Slug Control Security & Risk Analysis

wordpress.org/plugins/slug-control

Helps you craft amazing post URL slugs, for that hand-crafted URL feel.

10 active installs v0.1.0 PHP + WP 4.0+ Updated Apr 22, 2015
post-slugslugurls
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Slug Control Safe to Use in 2026?

Generally Safe

Score 85/100

Slug Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin 'slug-control' v0.1.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code's adherence to secure coding practices is evident through the lack of dangerous functions, the exclusive use of prepared statements for SQL queries, and proper output escaping. The absence of file operations and external HTTP requests further reduces the risk profile. The plugin's vulnerability history is clean, with no recorded CVEs, indicating a potentially well-maintained or less scrutinized codebase. While the lack of any identified taint flows is positive, it's important to note that the total flows analyzed is zero, meaning the taint analysis may not have been comprehensive or there simply aren't complex data flows to analyze in this version. The complete absence of nonce and capability checks is a notable weakness, especially if the plugin were to introduce any user-facing functionality or perform sensitive operations in future versions.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Slug Control Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Slug Control Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Slug Control Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Slug Control Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedApr 22, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Slug Control Developer Profile

Mark Jaquith

29 plugins · 176K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
3337 days
View full developer profile
Detection Fingerprints

How We Detect Slug Control

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Slug Control