
Slugs Manager: Delete Old Permalinks from WordPress Database Security & Risk Analysis
wordpress.org/plugins/remove-old-slugspermalinksScan & remove old or outdated slugs (permalinks) in Wordpress, keep your database optimized & your URLs SEO-friendly.
Is Slugs Manager: Delete Old Permalinks from WordPress Database Safe to Use in 2026?
Generally Safe
Score 100/100Slugs Manager: Delete Old Permalinks from WordPress Database has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'remove-old-slugspermalinks' plugin v2.8.1 exhibits a generally strong security posture based on the static analysis, with no identified direct entry points for attackers such as unprotected AJAX handlers, REST API routes, or shortcodes. The code also demonstrates good practices in SQL query handling, with all queries using prepared statements, and a reasonable number of nonce and capability checks are in place. File operations and external HTTP requests are notably absent, further reducing potential attack vectors.
However, a significant concern arises from the vulnerability history. The plugin has a known medium severity Cross-Site Request Forgery (CSRF) vulnerability that was patched relatively recently. The fact that CSRF vulnerabilities have been a recurring issue, even if resolved, suggests a potential for oversight in handling user actions that might be exploited if not carefully protected. While the current analysis shows no critical or high severity issues, and the attack surface is zero, the historical pattern of CSRF vulnerabilities warrants careful monitoring and a cautious approach.
In conclusion, the plugin demonstrates many positive security attributes in its current version, with a clean static analysis report. The primary weakness lies in its past vulnerability history, specifically concerning CSRF. While the latest version seems to have addressed these, ongoing vigilance and a thorough review of how user-initiated actions are handled are recommended to prevent recurrence of similar issues.
Key Concerns
- Known past medium severity CSRF vulnerability
- 74% of output properly escaped
Slugs Manager: Delete Old Permalinks from WordPress Database Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Slugs Manager <= 2.6.7 - Cross-Site Request Forgery
Slugs Manager: Delete Old Permalinks from WordPress Database Release Timeline
Slugs Manager: Delete Old Permalinks from WordPress Database Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Slugs Manager: Delete Old Permalinks from WordPress Database Attack Surface
WordPress Hooks 20
Maintenance & Trust
Slugs Manager: Delete Old Permalinks from WordPress Database Maintenance & Trust
Maintenance Signals
Community Trust
Slugs Manager: Delete Old Permalinks from WordPress Database Alternatives
Slugs Manager: Delete Old Permalinks from WordPress Database Developer Profile
64 plugins · 137K total installs
How We Detect Slugs Manager: Delete Old Permalinks from WordPress Database
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/remove-old-slugspermalinks/assets/css/remove-old-slugs-permalinks.css/wp-content/plugins/remove-old-slugspermalinks/assets/js/remove-old-slugs-permalinks.jsremove-old-slugs-permalinks/assets/css/remove-old-slugs-permalinks.css?ver=remove-old-slugs-permalinks/assets/js/remove-old-slugs-permalinks.js?ver=HTML / DOM Fingerprints
alg-sm-remove-old-slugs-noncealg_sm_flush_rewrite_rulesalg_sm_flush_rewrite_rules_noncealg-sm-flush-rewrite-rulesalg_slugs_manager_remove_old_slugsalg_slugs_manager_remove_selected_old_slugsalg_sm_remove_old_slugs_nonce+2 morealg_slugs_manager