Update Permalink/Slug Previews in Admin Security & Risk Analysis

wordpress.org/plugins/update-permalink-previews-in-admin

Automatically reloads permalink/slug previews in admin edit view when changing a page's parent or the categories of a post.

0 active installs v1.1 PHP 7.0+ WP 4.4+ Updated Nov 12, 2024
categoriescategoryparentpermalinkslug
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Update Permalink/Slug Previews in Admin Safe to Use in 2026?

Generally Safe

Score 92/100

Update Permalink/Slug Previews in Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "update-permalink-previews-in-admin" plugin v1.1 exhibits a mixed security posture. On one hand, its static analysis reveals a lack of dangerous functions, entirely prepared SQL queries, and no file operations or external HTTP requests. This indicates a generally well-written codebase that avoids common pitfalls. However, the most significant concern is the presence of one unprotected AJAX handler, which represents a direct entry point into the plugin's functionality without any authentication or authorization checks. The absence of nonce checks and capability checks in the static analysis further exacerbates this risk, as it means this AJAX endpoint could be triggered by unauthenticated users or users with limited privileges.

The taint analysis shows no critical or high-severity flows, and the vulnerability history is clean, with no recorded CVEs. This suggests that the plugin hasn't had publicly disclosed vulnerabilities. While this is a positive indicator, it does not negate the identified risk of the unprotected AJAX endpoint. The plugin's strengths lie in its clean handling of data and queries, but its weakness lies in a critical oversight in securing its administrative interface, making it a potential target for attackers seeking to exploit its functionality through the unprotected AJAX handler.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
Vulnerabilities
None known

Update Permalink/Slug Previews in Admin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Update Permalink/Slug Previews in Admin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface
1 unprotected

Update Permalink/Slug Previews in Admin Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_sample-permalinkupdate-permalink-previews.php:32
WordPress Hooks 3
actionadmin_headupdate-permalink-previews.php:18
filterget_page_uriupdate-permalink-previews.php:36
filterpost_link_categoryupdate-permalink-previews.php:59
Maintenance & Trust

Update Permalink/Slug Previews in Admin Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 12, 2024
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Update Permalink/Slug Previews in Admin Developer Profile

thomasbachem

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Update Permalink/Slug Previews in Admin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/update-permalink-previews-in-admin/
Script Paths
/wp-content/plugins/update-permalink-previews-in-admin/update-permalink-previews.js
Version Parameters
update-permalink-previews-in-admin/update-permalink-previews.js?ver=1.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Update Permalink/Slug Previews in Admin