R3DF Multisite Blog Slug Remover Security & Risk Analysis

wordpress.org/plugins/r3df-multisite-blog-slug-remover

Removes the '/blog' slug from the main site permalinks in a multisite.

10 active installs v1.0.0 PHP + WP 4.1+ Updated Apr 10, 2015
blogblog-slugpermalinkpermalinksslug
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is R3DF Multisite Blog Slug Remover Safe to Use in 2026?

Generally Safe

Score 85/100

R3DF Multisite Blog Slug Remover has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "r3df-multisite-blog-slug-remover" plugin v1.0.0 exhibits a seemingly strong security posture at first glance due to the absence of known vulnerabilities and a lack of identified critical code signals such as dangerous functions, SQL injection risks, or taint flows. The static analysis indicates a very small attack surface with no apparent entry points that are unprotected. Furthermore, the plugin does not perform file operations or external HTTP requests, reducing potential avenues for attack.

However, a significant concern arises from the output escaping. With 0% of outputs being properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. If any user-supplied data is ever processed and displayed without proper sanitization, an attacker could inject malicious scripts. The complete absence of nonce and capability checks, while not directly exploitable without entry points, indicates a lack of robust security best practices. The history of zero vulnerabilities is positive, but it is overshadowed by the critical flaw in output escaping, which could lead to future security incidents.

In conclusion, while the plugin currently has no known CVEs and a minimal attack surface, the critical lack of output escaping is a major weakness that significantly elevates its risk profile. The plugin's code should be reviewed and updated to ensure all output is properly escaped to prevent XSS attacks.

Key Concerns

  • 0% of outputs properly escaped (XSS risk)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

R3DF Multisite Blog Slug Remover Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

R3DF Multisite Blog Slug Remover Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

R3DF Multisite Blog Slug Remover Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

R3DF Multisite Blog Slug Remover Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initr3df-mulstisite-blog-slug-remover.php:64
actionin_admin_headerr3df-mulstisite-blog-slug-remover.php:74
actionin_admin_footerr3df-mulstisite-blog-slug-remover.php:134
Maintenance & Trust

R3DF Multisite Blog Slug Remover Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedApr 10, 2015
PHP min version
Downloads4K

Community Trust

Rating96/100
Number of ratings8
Active installs10
Developer Profile

R3DF Multisite Blog Slug Remover Developer Profile

Rick Radko

6 plugins · 370 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect R3DF Multisite Blog Slug Remover

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about R3DF Multisite Blog Slug Remover