
Rewrite Rule Testing Security & Risk Analysis
wordpress.org/plugins/rewrite-testingUnit test your rewrite rules from the WordPress Admin.
Is Rewrite Rule Testing Safe to Use in 2026?
Generally Safe
Score 85/100Rewrite Rule Testing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'rewrite-testing' plugin v0.1.1 exhibits a strong security posture based on the provided static analysis. The complete absence of any entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces its attack surface. Furthermore, the code signals indicate good security practices, with no dangerous functions, all SQL queries utilizing prepared statements, and a very high percentage of output being properly escaped. The presence of nonce and capability checks, even with a minimal attack surface, is commendable.
Concerns are minimal given the data. The taint analysis shows no identified flows, and the vulnerability history is clean, with no known CVEs. This suggests the plugin is either very new, has a very limited scope of functionality that doesn't lend itself to common vulnerabilities, or has been developed with security in mind. The plugin's strength lies in its minimal functionality and adherence to secure coding principles where applicable.
While the plugin appears very secure, the lack of any identified taint flows or complex code structures might also mean the analysis has not encountered scenarios where vulnerabilities could arise. The absence of file operations and external HTTP requests further limits potential attack vectors. Overall, for its current version and apparent functionality, 'rewrite-testing' demonstrates a robust security foundation.
Rewrite Rule Testing Security Vulnerabilities
Rewrite Rule Testing Release Timeline
Rewrite Rule Testing Code Analysis
Output Escaping
Rewrite Rule Testing Attack Surface
WordPress Hooks 4
Maintenance & Trust
Rewrite Rule Testing Maintenance & Trust
Maintenance Signals
Community Trust
Rewrite Rule Testing Alternatives
Debug Bar Rewrite Rules
debug-bar-rewrite-rules
Debug Bar Rewrite Rules adds a new panel to Debug Bar that displays information about WordPress Rewrites Rules (if used).
Admin Bar Tools
sf-adminbar-tools
Adds some small development tools to the admin bar.
WP Permastructure
wp-permastructure
Adds the ability to configure permalinks for custom post types using rewrite tags like %post_id% and %author%.
Nginx Helper
nginx-helper
Cleans nginx's fastcgi/proxy cache or redis-cache whenever a post is edited/published. Also does a few more things.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Rewrite Rule Testing Developer Profile
8 plugins · 8K total installs
How We Detect Rewrite Rule Testing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rewrite-testing/rewrite-testing.phprewrite-testing/rewrite-testing.php?ver=HTML / DOM Fingerprints
rt_test_resultserrorid="rt_test_results"