
Premmerce Permalink Manager for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-permalink-managerPremmerce Permalink Manager for WooCommerce allows you to change WooCommerce permalink and remove product and product_category slugs from the URL.
Is Premmerce Permalink Manager for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Premmerce Permalink Manager for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-permalink-manager" v2.3.11 plugin exhibits a mixed security posture. On the positive side, the code demonstrates good practices regarding database interactions, with all SQL queries utilizing prepared statements, and all output being properly escaped, which significantly mitigates risks of SQL injection and cross-site scripting respectively. The absence of file operations and external HTTP requests further strengthens its defensive capabilities.
However, significant concerns arise from the identified attack surface. The presence of one AJAX handler without any authentication checks presents a direct entry point for potential attacks. The complete absence of nonce checks on this handler, coupled with the lack of capability checks, means that any authenticated or even unauthenticated user could potentially trigger this AJAX action. While taint analysis showed no immediate flows, the lack of comprehensive checks on the AJAX handler means data passed to it could be vulnerable if not handled with extreme care within the handler itself.
The vulnerability history, particularly the past critical CVE related to Improper Control of Filename for Include/Require Statement, is a strong indicator of past security weaknesses. While this specific vulnerability is currently patched, its nature suggests that code logic around file handling or dynamic includes might have been a historical weak point. This past critical issue, despite being resolved, warrants ongoing vigilance and suggests a potential for similar vulnerabilities to emerge if code reviews are not rigorous.
Key Concerns
- AJAX handler without authentication
- Missing nonce checks on AJAX handler
- Missing capability checks on AJAX handler
- Past critical CVE (RFI) history
- Bundled outdated Freemius library
Premmerce Permalink Manager for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Premmerce Permalink Manager for WooCommerce <= 2.3.10 - Unauthenticated Local File Inclusion
Premmerce Permalink Manager for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Premmerce Permalink Manager for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 30
Maintenance & Trust
Premmerce Permalink Manager for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Premmerce Permalink Manager for WooCommerce Alternatives
Permalink Manager Lite
permalink-manager
Permalink Manager enhances WordPress’s built-in URL system, allowing you to change the URLs of native and custom post types and taxonomies.
Change Quantity on Checkout for WooCommerce
change-quantity-on-checkout-for-woocommerce
Allow customers to change product quantities and remove products directly from both Classic and Block-based WooCommerce checkout pages.
Delete All Products for WooCommerce
delete-all-products
Easily delete all WooCommerce products permanently or move them to the trash in just a few clicks.
NS Remove Related Products for WooCommerce
ns-remove-related-products-for-woocommerce
Remove Related Products from your shop page and product page
Woo Product Remover
woo-product-remover
Woo Product Remover allows you to remove all woocommerce products from your site. It cleans up your database from products and product variations
Premmerce Permalink Manager for WooCommerce Developer Profile
14 plugins · 60K total installs
How We Detect Premmerce Permalink Manager for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-permalink-manager/assets/css/admin.css/wp-content/plugins/woo-permalink-manager/assets/css/main.css/wp-content/plugins/woo-permalink-manager/assets/js/admin.js/wp-content/plugins/woo-permalink-manager/assets/js/main.js/wp-content/plugins/woo-permalink-manager/assets/js/premium.js/wp-content/plugins/woo-permalink-manager/assets/js/vendor.js/wp-content/plugins/woo-permalink-manager/assets/js/admin.js/wp-content/plugins/woo-permalink-manager/assets/js/main.js/wp-content/plugins/woo-permalink-manager/assets/js/premium.js/wp-content/plugins/woo-permalink-manager/assets/js/vendor.jswoo-permalink-manager/assets/css/admin.css?ver=woo-permalink-manager/assets/css/main.css?ver=woo-permalink-manager/assets/js/admin.js?ver=woo-permalink-manager/assets/js/main.js?ver=woo-permalink-manager/assets/js/premium.js?ver=woo-permalink-manager/assets/js/vendor.js?ver=HTML / DOM Fingerprints
premmerce_url_manager_bannerpremmerce_url_manager_ignore_bannerwoo-permalink-manager-adminPremmerce Permalink Manager Slug fixThis file is intended to fix a wrong plugin slug from an older version.data-premmerce_url_manager_ignore_bannerpremmerce_url_manager_ignore_bannerPremmerceUrlManagerpremmerceUrlManagerpremmerce_url_manager_ignore_banner/wp-json/premmerce/v1/settings