Slightly troublesome permalink Security & Risk Analysis

wordpress.org/plugins/slightly-troublesome-permalink

This plug-in controls the category in permalink. When the post belongs to two or more categories.

1K active installs v1.2.0 PHP + WP 4.5.0+ Updated Apr 20, 2021
permalink
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Slightly troublesome permalink Safe to Use in 2026?

Use With Caution

Score 63/100

Slightly troublesome permalink has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 4yr ago
Risk Assessment

The "slightly-troublesome-permalink" v1.2.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and performing nonces and capability checks, indicating an awareness of common WordPress security vulnerabilities. Furthermore, the absence of file operations, external HTTP requests, and taint analysis findings suggest a relatively contained and well-handled codebase in these specific areas.

However, a significant concern arises from the plugin's vulnerability history. The presence of a known, unpatched medium severity vulnerability, specifically a Cross-Site Scripting (XSS) flaw, is a critical red flag. This indicates that users of this plugin are currently exposed to this specific risk. The fact that this is the only recorded vulnerability in its history, and that it occurred relatively recently, could suggest a pattern of occasional security oversight or a specific weakness in how certain types of input are neutralized before output. While the current code analysis shows good practices, the outstanding CVE directly contradicts this and must be prioritized.

In conclusion, while the "slightly-troublesome-permalink" plugin has strengths in its limited attack surface and adherence to secure coding practices like prepared statements and nonce checks, the existence of an unpatched XSS vulnerability significantly degrades its overall security rating. The immediate priority for any user of this plugin should be to investigate and apply a patch for the known CVE. Developers should also consider a deeper review of input sanitization and output escaping, especially in light of the past XSS vulnerability, to prevent recurrence.

Key Concerns

  • Unpatched CVE exists
Vulnerabilities
1

Slightly troublesome permalink Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-57959medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Slightly troublesome permalink <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Slightly troublesome permalink Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
24 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped28 total outputs
Attack Surface

Slightly troublesome permalink Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterpost_linkslightly-troublesome-permalink.php:29
filterplugin_row_metaslightly-troublesome-permalink.php:30
actionadmin_menuslightly-troublesome-permalink.php:31
actionadmin_headslightly-troublesome-permalink.php:33
Maintenance & Trust

Slightly troublesome permalink Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 20, 2021
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Slightly troublesome permalink Developer Profile

tmatsuur

8 plugins · 21K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
1904 days
View full developer profile
Detection Fingerprints

How We Detect Slightly troublesome permalink

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slightly-troublesome-permalink/languages
Script Paths
jquery-ui-draggablejquery-ui-droppablejquery-ui-sortable

HTML / DOM Fingerprints

CSS Classes
priority-categorycategories-treeui-draggable-draggingui-state-placeholderui-sortable-helperui-draggable-disabledopenhasChildren+1 more
HTML Comments
Copyright (C) 2012-2021 tmatsuur (Email: takenori dot matsuura at 12net dot jp) This program is licensed under the GNU GPL Version 2.IE10FirefoxOpera+7 more
Data Attributes
data-category-id
JS Globals
slightly_troublesome_permalink
FAQ

Frequently Asked Questions about Slightly troublesome permalink