
WP 404 Auto Redirect to Similar Post Security & Risk Analysis
wordpress.org/plugins/wp-404-auto-redirect-to-similar-postAutomatically Redirect any 404 page to a Similar Post based on the Title Post Type & Taxonomy using 301 or 302 Redirects!
Is WP 404 Auto Redirect to Similar Post Safe to Use in 2026?
Generally Safe
Score 95/100WP 404 Auto Redirect to Similar Post has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin exhibits a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries and includes nonce and capability checks, there are significant concerns regarding its attack surface and output escaping. The presence of an unprotected AJAX handler is a critical vulnerability, providing an easily exploitable entry point for attackers. Furthermore, the low percentage of properly escaped output suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The plugin's vulnerability history, with four known CVEs including a high-severity XSS vulnerability, reinforces these concerns. The pattern of past vulnerabilities, predominantly XSS, indicates a recurring weakness in how user input is handled. Despite the secure SQL handling, the unprotected AJAX handler and widespread output escaping issues, coupled with past vulnerabilities, indicate a significant risk.
Key Concerns
- Unprotected AJAX handler
- Low output escaping percentage
- Unsanitized path in taint flow
- One high severity vulnerability history
- Three medium severity vulnerabilities history
WP 404 Auto Redirect to Similar Post Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WP 404 Auto Redirect <= 1.0.5 - Authenticated (Admin+) Stored Cross-Site Scripting
WP 404 Auto Redirect to Similar Post <= 1.0.4 - Reflected Cross-Site Scripting via Debug Mode URI
WP 404 Auto Redirect to Similar Post <= 1.0.3 - Reflected Cross-Site Scripting via request
WP 404 Auto Redirect to Similar Post <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP 404 Auto Redirect to Similar Post Release Timeline
WP 404 Auto Redirect to Similar Post Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP 404 Auto Redirect to Similar Post Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
WP 404 Auto Redirect to Similar Post Maintenance & Trust
Maintenance Signals
Community Trust
WP 404 Auto Redirect to Similar Post Alternatives
SEO Redirection Plugin – 301 Redirect Manager
seo-redirection
SEO Redirection is a powerful redirect manager to manage 301 redirects without requiring knowledge of Apache .htaccess files.
404 ReDirector
404-redirector
Simple, SEO friendly, permanent (301) and automatic redirect of 404 errors.
CeeWP Redirect 404 to Home
ceewp-redirect-404-to-home
Automatically redirects 404 (not found) pages to your homepage with a 301 permanent redirect.
SEO404
seo404
SEO404 redirects to the Blog front page with a 301. No more 404 errors on Google/Bing/etc.
Post Redirection – 301, 404 Redirects
advance-wp-redirect
Post Redirection – 301, 404 Redirects lets you quickly redirect pages, posts, custom types, and URLs to new locations for seamless navigation.
WP 404 Auto Redirect to Similar Post Developer Profile
5 plugins · 130K total installs
How We Detect WP 404 Auto Redirect to Similar Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-404-auto-redirect-to-similar-post/css/admin.css/wp-content/plugins/wp-404-auto-redirect-to-similar-post/css/style.css/wp-content/plugins/wp-404-auto-redirect-to-similar-post/js/admin.jswp-404-auto-redirect-to-similar-post/css/admin.css?ver=wp-404-auto-redirect-to-similar-post/css/style.css?ver=wp-404-auto-redirect-to-similar-post/js/admin.js?ver=HTML / DOM Fingerprints
wp404arsp-admin-wrapperwp404arsp-debug-wrapperwp404arsp-settings-wrapper<!-- WP 404 Auto Redirect to Similar Post by hwk-fr -->data-wp404arsp-ajax-noncewp404arsp_settings