
WorkflowDone 404 Monitor Security & Risk Analysis
wordpress.org/plugins/workflowdone-404-monitorMonitor your WordPress site for 404 errors and broken links. Get email notifications when issues are detected.
Is WorkflowDone 404 Monitor Safe to Use in 2026?
Generally Safe
Score 100/100WorkflowDone 404 Monitor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The workflowdone-404-monitor plugin version 1.0.3 demonstrates a generally strong security posture with several positive indicators. The complete absence of dangerous functions, a very high percentage of SQL queries using prepared statements, and almost all output being properly escaped are excellent practices that significantly reduce common web application vulnerabilities. Furthermore, the plugin effectively utilizes nonce and capability checks on its AJAX handlers, and there are no known CVEs in its history, suggesting diligent security development and maintenance.
However, the static analysis does reveal some potential areas for concern. The presence of 4 taint flows with unsanitized paths, specifically flagged as high severity, is a significant risk. While the vulnerability history is clean, these taint flows could indicate a latent vulnerability that has not yet been exploited or discovered. The plugin also makes one external HTTP request, which, while not inherently a vulnerability, can be a vector for information disclosure or other attacks if not handled securely. The overall attack surface is moderate with 8 AJAX handlers, and importantly, all are protected by authentication, which is a positive mitigation.
In conclusion, the plugin is built on a solid foundation of secure coding practices. The lack of known vulnerabilities and the extensive use of security features like prepared statements and output escaping are commendable. The primary weakness lies in the high-severity taint flows with unsanitized paths, which require immediate attention to prevent potential exploitation. Addressing these specific flows will greatly enhance the plugin's overall security.
Key Concerns
- High severity taint flows with unsanitized paths
- External HTTP request made
WorkflowDone 404 Monitor Security Vulnerabilities
WorkflowDone 404 Monitor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WorkflowDone 404 Monitor Attack Surface
AJAX Handlers 8
WordPress Hooks 4
Scheduled Events 1
Maintenance & Trust
WorkflowDone 404 Monitor Maintenance & Trust
Maintenance Signals
Community Trust
WorkflowDone 404 Monitor Alternatives
Broken Link Fixer
broken-link-fixer
The Broken Link Fixer plugin helps you automatically detect and unlink broken links in your WordPress content.
Nandann AI Smart 404 Redirects – Auto Fix Broken Links & Typos
nandann-ai-smart-404-redirect
AI-powered 404 redirect plugin with smart matching and typo detection. Automatically fix broken links and redirect visitors to the most relevant page.
Permalink Keeper
permalink-keeper
Automatically fixes broken WordPress permalinks by refreshing them at regular intervals. Prevents 404 errors and maintains SEO integrity.
Hamada Smart 404 Redirect & Logger
hamada-smart-404-redirect-logger
Hamada Smart 404 Redirect & Logger helps you monitor 404 errors, log broken URLs, and fix them with manual or automatic redirects.
LinkGuard NT
linkguard-nt
A fast, lightweight, and secure broken link scanner for WordPress. Detect, monitor, and fix broken links with a modern AJAX dashboard and multilingual …
WorkflowDone 404 Monitor Developer Profile
3 plugins · 40 total installs
How We Detect WorkflowDone 404 Monitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/workflowdone-404-monitor/css/wfd404-style.css/wp-content/plugins/workflowdone-404-monitor/js/wfd404-script.js/wp-content/plugins/workflowdone-404-monitor/js/wfd404-script.jsworkflowdone-404-monitor/css/wfd404-style.css?ver=workflowdone-404-monitor/js/wfd404-script.js?ver=HTML / DOM Fingerprints
wfd404-admin-wrapwfd404_ajax_object/wp-json/wfd404/v1/settings