PLUGIN SECURITY
Is Redirection safe?
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
What this plugin does
- Slug:
redirection - Author: John Godley
- 2000000+ active installs
- 88/100 rating (702 reviews on wordpress.org)
- 76788190 all-time downloads
- On WordPress.org since 2007-09-10
301404Apachehtaccessredirect
Maintenance status
- Latest known version: 5.9.0
- Last updated: 2026-07-11 12:51pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
4 known CVEs on file for Redirection. Reported between 2011 and 2018.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Redirection [redirection] < 3.6.4 | — | Unknown | < 3.6.4 | 3.6.4 | 2018-12-06 | ✓ fixed in latest |
| — | Redirection [redirection] < 3.6.4 | — | Unknown | < 3.6.4 | 3.6.4 | 2018-11-14 | ✓ fixed in latest |
| CVE-2018-1000504 | Redirection [redirection] < 2.8 | URL Redirection to Untrusted Site ('Open Redirect') | High 7.2 | < 2.8 | 2.8 | 2018-06-26 | ✓ fixed in latest |
| — | Redirection [redirection] < 2.8 | — | Unknown | < 2.8 | 2.8 | 2018-06-20 | ✓ fixed in latest |
| — | Redirection [redirection] < 2.3.4 | — | Unknown | < 2.3.4 | 2.3.4 | 2015-05-15 | ✓ fixed in latest |
| — | Redirection [redirection] < 2.2.9 | — | Unknown | < 2.2.9 | 2.2.9 | 2015-05-15 | ✓ fixed in latest |
| CVE-2011-5329 | Redirection [redirection] < 2.2.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.2.9 | 2.2.9 | 2014-08-01 | ✓ fixed in latest |
| CVE-2012-6717 | Redirection [redirection] < 2.2.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.2.12 | 2.2.12 | 2012-05-04 | ✓ fixed in latest |
+ 7 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2011-4562 | Redirection [redirection] < 2.2.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 2.2.10 | 2.2.10 | 2011-11-28 | ✓ fixed in latest |
| — | Redirection [redirection] < 3.6.3 | — | Unknown | < 3.6.3 | 3.6.3 | — | ✓ fixed in latest |
| — | Redirection [redirection] < 2.8 | — | Unknown | < 2.8 | 2.8 | — | ✓ fixed in latest |
| — | Redirection [redirection] < 2.3.4 | — | Unknown | < 2.3.4 | 2.3.4 | — | ✓ fixed in latest |
| — | Redirection 2.3.3 - view/admin/item.php URL Handling Reflected XSS | — | Unknown | < 2.3.4 | 2.3.4 | — | ✓ fixed in latest |
| — | Redirection < 2.8 - Authenticated Local File Inclusion | — | Unknown | < 2.8 | 2.8 | — | ✓ fixed in latest |
| — | Redirection <= 3.6.2 - Cross-Site Request Forgery (CSRF) | — | Unknown | < 3.6.3 | 3.6.3 | — | ✓ fixed in latest |
How to fix it
Keep Redirection updated — 5.9.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Broken Link Checker by AIOSEO – Find & Fix Broken Internal, External & Video Links — 300000+ active installs — 78/100 (83) — max PHP 8.4
- Redirection — 100000+ active installs — 100/100 (409) — max PHP 8.4
- Smart Custom 404 Error Page — 100000+ active installs — 98/100 (1196) — max PHP 8.4
- 404 to 301 – Redirect Manager, 404 Error Logs & Notifications — 100000+ active installs — 94/100 (311) — max PHP 8.4
- WP 404 Auto Redirect to Similar Post — 30000+ active installs — 98/100 (113) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.