
WP Simple Redirect Security & Risk Analysis
wordpress.org/plugins/wp-simple-redirectCreate short links and redirect in your WordPress dashboard, both simple links as well as regular expression matching.
Is WP Simple Redirect Safe to Use in 2026?
Use With Caution
Score 63/100WP Simple Redirect has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-simple-redirect plugin, despite having a small attack surface with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events, exhibits significant security concerns primarily stemming from its code signals and vulnerability history. The presence of the `unserialize` function, coupled with 100% of its SQL queries using prepared statements and a single nonce check, points to a mixed bag of security practices. However, the critical weakness lies in its output escaping, where 0% of outputs are properly escaped. This, combined with three identified flows with unsanitized paths, creates a high risk for Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history further amplifies these concerns, with one currently unpatched medium-severity CVE related to XSS, last discovered in 2026. This indicates a recurring pattern of input sanitization and output escaping issues that have not been fully addressed. While the use of prepared statements for SQL is a positive, the lack of comprehensive output escaping and the documented XSS vulnerability present a substantial risk that requires immediate attention.
Key Concerns
- Unpatched medium severity CVE (XSS)
- 0% of outputs properly escaped
- 3 flows with unsanitized paths
- Dangerous function unserialize present
- No capability checks
WP Simple Redirect Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Redirect <= 1.1 - Reflected Cross-Site Scripting
WP Simple Redirect Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Simple Redirect Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Simple Redirect Maintenance & Trust
Maintenance Signals
Community Trust
WP Simple Redirect Alternatives
Permalink Manager for WooCommerce
permalink-manager-for-woocommerce
Permalink Manager for WooCommerce improves your store permalinks and remove product, product_category and product_tag slugs from the URL.
Bulk Edit YOAST SEO fields in Spreadsheet
wp-sheet-editor-yoast-seo
Bulk Edit posts, pages, and WooCommerce products YOAST SEO fields using a spreadsheet.
Append extensions on Pages
append-extensions-on-pages
This plugin helps to appends .html or .asp or .htm etc on the wordpress pages when used with permalink.
Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress
plugins-on-steroids
Powerful Plugin Management Solution for WordPress
Pages Children
pages-children
[Plugin Homepage](http://www.codehooligans.com/projects/wordpress/pages-children/ "Pages-Children Plugin for WordPress")
WP Simple Redirect Developer Profile
4 plugins · 110 total installs
How We Detect WP Simple Redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-simple-redirect/core/css/admin.css/wp-content/plugins/wp-simple-redirect/core/css/common.css/wp-content/plugins/wp-simple-redirect/core/js/common.js/wp-content/plugins/wp-simple-redirect/core/js/common.jswp-simple-redirect/core/css/admin.css?ver=wp-simple-redirect/core/css/common.css?ver=wp-simple-redirect/core/js/common.js?ver=HTML / DOM Fingerprints
ArevicoRegistryArevicoSQA