Simple WWW Redirect Security & Risk Analysis

wordpress.org/plugins/simple-www-redirect

The plugin specifies whether your domain will include www. Redirects www to non-www or non-www to www.

1K active installs v1.0.2 PHP + WP 4.0+ Updated Nov 18, 2024
disablenon-wwwredirectworld-wide-webwww
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple WWW Redirect Safe to Use in 2026?

Generally Safe

Score 92/100

Simple WWW Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the 'simple-www-redirect' plugin v1.0.2 reveals a seemingly secure initial posture, with no identified attack surface points (AJAX, REST API, shortcodes, cron events) and no dangerous functions or external HTTP requests. The plugin also demonstrates good practice by utilizing prepared statements for all its SQL queries. However, a significant concern arises from the complete lack of output escaping for all 8 identified output points. This means that any data displayed to users, if it originates from an untrusted source or is manipulated by an attacker, could be rendered insecurely, potentially leading to cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. Despite the absence of direct attack vectors and raw SQL, the unescaped output is a notable weakness that introduces a potential security risk. While the plugin's current lack of historical vulnerabilities is reassuring, the unescaped output remains a clear area for improvement.

Key Concerns

  • No output escaping for 8 identified outputs
Vulnerabilities
None known

Simple WWW Redirect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple WWW Redirect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Simple WWW Redirect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedindex.php:23
actionadmin_menuindex.php:196
actionadmin_initindex.php:208
actionadmin_enqueue_scriptsindex.php:221
actionupdate_option_swr_force_typeindex.php:233
actionadd_option_swr_force_typeindex.php:234
Maintenance & Trust

Simple WWW Redirect Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 18, 2024
PHP min version
Downloads18K

Community Trust

Rating54/100
Number of ratings3
Active installs1K
Developer Profile

Simple WWW Redirect Developer Profile

LightPlugins

3 plugins · 2K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple WWW Redirect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-www-redirect/css/admin.css/wp-content/plugins/simple-www-redirect/js/admin.js
Script Paths
/wp-content/plugins/simple-www-redirect/js/admin.js

HTML / DOM Fingerprints

CSS Classes
swr-has-errorswr-errorsswr-radioswr-submitswr-wrapswr-settingsswr-information
FAQ

Frequently Asked Questions about Simple WWW Redirect