
Premmerce Redirect Manager Security & Risk Analysis
wordpress.org/plugins/premmerce-redirect-managerThe Premmerce Redirect Manager enables you to create 301 and 302 redirects and to set up the automatic redirects for the deleted products in the WooCo …
Is Premmerce Redirect Manager Safe to Use in 2026?
Generally Safe
Score 95/100Premmerce Redirect Manager has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'premmerce-redirect-manager' plugin v1.0.13 exhibits a mixed security posture. While it has a small attack surface with no directly unprotected entry points identified, and a majority of its SQL queries utilize prepared statements, several concerning signals are present. The static analysis reveals that a significant portion of output is not properly escaped (only 27%), and importantly, all analyzed taint flows (5 out of 5) have unsanitized paths, with 3 classified as high severity. This indicates a strong potential for input validation and output sanitization weaknesses that could lead to vulnerabilities.
The vulnerability history, with 3 known medium severity CVEs primarily related to CSRF and XSS, and the most recent one in November 2023, reinforces these concerns. Although there are currently no unpatched CVEs, the recurring nature of these vulnerability types suggests systemic issues with input handling and output escaping within the plugin that have been exploited in the past. The presence of bundled libraries like Select2 and Freemius v1.0 also warrants attention, as outdated versions of these libraries can introduce their own security risks, although specific version details and associated CVEs are not provided here.
In conclusion, while the plugin demonstrates some good practices in terms of limiting its attack surface and using prepared statements for SQL, the high number of unsanitized taint flows and the historical prevalence of XSS and CSRF vulnerabilities are significant red flags. The low rate of properly escaped output directly contributes to the risk of XSS. The plugin requires careful review and potential remediation to address the identified taint flow issues and to ensure more robust output sanitization to prevent future security incidents.
Key Concerns
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
- Bundled Select2 library
- Bundled Freemius library
- Medium severity CVEs in history
Premmerce Redirect Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Premmerce Redirect Manager <= 1.0.12 - Missing Authorization
Premmerce Redirect Manager <= 1.0.11 - Authenticated (Administrator+) Stored Cross-Site Scripting
Premmerce Redirect Manager <= 1.0.10 - Cross-Site Request Forgery via deleteRedirect()
Premmerce Redirect Manager <= 1.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Premmerce Redirect Manager Release Timeline
Premmerce Redirect Manager Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Premmerce Redirect Manager Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Premmerce Redirect Manager Maintenance & Trust
Maintenance Signals
Community Trust
Premmerce Redirect Manager Alternatives
No alternatives data available yet.
Premmerce Redirect Manager Developer Profile
14 plugins · 60K total installs
How We Detect Premmerce Redirect Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/premmerce-redirect-manager/assets/css/frontend.css/wp-content/plugins/premmerce-redirect-manager/assets/js/frontend.js/wp-content/plugins/premmerce-redirect-manager/assets/css/admin.css/wp-content/plugins/premmerce-redirect-manager/assets/js/admin.jspremmerce-redirect-manager/assets/css/frontend.css?ver=premmerce-redirect-manager/assets/js/frontend.js?ver=premmerce-redirect-manager/assets/css/admin.css?ver=premmerce-redirect-manager/assets/js/admin.js?ver=HTML / DOM Fingerprints
premmerce-redirect-manager-tablepremmerce-redirect-manager-btn-successpremmerce-redirect-manager-btn-dangerpremmerce-redirect-manager-btn-warningpremmerce-redirect-manager-add-redirect-formpremmerce-redirect-manager-input-groupdata-type="redirect"data-old-urldata-new-urldata-redirect-methodpremmerceRedirectManager/wp-json/premmerce-redirect-manager/v1/redirects/wp-json/premmerce-redirect-manager/v1/redirects/(?P<id>[\d]+)