?

Generally Safe

Score 95/100

Premmerce Redirect Manager has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Mar 20, 2026Updated 2mo ago
Risk Assessment

The 'premmerce-redirect-manager' plugin v1.0.13 exhibits a mixed security posture. While it has a small attack surface with no directly unprotected entry points identified, and a majority of its SQL queries utilize prepared statements, several concerning signals are present. The static analysis reveals that a significant portion of output is not properly escaped (only 27%), and importantly, all analyzed taint flows (5 out of 5) have unsanitized paths, with 3 classified as high severity. This indicates a strong potential for input validation and output sanitization weaknesses that could lead to vulnerabilities.

The vulnerability history, with 3 known medium severity CVEs primarily related to CSRF and XSS, and the most recent one in November 2023, reinforces these concerns. Although there are currently no unpatched CVEs, the recurring nature of these vulnerability types suggests systemic issues with input handling and output escaping within the plugin that have been exploited in the past. The presence of bundled libraries like Select2 and Freemius v1.0 also warrants attention, as outdated versions of these libraries can introduce their own security risks, although specific version details and associated CVEs are not provided here.

In conclusion, while the plugin demonstrates some good practices in terms of limiting its attack surface and using prepared statements for SQL, the high number of unsanitized taint flows and the historical prevalence of XSS and CSRF vulnerabilities are significant red flags. The low rate of properly escaped output directly contributes to the risk of XSS. The plugin requires careful review and potential remediation to address the identified taint flow issues and to ensure more robust output sanitization to prevent future security incidents.

Key Concerns

  • High severity taint flows with unsanitized paths
  • Low percentage of properly escaped output
  • Bundled Select2 library
  • Bundled Freemius library
  • Medium severity CVEs in history
Vulnerabilities
4 published

Premmerce Redirect Manager Security Vulnerabilities

CVEs by Year

3 CVEs in 2023
2023
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2026-32541medium · 4.3Missing Authorization

Premmerce Redirect Manager <= 1.0.12 - Missing Authorization

Mar 20, 2026 Patched in 1.0.13 (8d)
WF-b3d4f658-e9ce-490b-bcaa-1061a463dbb2-premmerce-redirect-managermedium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Premmerce Redirect Manager <= 1.0.11 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 13, 2023 Patched in 1.0.12 (71d)
CVE-2023-23787medium · 4.3Cross-Site Request Forgery (CSRF)

Premmerce Redirect Manager <= 1.0.10 - Cross-Site Request Forgery via deleteRedirect()

Mar 30, 2023 Patched in 1.0.11 (299d)
CVE-2023-23789medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Premmerce Redirect Manager <= 1.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 30, 2023 Patched in 1.0.12 (299d)
Code Analysis
Analyzed Mar 16, 2026

Premmerce Redirect Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
9 prepared
Unescaped Output
40
15 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

SQL Query Safety

90% prepared10 total queries

Output Escaping

27% escaped55 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
useRedirect (src\RedirectPlugin.php:66)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Premmerce Redirect Manager Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_get_posts_by_stringsrc\Admin\Admin.php:115
WordPress Hooks 9
actionadmin_menusrc\Admin\Admin.php:103
actionadmin_menusrc\Admin\Admin.php:104
filterpre_trash_postsrc\Admin\Admin.php:107
actionuntrashed_postsrc\Admin\Admin.php:108
actionsave_postsrc\Admin\Admin.php:111
actionadmin_post_premmerce_delete_redirectsrc\Admin\Admin.php:113
actiontemplate_redirectsrc\RedirectPlugin.php:41
actioninitsrc\RedirectPlugin.php:42
filterhide_account_tabsviews\admin\tabs\account.php:13
Maintenance & Trust

Premmerce Redirect Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version5.6
Downloads16K

Community Trust

Rating100/100
Number of ratings2
Active installs600
Alternatives

Premmerce Redirect Manager Alternatives

No alternatives data available yet.

Developer Profile

Premmerce Redirect Manager Developer Profile

Premmerce

14 plugins · 60K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
401 days
View full developer profile
Detection Fingerprints

How We Detect Premmerce Redirect Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/premmerce-redirect-manager/assets/css/frontend.css/wp-content/plugins/premmerce-redirect-manager/assets/js/frontend.js/wp-content/plugins/premmerce-redirect-manager/assets/css/admin.css/wp-content/plugins/premmerce-redirect-manager/assets/js/admin.js
Version Parameters
premmerce-redirect-manager/assets/css/frontend.css?ver=premmerce-redirect-manager/assets/js/frontend.js?ver=premmerce-redirect-manager/assets/css/admin.css?ver=premmerce-redirect-manager/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
premmerce-redirect-manager-tablepremmerce-redirect-manager-btn-successpremmerce-redirect-manager-btn-dangerpremmerce-redirect-manager-btn-warningpremmerce-redirect-manager-add-redirect-formpremmerce-redirect-manager-input-group
Data Attributes
data-type="redirect"data-old-urldata-new-urldata-redirect-method
JS Globals
premmerceRedirectManager
REST Endpoints
/wp-json/premmerce-redirect-manager/v1/redirects/wp-json/premmerce-redirect-manager/v1/redirects/(?P<id>[\d]+)
FAQ

Frequently Asked Questions about Premmerce Redirect Manager