
SEO Redirection Plugin – 301 Redirect Manager Security & Risk Analysis
wordpress.org/plugins/seo-redirectionSEO Redirection is a powerful redirect manager to manage 301 redirects without requiring knowledge of Apache .htaccess files.
Is SEO Redirection Plugin – 301 Redirect Manager Safe to Use in 2026?
Generally Safe
Score 96/100SEO Redirection Plugin – 301 Redirect Manager has a strong security track record. Known vulnerabilities have been patched promptly.
The 'seo-redirection' plugin version 9.16 presents a mixed security posture. While it shows strengths in areas like the absence of dangerous functions and a good percentage of properly escaped output, significant concerns arise from its attack surface and vulnerability history. The static analysis reveals a substantial number of AJAX handlers without proper authentication checks, creating a wide entry point for potential attacks. Furthermore, the taint analysis indicates a concerning presence of unsanitized paths, with two flows flagged as high severity, suggesting risks of data manipulation or unauthorized access through these vulnerabilities.
The plugin's vulnerability history is a major red flag. With a total of nine known CVEs, including three high-severity ones, and a recent vulnerability in late 2022, it indicates a recurring pattern of security weaknesses. The common types of vulnerabilities (CSRF, SQL Injection, XSS) further suggest fundamental flaws in input validation and state management. The absence of currently unpatched CVEs is a positive sign, but the historical record points to a plugin that has struggled with maintaining a secure codebase over time, requiring diligent patching.
In conclusion, despite some good practices in output escaping and SQL query preparation, the 'seo-redirection' plugin's numerous unprotected entry points, high-severity taint flows, and extensive history of significant vulnerabilities warrant a cautious approach. The potential for attackers to exploit unprotected AJAX handlers and the past issues with injection and cross-site scripting are critical risks that users should be aware of.
Key Concerns
- 5 unprotected AJAX handlers
- 2 high severity taint flows
- 3 high severity CVEs historically
- Common vulnerability types (SQLi, XSS, CSRF)
- 5 out of 6 AJAX handlers lack auth checks
- 4 unsanitized path flows
SEO Redirection Plugin – 301 Redirect Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
SEO Redirection Plugin <= 8.9 - Cross-Site Request Forgery
SEO Redirection Plugin – 301 Redirect Manager <= 8.9 - Cross-Site Request Forgery
SEO Redirection <= 8.1 - Subscriber+ SQL Injection
SEO Redirection Plugin – 301 Redirect Manager <= 7.8 - Cross-Site Request Forgery
SEO Redirection Plugin – 301 Redirect Manager <= 7.3 - Reflected Cross-Site Scripting
SEO Redirection <= 6.4 - Authenticated Stored Cross-Site Scripting
SEO Redirection Plugin - 301 Redirect Manager <= 6.3 - Reflected Cross-Site Scripting
SEO Redirection <= 4.2 - Stored Cross-Site Scripting
SEO Redirection <= 2.8 - Reflected Cross-Site Scripting
SEO Redirection Plugin – 301 Redirect Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SEO Redirection Plugin – 301 Redirect Manager Attack Surface
AJAX Handlers 6
WordPress Hooks 15
Maintenance & Trust
SEO Redirection Plugin – 301 Redirect Manager Maintenance & Trust
Maintenance Signals
Community Trust
SEO Redirection Plugin – 301 Redirect Manager Alternatives
Redirection
redirection
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
301 Redirects – Redirect Manager
eps-301-redirects
Manage 301 & 302 redirects. Simple redirection & redirects validation. Includes redirect stats & 404 error log.
Redirection
redirect-redirection
Redirection
Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More
simple-301-redirects
Simple 301 Redirects provides an easy method of redirecting requests to another page on your site or elsewhere on the web.
301 Redirects & 404 Error Log
301-redirects
Create & manage 301 redirects. Easily test redirects. Includes 404 error log.
SEO Redirection Plugin – 301 Redirect Manager Developer Profile
13 plugins · 355K total installs
How We Detect SEO Redirection Plugin – 301 Redirect Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/seo-redirection/custom/images/icon.png/wp-content/plugins/seo-redirection/custom/css/custom.css/wp-content/plugins/seo-redirection/custom/js/custom.jsHTML / DOM Fingerprints
seo-redirection-admin-barwpsr-404-errors-admin-barwpsr-404-noticedata-seo-redirection-iddata-seo-redirection-sourcedata-seo-redirection-destinationwindow.WPSR_redirect_datavar WPSR_redirect_settings[seo_redirection_form][seo_redirection_list]