
WP Force SSL & HTTPS SSL Redirect Security & Risk Analysis
wordpress.org/plugins/wp-force-sslEnable SSL & HTTPS redirect with 1 click! Add SSL certificate & WP Force SSL to redirect site from HTTP to HTTPS & fix SSL errors.
Is WP Force SSL & HTTPS SSL Redirect Safe to Use in 2026?
Generally Safe
Score 99/100WP Force SSL & HTTPS SSL Redirect has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-force-ssl plugin exhibits a generally strong security posture, adhering to several good coding practices. Notably, there are no detected dangerous functions, all SQL queries utilize prepared statements, and the vast majority of output is properly escaped. The presence of nonce and capability checks on all identified AJAX handlers is a significant strength, as is the complete absence of REST API routes, shortcodes, and cron events, which limits the plugin's attack surface. The plugin also makes external HTTP requests, which are a potential area of concern but are not inherently a vulnerability. The vulnerability history shows a single medium-severity CVE in the past, which has been patched. This indicates that while past issues have occurred, the developers have a history of addressing them.
However, there are areas for improvement. The plugin's attack surface, while limited to AJAX handlers, could be further scrutinized for any implicit assumptions about user roles or permissions that might not be explicitly enforced through capability checks. The two external HTTP requests, while not flagged as a vulnerability in the static analysis, represent potential vectors for supply chain attacks or information leakage if not handled with extreme care regarding the sources and content of these requests. The absence of taint analysis results is common for smaller plugins but would be a more comprehensive way to assess the handling of user-supplied data. Overall, wp-force-ssl appears to be a relatively secure plugin, but vigilance regarding external requests and thorough review of all authorization mechanisms remain important.
Key Concerns
- External HTTP requests detected
- One medium CVE historically
WP Force SSL & HTTPS SSL Redirect Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Force SSL & HTTPS SSL Redirect <= 1.66 - Missing Authorization to Settings Update
WP Force SSL & HTTPS SSL Redirect Code Analysis
Output Escaping
WP Force SSL & HTTPS SSL Redirect Attack Surface
AJAX Handlers 4
WordPress Hooks 19
Maintenance & Trust
WP Force SSL & HTTPS SSL Redirect Maintenance & Trust
Maintenance Signals
Community Trust
WP Force SSL & HTTPS SSL Redirect Alternatives
SSL Zen — SSL Certificate Installer & HTTPS Redirects
ssl-zen
Helps install a free Let's Encrypt SSL certificate, redirects HTTP to HTTPS and forces SSL on all pages.
SSL Mixed Content Fix
http-https-remover
A fix for mixed content! This Plugin creates protocol relative urls by removing http + https from links. Works in Front- and Backend!
Easy HTTPS Redirection (SSL)
https-redirection
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
SSL Insecure Content Fixer
ssl-insecure-content-fixer
Clean up WordPress website HTTPS insecure content
One Click SSL
one-click-ssl
Enable SSL/TLS (https://) to redirect all pages to SSL/TLS and load all resources over SSL/TLS.
WP Force SSL & HTTPS SSL Redirect Developer Profile
28 plugins · 3.5M total installs
How We Detect WP Force SSL & HTTPS SSL Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-force-ssl/css/wpfs-style.css/wp-content/plugins/wp-force-ssl/css/sweetalert2.min.css/wp-content/plugins/wp-force-ssl/js/wpfs-pointers.js/wp-content/plugins/wp-force-ssl/js/wpfs-sweetalert2.js/wp-content/plugins/wp-force-ssl/js/wpfs-admin.js/wp-content/plugins/wp-force-ssl/js/wpfs-pointers.js/wp-content/plugins/wp-force-ssl/js/wpfs-sweetalert2.js/wp-content/plugins/wp-force-ssl/js/wpfs-admin.jswp-force-ssl/css/wpfs-style.css?ver=wp-force-ssl/css/sweetalert2.min.css?ver=wp-force-ssl/js/wpfs-pointers.js?ver=wp-force-ssl/js/wpfs-sweetalert2.js?ver=wp-force-ssl/js/wpfs-admin.js?ver=HTML / DOM Fingerprints
Thank you for installing the <b style="font-weight: 800;">WP Force SSL</b> plugin!<br>Open <a href="">Settings - WP Force SSL</a> to access SSL settings.wp_force_ssl_pointerswp_force_ssl_pointers