
sCategory Permalink Security & Risk Analysis
wordpress.org/plugins/scategory-permalinkPlugin allows to select category which will be used to generate permalink on post edit page. Use custom permalink option %scategory%.
Is sCategory Permalink Safe to Use in 2026?
Generally Safe
Score 85/100sCategory Permalink has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scategory-permalink" v0.6.2 plugin exhibits a seemingly strong security posture based on the provided static analysis, with no direct entry points identified in AJAX handlers, REST API, shortcodes, or cron events. Furthermore, the absence of dangerous functions, external HTTP requests, and the reported use of prepared statements for all SQL queries are positive indicators. The lack of any recorded vulnerabilities in its history suggests a generally well-maintained codebase or limited exposure.
However, a significant concern arises from the complete lack of output escaping. This means that any data processed by the plugin and subsequently displayed to users could be vulnerable to Cross-Site Scripting (XSS) attacks. The absence of nonce checks and capability checks on what are effectively hidden entry points (even if they are currently 0) also represent potential gaps that could become exploitable if new entry points are introduced in future versions without proper security considerations. The complete lack of taint analysis results is also unusual and might indicate a limitation of the analysis tool or that the plugin's code structure did not trigger any flows for analysis.
In conclusion, while the plugin has a clean vulnerability history and avoids common pitfalls like raw SQL and external requests, the critical flaw of unescaped output presents a tangible risk. The absence of explicit permission and nonce checks, even with zero current entry points, warrants attention for future development to ensure robust security.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
sCategory Permalink Security Vulnerabilities
sCategory Permalink Code Analysis
Output Escaping
sCategory Permalink Attack Surface
WordPress Hooks 6
Maintenance & Trust
sCategory Permalink Maintenance & Trust
Maintenance Signals
Community Trust
sCategory Permalink Alternatives
Hikari Category Permalink
hikari-category-permalink
For each post, author can choose which category is used in permalink.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
No category parents
no-category-parents
This plugin will completely remove the mandatory 'Category Base' and all the parents from your category permalinks (e.g.
Wenprise Pinyin Slug
wenprise-pinyin-slug
自动转换 WordPress 中的中文文章别名、分类项目别名、图片文件名称为汉语拼音或英文翻译。
sCategory Permalink Developer Profile
3 plugins · 1K total installs
How We Detect sCategory Permalink
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scategory-permalink/scategory_permalink.js/wp-content/plugins/scategory-permalink/scategory_permalink.jsHTML / DOM Fingerprints
scategory_linkjQuery('#categorydiv').sCategoryPermalink