
Redirect Old Slugs Security & Risk Analysis
wordpress.org/plugins/redirect-old-slugsAllows you to change your post slugs without breaking your permalinks.
Is Redirect Old Slugs Safe to Use in 2026?
Generally Safe
Score 85/100Redirect Old Slugs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "redirect-old-slugs" plugin v0.3 exhibits a mixed security posture. On the positive side, the static analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no reported dangerous functions, file operations, or external HTTP requests, and the single SQL query uses prepared statements, indicating good practices in these areas. The absence of any known vulnerabilities or CVEs in its history is also a strong positive indicator, suggesting a well-maintained or less complex plugin.
However, significant concerns arise from the output escaping. With 100% of outputs not properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users that originates from user input or is not rigorously sanitized before output could be exploited by attackers to inject malicious scripts. The complete absence of nonce checks and capability checks, especially if any entry points were to exist (even if currently none are reported), would represent a critical security gap, allowing unauthenticated or unauthorized actions.
In conclusion, while the plugin's attack surface and known vulnerability history are currently very low, the lack of output escaping presents a serious and immediate risk. Developers should prioritize addressing the unescaped output to prevent potential XSS attacks. The absence of checks like nonces and capabilities, although not directly exploitable with the current static analysis findings, points to a potential for future vulnerabilities if the plugin's functionality expands.
Key Concerns
- Unescaped output
Redirect Old Slugs Security Vulnerabilities
Redirect Old Slugs Code Analysis
SQL Query Safety
Output Escaping
Redirect Old Slugs Attack Surface
WordPress Hooks 4
Maintenance & Trust
Redirect Old Slugs Maintenance & Trust
Maintenance Signals
Community Trust
Redirect Old Slugs Alternatives
VK Link Target Controller
vk-link-target-controller
Redirect your visitors to another page than the post content when they click on the post title.
Redirect
simple-redirect
Easily redirect any post or page to another page with a dropdown menu or by manually typing in a URL. Check out the screenshots.
WP Change Custom Posts Slugs
wp-change-custom-post-slug
The plugin allows to can easily change slug of custom post types from WordPress admin panel.
Publish And Redirect To Add New Post
publish-and-redirect-to-add-new-post
Redirects to 'Add new post' page after 'save draft' or 'publish post' for faster adding mulitple posts.
Kandeshop Duplicate Post Manager
kandeshop-duplicate-post-manager
Manage and clean up duplicate WordPress posts with ease. Delete duplicates, assign 301 redirects, and generate .htaccess rules.
Redirect Old Slugs Developer Profile
29 plugins · 176K total installs
How We Detect Redirect Old Slugs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
txfx-old-slug<input type="hidden" id="txfx-old-slug" name="txfx-old-slug" value="