WordPress.Security.SafeRedirect.wp_redirect_wp_redirect

wp redirect wp redirect

Plugin Check reported a security-sensitive coding pattern that needs review.

critical weight

Why It Shows Up

The finding came from a security-focused WordPress coding standard or Plugin Check rule.

Why It Matters

Security findings often involve trust boundaries: request input, browser output, redirects, database access, capabilities, or filesystem behavior.

How to Fix

  • Identify the untrusted value or privileged action involved.
  • Add validation, sanitization, escaping, nonce checks, capability checks, or prepared SQL as appropriate.
  • Rerun Plugin Check after the code path is fixed.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1Themify Builder95,1952,0965k+Text Domain Mismatch
#2JetBackup – Backup, Restore & Migrate101,559145100k+Exception Not Escaped
#3AnyComment174454495k+Output Not Escaped
#4WPtouch – Make your WordPress Website Mobile-Friendly171,46632550k+Text Domain Mismatch
#5Prime Slider Addons for Elementor183,500230100k+Text Domain Mismatch
#6Podlove Podcast Publisher182,3261,4293k+Output Not Escaped
#7Property Hive181,9576,0273k+Missing
#8Shopping Cart & eCommerce Store185,45917,2984k+Non Prefixed Variable Found
#9WP Directory Kit182,1192,6172k+Non Prefixed Variable Found
#10Element Pack – Widgets, Templates & Addons for Elementor199,448517100k+Text Domain Mismatch
#11Block Slider – Responsive Image Slider, Video Slider & Post Slider195551,2913k+Non Prefixed Variable Found
#12Download Monitor194251,36480k+Non Prefixed Hookname Found
#13Event Organiser191,10654420k+Text Domain Mismatch
#14Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution191,218901100k+Exception Not Escaped
#15Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)193,2753,22810k+Output Not Escaped
#16Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization191,2952,6799k+Output Not Escaped
#17Razorpay Payment Button Plugin19486982k+Exception Not Escaped
#18Realtyna Organic IDX plugin + WPL Real Estate199473,6532k+Non Prefixed Variable Found
#19Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#20Membership Plugin – Kadence Memberships195,0822,9829k+Text Domain Mismatch
#21Scrollsequence – Cinematic Scroll Image Animation Plugin198781,5284k+Non Prefixed Variable Found
#22SendPress Newsletters192,2931,4222k+Output Not Escaped
#23Brizy – Page Builder2058972070k+Output Not Escaped
#24DMCA Protection Badge204,4252171k+Output Not Escaped
#25Filter Everything — WordPress & WooCommerce Filters2056873050k+Output Not Escaped
#26GiveWP – Donation Plugin and Fundraising Platform203,4353,580100k+Output Not Escaped
#27Link Library201,9411,39710k+Unsafe Printing Function
#28MBE eShip205277401k+Non Prefixed Variable Found
#29Brevo – Email, SMS, Web Push, Chat, and more.20460646100k+Missing Unslash
#30MAS Videos205191,6931k+Non Prefixed Variable Found
#31Microthemer Lite – Visual Editor to Customize CSS201,0041,69910k+Non Prefixed Variable Found
#32Quill Forms | Conversational Multi Step Forms, Surveys & quizzes204013683k+Text Domain Mismatch
#33Remove Add to Cart WooCommerce206161,3784k+Non Prefixed Variable Found
#34Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF20557541100k+Output Not Escaped
#35Trace My IP – Visitor IP Tracker, Stats Analytics & Page Views Counter with Email Alerts208663381k+wp function not compatible with requires wp
#36Razorpay for WooCommerce20974855100k+Non Prefixed Function Found
#37WPJAM Basic203283564k+Output Not Escaped
#38Backup Migration219811,09380k+Non Prefixed Variable Found
#39CallTrackingMetrics219232863k+Unsafe Printing Function
#40Smart Grid-Layout Design for Contact Form 7211,12673410k+Output Not Escaped
#41Comet Cache2185724520k+Output Not Escaped
#42Free Downloads WooCommerce214303594k+Output Not Escaped
#43Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More212,5721,2771m+Output Not Escaped
#44Envo Extra2187860020k+Text Domain Mismatch
#45ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support218295,9665k+Direct Query
#46Eupago Gateway For Woocommerce216123202k+Output Not Escaped
#47EventPrime – Events Calendar, Bookings and Tickets218724,2977k+Non Prefixed Variable Found
#48Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More21521,959300k+Non Prefixed Variable Found
#49Campaign Monitor for WordPress213864612k+Non Prefixed Variable Found
#50If-So Dynamic Content – Elementor & All Page Builders Personalization218897257k+Unsafe Printing Function