
Slug Trace Security & Risk Analysis
wordpress.org/plugins/slugtraceExpose the hidden "old slugs" WordPress stores and automatically redirects for your Posts, Pages, and all Public Custom Post Types.
Is Slug Trace Safe to Use in 2026?
Generally Safe
Score 100/100Slug Trace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the 'slugtrace' v1.0 plugin appears to have a very strong security posture. The code analysis reveals no dangerous functions, SQL injection vulnerabilities, or unsanitized output. Furthermore, the absence of file operations, external HTTP requests, and the reported zero total entry points across AJAX, REST API, shortcodes, and cron events significantly limit the potential attack surface. The plugin also demonstrates good practices by not bundling any external libraries, further reducing the risk of known vulnerabilities in third-party code.
The vulnerability history further reinforces this positive assessment, with zero recorded CVEs of any severity. This indicates a history of secure development and maintenance for this plugin. However, it is important to note that the static analysis did not detect any nonce or capability checks. While the current attack surface is zero, the absence of these checks means that *if* new entry points were to be introduced in future versions without proper authentication or authorization, they could potentially be exploited. This is a minor concern given the current state, but something to monitor in future updates.
In conclusion, 'slugtrace' v1.0 exhibits excellent security practices with no identified vulnerabilities in its current version and a clean vulnerability history. The primary area for potential improvement, though not an immediate risk due to the lack of entry points, is the implementation of nonce and capability checks for any future expansion of its functionality.
Key Concerns
- No nonce checks detected
- No capability checks detected
Slug Trace Security Vulnerabilities
Slug Trace Release Timeline
Slug Trace Code Analysis
Output Escaping
Slug Trace Attack Surface
WordPress Hooks 2
Maintenance & Trust
Slug Trace Maintenance & Trust
Maintenance Signals
Community Trust
Slug Trace Alternatives
Wenprise Pinyin Slug
wenprise-pinyin-slug
自动转换 WordPress 中的中文文章别名、分类项目别名、图片文件名称为汉语拼音或英文翻译。
Greek Multi Tool – Greeklish Slugs, Permalinks & Transliteration
greek-multi-tool
The only lightweight plugin you need for Greek WordPress sites. Auto-convert Greeklish slugs, optimize permalinks, and enhance search without bloat.
Change Permalink Helper
change-permalink-helper
It checks the Permalink and redirects to the new URL, if it doesn't exist. It sends the header message "moved permanently 301"
Advanced Permalinks
advanced-permalinks
Allows multiple permalink structures and category-specific permalinks without needing redirects.
Legacy URL Suffix & SEO Preserver
php-to-pages
Maintain SEO rankings with custom URL suffixes like .php or .html. Perfect for legacy site migrations, fixing 404s, and preserving link juice.
Slug Trace Developer Profile
5 plugins · 410 total installs
How We Detect Slug Trace
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
Slug HistoryHistory starts after the first publish.No previous slugs found.