
WP HTTPS Redirect Security & Risk Analysis
wordpress.org/plugins/wp-https-redirectThis plugin helps you redirect HTTP traffic to HTTPS without the need of touching any code.
Is WP HTTPS Redirect Safe to Use in 2026?
Generally Safe
Score 85/100WP HTTPS Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "wp-https-redirect" v1.0.0 reveals a plugin with a minimal attack surface and seemingly strong coding practices. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points into the plugin's functionality. Furthermore, the code signals indicate a lack of dangerous functions, all SQL queries utilize prepared statements, and all outputs are properly escaped. The absence of file operations, external HTTP requests, nonce checks, and capability checks in the code analysis is also a positive sign, suggesting the plugin doesn't engage in potentially risky operations or bypass standard WordPress security mechanisms. The vulnerability history is clean, with no known CVEs recorded, further bolstering its security reputation. However, the taint analysis shows 2 flows with unsanitized paths, though these are not flagged as critical or high severity. While the absence of vulnerabilities and attack vectors is excellent, the presence of unsanitized paths in taint analysis, even if low severity, suggests a potential for subtle issues that might not have manifested as exploitable vulnerabilities yet. The lack of capability checks and nonce checks, while seemingly good due to the lack of direct entry points, could become a concern if functionality were ever added or if the plugin interacted with other components in unintended ways.
Key Concerns
- Flows with unsanitized paths
WP HTTPS Redirect Security Vulnerabilities
WP HTTPS Redirect Code Analysis
Data Flow Analysis
WP HTTPS Redirect Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP HTTPS Redirect Maintenance & Trust
Maintenance Signals
Community Trust
WP HTTPS Redirect Alternatives
WP Force SSL & HTTPS SSL Redirect
wp-force-ssl
Enable SSL & HTTPS redirect with 1 click! Add SSL certificate & WP Force SSL to redirect site from HTTP to HTTPS & fix SSL errors.
Auto-Install Free SSL – Generate & Install Free SSL Certificates
auto-install-free-ssl
Generate & install Free SSL Certificates for WordPress, HTTPS redirect, get PADLOCK in the browser, get automatic Renewal Reminders from plugin.
NertWorks Site Wide SSL
nertworks-site-wide-ssl
Enforce SSL throughout the entire site. Supporting multiple methods. Can be used on the Front End of the site of the Admin Dashboard
Force User SSL
force-user-ssl
This plugin forces logged in users to use SSL.
Easy HTTPS Redirection (SSL)
https-redirection
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
WP HTTPS Redirect Developer Profile
1 plugin · 0 total installs
How We Detect WP HTTPS Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapabout-wrap