Suggest 404 links Security & Risk Analysis

wordpress.org/plugins/suggest-404-links

Appends "did you mean" links to your "404" page.

0 active installs v0.3.2 PHP 7.2+ WP 6.2+ Updated Oct 25, 2025
404did-you-meansimilarsuggestions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Suggest 404 links Safe to Use in 2026?

Generally Safe

Score 100/100

Suggest 404 links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "suggest-404-links" v0.3.2 exhibits a generally good security posture in terms of its attack surface and output sanitization. All identified entry points (AJAX, REST API, shortcodes, cron) are either protected by authentication or permission checks, and all output is properly escaped. The absence of external HTTP requests and a clean vulnerability history further contribute to its positive security profile. However, a significant concern is the presence of the `unserialize` function, which, when used with untrusted input, can lead to Remote Code Execution vulnerabilities. While taint analysis shows no current flows with unsanitized paths, the potential for such a flow exists if `unserialize` is ever exposed to external data without proper sanitization or validation. The static analysis also indicates that the single SQL query is not using prepared statements, which could be a risk if sensitive data is involved or if the query is dynamically constructed.

Key Concerns

  • Use of unserialize without clear sanitization context
  • SQL query not using prepared statements
Vulnerabilities
None known

Suggest 404 links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Suggest 404 links Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
0
32 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$settings = @unserialize($settings); // phpcs:ignore Generic.PHP.NoSilencedErrors -- unserialize casrc\Services\Config.php:87

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped32 total outputs
Attack Surface

Suggest 404 links Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[suggest_404_links] src\Core\Shortcodes.php:19
WordPress Hooks 14
actionplugins_loadedsrc\Core\Bootstrap.php:35
actionenqueue_block_assetssrc\Core\Bootstrap.php:37
actionadmin_noticessrc\Core\Bootstrap.php:101
actioninitsrc\Core\Bootstrap.php:134
actionenqueue_block_assetssrc\Core\Bootstrap.php:135
actionwp_headsrc\Core\Hooks.php:18
actionadmin_menusrc\Dashboard\AbstractPage.php:88
filteradmin_footer_textsrc\Dashboard\AbstractPage.php:146
filterupdate_footersrc\Dashboard\AbstractPage.php:147
actionadmin_enqueue_scriptssrc\Dashboard\AbstractPage.php:150
actionenqueue_block_editor_assetssrc\Dashboard\Dashboard.php:34
actionwp_loadedsrc\Dashboard\Dashboard.php:35
filterplugin_row_metasrc\Dashboard\Dashboard.php:37
actionadmin_noticessrc\Dashboard\Dashboard.php:146
Maintenance & Trust

Suggest 404 links Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 25, 2025
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Suggest 404 links Developer Profile

Tekod lab.

4 plugins · 630 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Suggest 404 links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/suggest-404-links/assets/public/style.css
Version Parameters
suggest-404-links/assets/public/style.css?ver=

HTML / DOM Fingerprints

Shortcode Output
<!-- suggest_404_links_widget_start --><!-- suggest_404_links_widget_end -->
FAQ

Frequently Asked Questions about Suggest 404 links