Redirect.txt Security & Risk Analysis

wordpress.org/plugins/redirect-txt

Manage 301 & 302 redirects easily. No posts creation bloat, just a simple list.

0 active installs v0.2.5 PHP 7.2+ WP 6.2+ Updated Unknown
301404redirectredirectionredirects
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Redirect.txt Safe to Use in 2026?

Generally Safe

Score 100/100

Redirect.txt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "redirect-txt" v0.2.5 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests further reduces the potential attack surface. Crucially, the plugin also appears to have a clean vulnerability history with zero known CVEs, indicating a lack of historical security issues.

While the static analysis reports zero entry points and zero unprotected entry points, and the taint analysis reveals no concerning flows, the absence of nonce checks and the presence of capability checks (though not explicitly detailed how they are implemented) warrant a slight degree of caution. The zero-day potential cannot be entirely ruled out for any software, but based solely on the provided data, the plugin is remarkably secure. The plugin's strengths lie in its clean code and lack of known vulnerabilities. The only potential area for minor improvement, though not a direct flaw presented here, is the overall lack of explicitly stated security mechanisms like nonce checks on any potential interaction points, even if they are currently reported as zero.

In conclusion, "redirect-txt" v0.2.5 appears to be a very secure plugin. Its developers have clearly prioritized security by avoiding common pitfalls like raw SQL and unescaped output. The absence of historical vulnerabilities further reinforces this assessment. The lack of detected vulnerabilities in static analysis, combined with a clean history, suggests a low-risk plugin for WordPress users.

Vulnerabilities
None known

Redirect.txt Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Redirect.txt Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Redirect.txt Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_menuclasses\class-admin.php:20
filteradmin_body_classclasses\class-admin.php:22
actionadmin_enqueue_scriptsclasses\class-assets.php:20
filterredirect_txt_update_settingsclasses\class-logs.php:22
actionadmin_initclasses\class-logs.php:31
actiontemplate_redirectclasses\class-logs.php:37
actionredirect_txt_redirect_hitclasses\class-logs.php:38
actionparse_requestclasses\class-redirects.php:31
actionwpclasses\class-redirects.php:35
filterallowed_redirect_hostsclasses\class-redirects.php:377
actionrest_api_initclasses\class-rest.php:34
actioninitredirect-txt.php:79
actionplugins_loadedredirect-txt.php:125
Maintenance & Trust

Redirect.txt Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Redirect.txt Developer Profile

Danny van Kooten

90 plugins · 2.1M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
522 days
View full developer profile
Detection Fingerprints

How We Detect Redirect.txt

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/redirect-txt/build/admin.js/wp-content/plugins/redirect-txt/build/style-admin.css
Script Paths
/wp-content/plugins/redirect-txt/build/admin.js
Version Parameters
redirect-txt/build/admin.js?ver=redirect-txt/build/style-admin.css?ver=

HTML / DOM Fingerprints

JS Globals
redirectTxtAdminData
REST Endpoints
/wp-json/redirect-txt/v1/update_rules//wp-json/redirect-txt/v1/update_settings/
FAQ

Frequently Asked Questions about Redirect.txt