HTTPS redirection plugins intercept incoming requests, decide the target scheme, and issue redirects while reading proxy and forwarded headers. Easy HTTPS Redirection (SSL) version 2.0.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65704, confirming that the review focused on redirect target handling, settings storage, capability and nonce checks, and safe processing of proxy and forwarded headers.
| Name of | Easy HTTPS Redirection (SSL) |
| Version | 2.0.1 |
| Active installations | 100,000+ |
| Description | Automatically redirects HTTP requests to HTTPS site-wide or per-page, with full-site or partial redirection modes and support for sites behind load balancers and reverse proxies. |
| Security | Successfully tested for: SQL Injection (SQLi) Cross-Site Scripting (XSS) – Stored and Reflected Cross-Site Request Forgery (CSRF) Authentication Vulnerabilities Authentication Bypass Exploits Privilege Escalation Buffer Overflow Denial-of-Service (DoS) vectors Data Leakage Vulnerabilities Insecure Dependency Usage Remote Code Execution (RCE) Risks Unauthorized File Access Insufficient Injection Protection Information Disclosure via Misconfigured Endpoints |
| CleanTalk Certification | Proudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards. |
| Additional Information | Use Easy HTTPS Redirection with confidence backed by the “Plugin Security Certification” (PSC). Install a valid SSL certificate first, choose full-site redirection where possible, and verify the correct behavior behind any CDN or reverse proxy. |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Key Features
Easy HTTPS Redirection forces visitors onto HTTPS without manual .htaccess edits. Administrators can enable full-site redirection or restrict it to specific pages, and the plugin adapts to sites served through load balancers and reverse proxies where the original scheme arrives in a forwarded header. Settings are managed from a single options page in the WordPress admin.
Security Assurance
The CleanTalk Plugin Security Certification evaluation focused on how the plugin builds and issues redirects, the storage and sanitization of its options, capability checks and nonce validation on the settings page, and the safe handling of proxy and forwarded headers so that scheme detection cannot be abused. The review also considered protection against open redirect behavior and header injection in the redirect response.
The plugin has been successfully tested for:
✅ Information Leakage Vulnerabilities
✅ SQL Injection Vulnerabilities
✅ Cross-Site Scripting (XSS) Attacks
✅ Cross-Site Request Forgery (CSRF) Attacks
✅ Authentication and Authentication Bypass Vulnerabilities
✅ Privilege Escalation Vulnerabilities
✅ Buffer Overflow Vulnerabilities
✅ Denial-of-Service (DoS) Vulnerabilities
✅ Data Leakage Vulnerabilities
✅ Insecure Dependencies
✅ Code Execution Vulnerabilities
✅ File Unauthorized Access Vulnerabilities
✅ Insufficient Injection Protection
Conclusion
With PSC-2026-65704, Easy HTTPS Redirection (SSL) version 2.0.1 demonstrates strong baseline security for its redirection workflows. The certification addresses redirect target handling, settings integrity, request validation, and safe processing of proxy headers. Site owners should ensure a valid SSL certificate is installed, prefer full-site redirection, and confirm correct behavior behind any CDN or proxy layer.
Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.
