
Slightly troublesome permalink Security & Risk Analysis
wordpress.org/plugins/slightly-troublesome-permalinkThis plug-in controls the category in permalink. When the post belongs to two or more categories.
Is Slightly troublesome permalink Safe to Use in 2026?
Use With Caution
Score 63/100Slightly troublesome permalink has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "slightly-troublesome-permalink" v1.2.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and performing nonces and capability checks, indicating an awareness of common WordPress security vulnerabilities. Furthermore, the absence of file operations, external HTTP requests, and taint analysis findings suggest a relatively contained and well-handled codebase in these specific areas.
However, a significant concern arises from the plugin's vulnerability history. The presence of a known, unpatched medium severity vulnerability, specifically a Cross-Site Scripting (XSS) flaw, is a critical red flag. This indicates that users of this plugin are currently exposed to this specific risk. The fact that this is the only recorded vulnerability in its history, and that it occurred relatively recently, could suggest a pattern of occasional security oversight or a specific weakness in how certain types of input are neutralized before output. While the current code analysis shows good practices, the outstanding CVE directly contradicts this and must be prioritized.
In conclusion, while the "slightly-troublesome-permalink" plugin has strengths in its limited attack surface and adherence to secure coding practices like prepared statements and nonce checks, the existence of an unpatched XSS vulnerability significantly degrades its overall security rating. The immediate priority for any user of this plugin should be to investigate and apply a patch for the known CVE. Developers should also consider a deeper review of input sanitization and output escaping, especially in light of the past XSS vulnerability, to prevent recurrence.
Key Concerns
- Unpatched CVE exists
Slightly troublesome permalink Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Slightly troublesome permalink <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Slightly troublesome permalink Code Analysis
Output Escaping
Slightly troublesome permalink Attack Surface
WordPress Hooks 4
Maintenance & Trust
Slightly troublesome permalink Maintenance & Trust
Maintenance Signals
Community Trust
Slightly troublesome permalink Alternatives
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Custom Permalinks
custom-permalinks
A powerful WordPress plugin for full URL control. Set custom permalinks, auto-redirects, and use dynamic tags for ideal site structure and SEO.
Nginx Helper
nginx-helper
Cleans nginx's fastcgi/proxy cache or redis-cache whenever a post is edited/published. Also does a few more things.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Permalink Manager Lite
permalink-manager
Permalink Manager enhances WordPress’s built-in URL system, allowing you to change the URLs of native and custom post types and taxonomies.
Slightly troublesome permalink Developer Profile
8 plugins · 21K total installs
How We Detect Slightly troublesome permalink
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slightly-troublesome-permalink/languagesjquery-ui-draggablejquery-ui-droppablejquery-ui-sortableHTML / DOM Fingerprints
priority-categorycategories-treeui-draggable-draggingui-state-placeholderui-sortable-helperui-draggable-disabledopenhasChildren+1 moreCopyright (C) 2012-2021 tmatsuur (Email: takenori dot matsuura at 12net dot jp)
This program is licensed under the GNU GPL Version 2.IE10FirefoxOpera+7 moredata-category-idslightly_troublesome_permalink