
Update Permalink/Slug Previews in Admin Security & Risk Analysis
wordpress.org/plugins/update-permalink-previews-in-adminAutomatically reloads permalink/slug previews in admin edit view when changing a page's parent or the categories of a post.
Is Update Permalink/Slug Previews in Admin Safe to Use in 2026?
Generally Safe
Score 92/100Update Permalink/Slug Previews in Admin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "update-permalink-previews-in-admin" plugin v1.1 exhibits a mixed security posture. On one hand, its static analysis reveals a lack of dangerous functions, entirely prepared SQL queries, and no file operations or external HTTP requests. This indicates a generally well-written codebase that avoids common pitfalls. However, the most significant concern is the presence of one unprotected AJAX handler, which represents a direct entry point into the plugin's functionality without any authentication or authorization checks. The absence of nonce checks and capability checks in the static analysis further exacerbates this risk, as it means this AJAX endpoint could be triggered by unauthenticated users or users with limited privileges.
The taint analysis shows no critical or high-severity flows, and the vulnerability history is clean, with no recorded CVEs. This suggests that the plugin hasn't had publicly disclosed vulnerabilities. While this is a positive indicator, it does not negate the identified risk of the unprotected AJAX endpoint. The plugin's strengths lie in its clean handling of data and queries, but its weakness lies in a critical oversight in securing its administrative interface, making it a potential target for attackers seeking to exploit its functionality through the unprotected AJAX handler.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
Update Permalink/Slug Previews in Admin Security Vulnerabilities
Update Permalink/Slug Previews in Admin Code Analysis
Update Permalink/Slug Previews in Admin Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Update Permalink/Slug Previews in Admin Maintenance & Trust
Maintenance Signals
Community Trust
Update Permalink/Slug Previews in Admin Alternatives
No category parents
no-category-parents
This plugin will completely remove the mandatory 'Category Base' and all the parents from your category permalinks (e.g.
Simple Category List
categorylist
Major features in Simple category list include:
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
WP No Base Permalink
wp-no-base-permalink
Removes category base or parents categories or tag base from your permalinks. Compatible with WPML Plugin and WordPress Multisite.
Category Dropdown by GCS Design
wp-category-dropdown
Display a parent and child categories in a dropdown. Works with custom taxonomies and WooCommerce product categories.
Update Permalink/Slug Previews in Admin Developer Profile
1 plugin · 0 total installs
How We Detect Update Permalink/Slug Previews in Admin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/update-permalink-previews-in-admin//wp-content/plugins/update-permalink-previews-in-admin/update-permalink-previews.jsupdate-permalink-previews-in-admin/update-permalink-previews.js?ver=1.0