Zip Code Redirect Security & Risk Analysis

wordpress.org/plugins/zip-codes-redirect

Zip Code Redirect Will Check A Users Zip Code Or Post Code And Redirect The User To A Pre-determined URL Or Display A Useful Message.

90 active installs v5.3.5 PHP 8.0+ WP 6.3+ Updated Sep 13, 2025
messagepostcoderedirectwebsitezipcode
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zip Code Redirect Safe to Use in 2026?

Generally Safe

Score 100/100

Zip Code Redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "zip-codes-redirect" v5.3.5 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history suggest a history of secure development or diligent patching. The code analysis reveals excellent practices, with 100% of SQL queries using prepared statements and all output being properly escaped, significantly mitigating risks of SQL injection and Cross-Site Scripting (XSS). The presence of nonce checks on AJAX handlers further enhances security by protecting against Cross-Site Request Forgery (CSRF) attacks. The plugin's attack surface, while present with AJAX handlers and shortcodes, is not inherently concerning as there are no identified unprotected entry points. The single file operation and lack of external HTTP requests also reduce potential attack vectors. A minor point of attention is the zero capability checks; while not a direct vulnerability in this analysis, it could be a concern if the plugin's functionality were to expand and require more granular access control. Overall, this plugin appears to be developed with security in mind, demonstrating good practices in critical areas.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

Zip Code Redirect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Zip Code Redirect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
111 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped111 total outputs
Attack Surface

Zip Code Redirect Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 2

authwp_ajax_zipredirect_ajax_callzipcoderedirect.php:77
noprivwp_ajax_zipredirect_ajax_callzipcoderedirect.php:78

Shortcodes 2

[zipcoderedirect] zipcoderedirect.php:79
[zipcoderedirectplus] zipcoderedirect.php:80
WordPress Hooks 4
actionadmin_initzipcoderedirect.php:74
actionadmin_menuzipcoderedirect.php:75
actionadmin_enqueue_scriptszipcoderedirect.php:76
actionafter_uninstallzipcoderedirect.php:82
Maintenance & Trust

Zip Code Redirect Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 13, 2025
PHP min version8.0
Downloads10K

Community Trust

Rating100/100
Number of ratings4
Active installs90
Developer Profile

Zip Code Redirect Developer Profile

Paul Glover

3 plugins · 100 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zip Code Redirect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zip-codes-redirect/images/zipcode.ico

HTML / DOM Fingerprints

Shortcode Output
[zipcoderedirect][zipcoderedirectplus]
FAQ

Frequently Asked Questions about Zip Code Redirect