Redirects for Htaccess Security & Risk Analysis

wordpress.org/plugins/redirects-for-htaccess

Generates redirect code for .htaccess file

0 active installs v1.0.2 PHP + WP 6.0.0+ Updated Unknown
301htaccessredirect
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Redirects for Htaccess Safe to Use in 2026?

Generally Safe

Score 100/100

Redirects for Htaccess has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "redirects-for-htaccess" plugin v1.0.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, reliance on prepared statements for any SQL interactions (though none were found), and 100% output escaping indicate excellent coding practices regarding common web vulnerabilities. Furthermore, the plugin appears to have a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. The presence of a nonce check, while no explicit capability checks were noted, is a positive sign for authorization. The complete lack of known CVEs, both historical and current, further strengthens this assessment, suggesting a well-maintained and secure plugin.

However, the absence of capability checks is a potential concern, as it might imply that some actions, if they were to exist, could be performed by any logged-in user without proper authorization. While the current code analysis shows no direct vulnerabilities stemming from this, it represents a gap in robust access control. The taint analysis showing zero flows is excellent, but this is contingent on the thoroughness of the analysis itself. Given the plugin's current state, the risk is very low, but the lack of explicit capability checks should be noted as a minor area for potential improvement in future development.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

Redirects for Htaccess Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Redirects for Htaccess Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
20 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped20 total outputs
Attack Surface

Redirects for Htaccess Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedactions.php:18
actionplugins_loadedactions.php:19
actionplugins_loadedactions.php:20
actionadmin_menuincludes\class-admin-page.php:44
filterplugin_action_linksincludes\class-admin-page.php:45
actionadmin_enqueue_scriptsincludes\class-assets.php:28
Maintenance & Trust

Redirects for Htaccess Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version
Downloads594

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Redirects for Htaccess Developer Profile

Pavel

8 plugins · 30 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Redirects for Htaccess

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/redirects-for-htaccess/assets/css/admin.css/wp-content/plugins/redirects-for-htaccess/assets/js/admin.js
Version Parameters
redirects-for-htaccess-css?ver=redirects-for-htaccess-js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Redirects for Htaccess