Slugs Manager: Delete Old Permalinks from WordPress Database Security & Risk Analysis

wordpress.org/plugins/remove-old-slugspermalinks

Scan & remove old or outdated slugs (permalinks) in Wordpress, keep your database optimized & your URLs SEO-friendly.

4K active installs v2.8.1 PHP + WP 3.5.1+ Updated Sep 23, 2025
old-slugsregenerate-slugsslugs-manager
100
A · Safe
CVEs total1
Unpatched0
Last CVEMar 29, 2024
Safety Verdict

Is Slugs Manager: Delete Old Permalinks from WordPress Database Safe to Use in 2026?

Generally Safe

Score 100/100

Slugs Manager: Delete Old Permalinks from WordPress Database has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Mar 29, 2024Updated 7mo ago
Risk Assessment

The 'remove-old-slugspermalinks' plugin v2.8.1 exhibits a generally strong security posture based on the static analysis, with no identified direct entry points for attackers such as unprotected AJAX handlers, REST API routes, or shortcodes. The code also demonstrates good practices in SQL query handling, with all queries using prepared statements, and a reasonable number of nonce and capability checks are in place. File operations and external HTTP requests are notably absent, further reducing potential attack vectors.

However, a significant concern arises from the vulnerability history. The plugin has a known medium severity Cross-Site Request Forgery (CSRF) vulnerability that was patched relatively recently. The fact that CSRF vulnerabilities have been a recurring issue, even if resolved, suggests a potential for oversight in handling user actions that might be exploited if not carefully protected. While the current analysis shows no critical or high severity issues, and the attack surface is zero, the historical pattern of CSRF vulnerabilities warrants careful monitoring and a cautious approach.

In conclusion, the plugin demonstrates many positive security attributes in its current version, with a clean static analysis report. The primary weakness lies in its past vulnerability history, specifically concerning CSRF. While the latest version seems to have addressed these, ongoing vigilance and a thorough review of how user-initiated actions are handled are recommended to prevent recurrence of similar issues.

Key Concerns

  • Known past medium severity CSRF vulnerability
  • 74% of output properly escaped
Vulnerabilities
1 published

Slugs Manager: Delete Old Permalinks from WordPress Database Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-30536medium · 4.3Cross-Site Request Forgery (CSRF)

Slugs Manager <= 2.6.7 - Cross-Site Request Forgery

Mar 29, 2024 Patched in 2.7.0 (6d)
Version History

Slugs Manager: Delete Old Permalinks from WordPress Database Release Timeline

v2.8.1Current
v2.8.0
v2.7.5
v2.7.4
v2.7.3
v2.7.2
v2.7.1
v2.7.0
v2.6.71 CVE
v2.6.61 CVE
v2.6.51 CVE
v2.6.41 CVE
v2.6.31 CVE
v2.6.21 CVE
v2.6.11 CVE
v2.6.01 CVE
v2.5.11 CVE
v2.5.01 CVE
v2.4.11 CVE
v2.4.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Slugs Manager: Delete Old Permalinks from WordPress Database Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
5
14 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

74% escaped19 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_settings (includes\settings\class-alg-slugs-manager-settings.php:63)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Slugs Manager: Delete Old Permalinks from WordPress Database Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_initincludes\class-alg-slugs-manager-core.php:31
actionadmin_initincludes\class-alg-slugs-manager-core.php:32
actionadmin_noticesincludes\class-alg-slugs-manager-core.php:52
actionadmin_noticesincludes\class-alg-slugs-manager-core.php:58
actionadmin_noticesincludes\class-alg-slugs-manager-core.php:64
actionadmin_noticesincludes\class-alg-slugs-manager-core.php:119
actionadmin_noticesincludes\class-alg-slugs-manager-core.php:125
actionadmin_noticesincludes\class-alg-slugs-manager-core.php:141
actionadmin_noticesincludes\class-alg-slugs-manager-core.php:154
actionadmin_noticesincludes\class-alg-slugs-manager-core.php:156
actioninitincludes\class-alg-slugs-manager.php:76
actioninitincludes\class-alg-slugs-manager.php:135
actionadmin_initincludes\class-alg-slugs-manager.php:142
actionadmin_menuincludes\settings\class-alg-slugs-manager-settings.php:26
actionadmin_initincludes\settings\class-alg-slugs-manager-settings.php:27
actionadmin_footerincludes\settings\class-alg-slugs-manager-settings.php:28
actionadmin_noticesincludes\settings\class-alg-slugs-manager-settings.php:71
actionadmin_noticesincludes\settings\class-alg-slugs-manager-settings.php:89
actionadmin_noticesincludes\settings\class-alg-slugs-manager-settings.php:111
actionplugins_loadedremove-old-slugs.php:55
Maintenance & Trust

Slugs Manager: Delete Old Permalinks from WordPress Database Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 23, 2025
PHP min version
Downloads96K

Community Trust

Rating84/100
Number of ratings13
Active installs4K
Developer Profile

Slugs Manager: Delete Old Permalinks from WordPress Database Developer Profile

WPFactory

64 plugins · 137K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect Slugs Manager: Delete Old Permalinks from WordPress Database

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/remove-old-slugspermalinks/assets/css/remove-old-slugs-permalinks.css/wp-content/plugins/remove-old-slugspermalinks/assets/js/remove-old-slugs-permalinks.js
Version Parameters
remove-old-slugs-permalinks/assets/css/remove-old-slugs-permalinks.css?ver=remove-old-slugs-permalinks/assets/js/remove-old-slugs-permalinks.js?ver=

HTML / DOM Fingerprints

CSS Classes
alg-sm-remove-old-slugs-nonce
Data Attributes
alg_sm_flush_rewrite_rulesalg_sm_flush_rewrite_rules_noncealg-sm-flush-rewrite-rulesalg_slugs_manager_remove_old_slugsalg_slugs_manager_remove_selected_old_slugsalg_sm_remove_old_slugs_nonce+2 more
JS Globals
alg_slugs_manager
FAQ

Frequently Asked Questions about Slugs Manager: Delete Old Permalinks from WordPress Database