
Remove Old Slug For Post/Pages Security & Risk Analysis
wordpress.org/plugins/remove-old-slug-for-postpagesThis plugin used to remove the old slugs of post and pages.
Is Remove Old Slug For Post/Pages Safe to Use in 2026?
Generally Safe
Score 85/100Remove Old Slug For Post/Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "remove-old-slug-for-postpages" v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having a minimal attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authorization. Furthermore, it avoids dangerous functions, file operations, and external HTTP requests. The high percentage of SQL queries using prepared statements and properly escaped outputs are also encouraging signs.
However, several concerns are raised by the code analysis. The lack of nonce checks is a significant weakness, especially considering the 3 taint flows analyzed, 2 of which are of high severity. While the total number of flows is small, high-severity issues with unsanitized paths are concerning. The absence of capability checks further amplifies this risk, as these flows could potentially be exploited by unauthenticated users. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong indicator of past security awareness or luck. Nonetheless, the presence of high-severity taint flows without corresponding security checks warrants attention.
In conclusion, while the plugin has a small attack surface and generally good coding practices regarding SQL and output escaping, the identified high-severity taint flows, coupled with a complete lack of nonce and capability checks, present a notable risk. The clean vulnerability history is a positive, but it does not negate the immediate security concerns identified in the static analysis.
Key Concerns
- High severity taint flows without sanitization
- High severity taint flows without sanitization
- No nonce checks
- No capability checks
- SQL queries without prepared statements (45%)
- Output not properly escaped (14%)
Remove Old Slug For Post/Pages Security Vulnerabilities
Remove Old Slug For Post/Pages Release Timeline
Remove Old Slug For Post/Pages Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Remove Old Slug For Post/Pages Attack Surface
WordPress Hooks 3
Maintenance & Trust
Remove Old Slug For Post/Pages Maintenance & Trust
Maintenance Signals
Community Trust
Remove Old Slug For Post/Pages Alternatives
Remove Old Slug For Post/Pages Developer Profile
3 plugins · 120 total installs
How We Detect Remove Old Slug For Post/Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
remove-old-slug-for-postpages/remove_old_slug.php?ver=1.0