
Redirector Mod Security & Risk Analysis
wordpress.org/plugins/redirector-modRedirect a page to an URL or WordPress page.
Is Redirector Mod Safe to Use in 2026?
Generally Safe
Score 85/100Redirector Mod has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The redirector-mod plugin v1.0 presents a mixed security picture. On the positive side, the plugin exhibits strong practices regarding database interactions, with all SQL queries utilizing prepared statements, which is excellent for preventing SQL injection vulnerabilities. Furthermore, there's no history of known vulnerabilities (CVEs) for this plugin, suggesting a relatively stable and well-maintained codebase in its past. The static analysis also indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. File operations and external HTTP requests are also absent, further limiting potential entry points.
However, a significant concern arises from the output escaping. 100% of the identified output operations are not properly escaped, which is a critical weakness. This means that any data displayed to users or in administrative interfaces could be vulnerable to Cross-Site Scripting (XSS) attacks if that data originates from an untrusted source. Additionally, the taint analysis revealed two flows with unsanitized paths, which, while not reaching critical or high severity in this analysis, indicate potential weaknesses that could be exploited in conjunction with other factors. The complete lack of nonce and capability checks on any identified entry points (even though the attack surface is currently zero) is also a notable gap, suggesting that if entry points were added in future versions without proper authorization checks, the plugin would be immediately vulnerable. The absence of any detected vulnerabilities in its history is a positive indicator, but it should not overshadow the clear and present risk of unescaped output.
Key Concerns
- All outputs are unescaped
- Unsanitized paths in taint flows
- No nonce checks
- No capability checks
Redirector Mod Security Vulnerabilities
Redirector Mod Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Redirector Mod Attack Surface
WordPress Hooks 3
Maintenance & Trust
Redirector Mod Maintenance & Trust
Maintenance Signals
Community Trust
Redirector Mod Alternatives
IP2Location Redirection
ip2location-redirection
Redirects visitors to a blog page or a predefined URL based on their country and region geolocated using IP address.
404 to 301 – Redirect, Log and Notify 404 Errors
404-to-301
Automatically redirect, log and notify all 404 page errors to any page using 301 redirect for SEO. No more 404 Errors in WebMaster tool.
Page Links To
page-links-to
Lets you make a WordPress page (or port or other content type) link to a URL of your choosing (on your site, or on another site), instead of its norma …
Redirect 404 to Homepage
404-to-homepage
Redirect 404 missing pages to the homepage using SEO 301 redirection. Super lightweight!
VK Link Target Controller
vk-link-target-controller
Redirect your visitors to another page than the post content when they click on the post title.
Redirector Mod Developer Profile
5 plugins · 770 total installs
How We Detect Redirector Mod
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/redirector/redirector.css/wp-content/plugins/redirector/redirector.js/wp-content/plugins/redirector/redirector.jsHTML / DOM Fingerprints
redirect_settingsredirect_settings_pageredirect_settings_urlredirect_settings_childredirect_typeredirectorredirector_urlredirector_type_set