
Shortcode Redirect Security & Risk Analysis
wordpress.org/plugins/shortcode-redirectA super easy way to automatically redirect a user to another page when viewing a post/page on your site.
Is Shortcode Redirect Safe to Use in 2026?
Generally Safe
Score 98/100Shortcode Redirect has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'shortcode-redirect' plugin version 1.0.03 presents a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries are prepared, there are no file operations or external HTTP requests, and the limited attack surface (one shortcode) does not appear to have immediate unprotected entry points based on the provided data. Taint analysis also shows no critical or high severity flows.
However, several concerns arise. The vulnerability history shows a significant past issue with two medium severity Cross-site Scripting (XSS) vulnerabilities, even though none are currently unpatched. The fact that a recent vulnerability was recorded in August 2025, while the analyzed version is 1.0.03, suggests potential for undiscovered or historical issues. Furthermore, only 40% of output is properly escaped, indicating a potential for XSS vulnerabilities if user-supplied data is rendered without adequate sanitization, especially given the plugin's shortcode functionality which often handles user input.
While the current static analysis and taint analysis don't flag immediate critical issues, the past vulnerability history and the moderate output escaping rate are red flags. The plugin has a track record of XSS, and the current code may still be susceptible if user input is not handled carefully within the shortcode. It's advisable to audit the shortcode implementation thoroughly for any unescaped output that might be rendered in a user's browser.
Key Concerns
- Past medium severity XSS vulnerabilities
- Moderate output escaping (40%)
- No capability checks on shortcode
Shortcode Redirect Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Shortcode Redirect <= 1.0.02 - Authenticated (Contributor+) Stored Cross-Site Scripting
Shortcode Redirect <= 1.0.01 - Cross-Site Scripting
Shortcode Redirect Release Timeline
Shortcode Redirect Code Analysis
Output Escaping
Shortcode Redirect Attack Surface
Shortcodes 1
Maintenance & Trust
Shortcode Redirect Maintenance & Trust
Maintenance Signals
Community Trust
Shortcode Redirect Alternatives
Page Redirection & Hit Counter
redirection-page-hit-counter
Page Redirection, Post Redirection, Other Page Url Redirection
Easy url rewrite
easy-url-rewrite
Create your custom URLs pointing to custom files.
VK Link Target Controller
vk-link-target-controller
Redirect your visitors to another page than the post content when they click on the post title.
Permalink Editor
permalink-editor
Fully customise the permalink for an individual page or post and globally set the permalink structure for pages, categories, tags or authors.
Password Passthrough
password-passthrough
This plugin allows passwords for password-protected pages/posts to be passed directly through the URL.
Shortcode Redirect Developer Profile
6 plugins · 32K total installs
How We Detect Shortcode Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
Please wait while you are redirected...or <a href=