
Url Rewrite Analyzer Security & Risk Analysis
wordpress.org/plugins/url-rewrite-analyzerSee clearly and understand how WordPress rewrite rules work within a simple and clean interface
Is Url Rewrite Analyzer Safe to Use in 2026?
Generally Safe
Score 99/100Url Rewrite Analyzer has a strong security track record. Known vulnerabilities have been patched promptly.
The "url-rewrite-analyzer" plugin v1.3.4 demonstrates a generally good security posture, with a low overall risk. The static analysis reveals a small attack surface with all entry points protected by authentication checks, which is a significant strength. Furthermore, the plugin utilizes prepared statements for all SQL queries and has a good number of nonce and capability checks in place. However, there are areas for improvement. The output escaping is only properly implemented for 59% of outputs, indicating a potential for cross-site scripting (XSS) vulnerabilities if untrusted data is rendered without sufficient sanitization. Taint analysis found no unsanitized paths, which is positive, but the low number of flows analyzed (2) might limit the thoroughness of this assessment.
The vulnerability history shows one previously known medium severity vulnerability related to missing authorization. While this is currently patched, the pattern of a past authorization issue warrants attention. The absence of any currently unpatched CVEs is a positive sign. In conclusion, the plugin has robust defenses against common web vulnerabilities like SQL injection and has a well-managed attack surface. The primary concern lies with the moderate percentage of improperly escaped output, which, if exploited, could lead to XSS. The past authorization vulnerability, though patched, serves as a reminder to maintain vigilance regarding access control.
Key Concerns
- Output escaping is not fully implemented (59% proper)
- Past medium severity vulnerability (2025-05-19)
Url Rewrite Analyzer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Url Rewrite Analyzer <= 1.3.3 - Missing Authorization
Url Rewrite Analyzer Code Analysis
Output Escaping
Data Flow Analysis
Url Rewrite Analyzer Attack Surface
AJAX Handlers 2
WordPress Hooks 5
Maintenance & Trust
Url Rewrite Analyzer Maintenance & Trust
Maintenance Signals
Community Trust
Url Rewrite Analyzer Alternatives
Monkeyman Rewrite Analyzer
monkeyman-rewrite-analyzer
Making sense of the rewrite mess. Display and play with your rewrite rules.
Debug Bar Rewrite Rules
debug-bar-rewrite-rules
Debug Bar Rewrite Rules adds a new panel to Debug Bar that displays information about WordPress Rewrites Rules (if used).
Query Monitor – The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
Monster Widget
monster-widget
Provides a quick and easy method of adding all core widgets to a sidebar for testing purposes.
What Template
what-template
Adds the current page's template name to the admin bar.
Url Rewrite Analyzer Developer Profile
5 plugins · 5K total installs
How We Detect Url Rewrite Analyzer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/url-rewrite-analyzer/dist/url-rewrite-analyzer.js/wp-content/plugins/url-rewrite-analyzer/dist/url-rewrite-analyzer.css/wp-content/plugins/url-rewrite-analyzer/dist/url-rewrite-analyzer.jsurl-rewrite-analyzer.js?ver=url-rewrite-analyzer.css?ver=HTML / DOM Fingerprints
urap-wrapperdata-urap-ui-styleadminRewrite_Analyzer_Regexes