
Simple WWW Redirect Security & Risk Analysis
wordpress.org/plugins/simple-www-redirectThe plugin specifies whether your domain will include www. Redirects www to non-www or non-www to www.
Is Simple WWW Redirect Safe to Use in 2026?
Generally Safe
Score 92/100Simple WWW Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'simple-www-redirect' plugin v1.0.2 reveals a seemingly secure initial posture, with no identified attack surface points (AJAX, REST API, shortcodes, cron events) and no dangerous functions or external HTTP requests. The plugin also demonstrates good practice by utilizing prepared statements for all its SQL queries. However, a significant concern arises from the complete lack of output escaping for all 8 identified output points. This means that any data displayed to users, if it originates from an untrusted source or is manipulated by an attacker, could be rendered insecurely, potentially leading to cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. Despite the absence of direct attack vectors and raw SQL, the unescaped output is a notable weakness that introduces a potential security risk. While the plugin's current lack of historical vulnerabilities is reassuring, the unescaped output remains a clear area for improvement.
Key Concerns
- No output escaping for 8 identified outputs
Simple WWW Redirect Security Vulnerabilities
Simple WWW Redirect Code Analysis
Output Escaping
Simple WWW Redirect Attack Surface
WordPress Hooks 6
Maintenance & Trust
Simple WWW Redirect Maintenance & Trust
Maintenance Signals
Community Trust
Simple WWW Redirect Alternatives
Disable cart page for WooCommerce
disable-cart-page-for-woocommerce
Disable WooCommerce cart page and force customers to buy single products.
Disable WP Registration Page
disable-wp-registration-page
Disable default WP registration page.
PowerUp – Admin Tools (Login/Logout Redirects, Scripts & Comments Control)
powerup
Simplify site management with Login/Logout Redirect, Hide Admin Bar, Disable Comments, Header Footer Scripts and Remove Footer Credit.
Redirect Gravatar requests
redirect-gravatar-requests
All requests to load an avatar from gravatar.com are redirected to a local image, preventing Gravatar from potentially gathering data about your site …
WPPlugz Disable Checkout
wpplugz-disable-checkout
Disable the checkout process in WooCommerce while allowing users to add products to the cart, view cart, edit cart. This plugin is useful for demo web …
Simple WWW Redirect Developer Profile
3 plugins · 2K total installs
How We Detect Simple WWW Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-www-redirect/css/admin.css/wp-content/plugins/simple-www-redirect/js/admin.js/wp-content/plugins/simple-www-redirect/js/admin.jsHTML / DOM Fingerprints
swr-has-errorswr-errorsswr-radioswr-submitswr-wrapswr-settingsswr-information