Description
Safely manage your site’s redirects the WordPress way. There are many redirect plugins available. Most of them store redirects in the options table or in custom tables. Most of them provide tons of unnecessary options. Some of them have serious performance implications (404 error logging). Safe Redirect Manager stores redirects as Custom Post Types. This makes your data portable and your website scalable. Safe Redirect Manager is built to handle enterprise level traffic and is used on major publishing websites. The plugin comes with only what you need following the WordPress mantra, decisions not options. Actions and filters make the plugin very extensible.
Configuration
There are no overarching settings for this plugin. To manage redirects, navigate to the administration panel (“Tools” > “Safe Redirect Manager”).
Each redirect contains a few fields that you can utilize:
“Redirect From”
This should be a path relative to the root of your WordPress installation. When someone visits your site with a path that matches this one, a redirect will occur. If your site is located at http://example.com/wp/ and you wanted to redirect http://example.com/wp/about to http://example.com, your “Redirect From” would be /about.
Clicking the “Enable Regex” checkbox allows you to use regular expressions in your path. There are many great tutorials on regular expressions.
You can also use wildcards in your “Redirect From” paths. By adding an * at the end of a URL, your redirect will match any request that starts with your “Redirect From”. Wildcards support replacements. This means if you have a wildcard in your from path that matches a string, you can have that string replace a wildcard character in your “Redirect To” path. For example, if your “Redirect From” is /test/*, your “Redirect To” is http://google.com/*, and the requested path is /test/string, the user would be redirect to http://google.com/string.
“Redirect To”
This should be a path (i.e. /test) or a URL (i.e. http://example.com/wp/test). If a requested path matches “Redirect From”, they will be redirected here. “Redirect To” supports wildcard and regular expression replacements.
“HTTP Status Code”
HTTP status codes are numbers that contain information about a request (i.e. whether it was successful, unauthorized, not found, etc). You should almost always use either 302 (temporarily moved) or 301 (permanently moved).
Note:
- Redirects are cached using the Transients API. Cache busts occur when redirects are added, updated, and deleted so you shouldn’t be serving stale redirects.
- By default the plugin only allows at most 1000 redirects to prevent performance issues. There is a filter
srm_max_redirectsthat you can utilize to up this number. - “Redirect From” and requested paths are case insensitive by default.
- Developers can use
srm_additional_status_codesfilter to add status codes if needed. - Rules set with 403 and 410 status codes are handled by applying the HTTP status code and render the default WordPress
wp_diescreen with an optional message. - Rules set with a 404 status code will apply the status code and render the 404 template.
- Browsers heavily cache 301 (permanently moved) redirects. It’s recommended to test your permanent redirects using the 302 (temporarily moved) status code before changing them to 301 permanently moved.
Developer Documentation
Safe Redirect Manager includes a number of actions and filters developers can make use of. These are documented on the Safe Redirect Manager developer documentation micro-site.
Screenshots




Installation
Install the plugin in WordPress. You can download a zip via GitHub and upload it using the WordPress plugin uploader (“Plugins” > “Add New” > “Upload Plugin”).
FAQ
-
Where do I report security bugs found in this plugin?
-
Please report security bugs found in the source code of the Safe Redirect Manager plugin through the Patchstack Vulnerability Disclosure Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.
Reviews
Contributors & Developers
“Safe Redirect Manager” is open source software. The following people have contributed to this plugin.
Contributors“Safe Redirect Manager” has been translated into 7 locales. Thank you to the translators for their contributions.
Translate “Safe Redirect Manager” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.3.0 – 2026-09-21
Security
- Resolve GHSA-xxq8-pr9f-w3c6 (props @dkotter, @peterwilsoncc via GHSA-xxq8-pr9f-w3c6 ).
Added
- Export redirect rules as CSV or JSON from the admin redirect list table (props @nhrrob, @thrijith, @peterwilsoncc, @dkotter via #452, #469).
- Run a
current_user_cancheck when we validate a URL to ensure the user has proper permissions (props @dkotter, @peterwilsoncc via #464).
Changed
- Bump WordPress tested-up-to version 7.1 (props @Rishabh-fueled, @dkotter, @peterwilsoncc, @phpbits, @zamanq via #418, #429, #444, #458).
- Bump WordPress minimum supported version to 6.9 (props @Rishabh-fueled, @jeffpaul, @dkotter via #419, #461).
- Update NPM dependencies via
npm audit fix(props @peterwilsoncc, @dkotter via #434).
Fixed
- Prevent duplicate redirect detection from flagging own post as a duplicate (props @peterwilsoncc, @dkotter via #438).
- PHP 8.4 deprecation warnings (props @dkotter, @jeffpaul, @peterwilsoncc via #440).
- Prevent wildcard redirects from dropping the leading slash when the source and destination bases do not include a trailing slash (props @thisismyurl, @thrijith, @dkotter, @earthlingdavey via #453).
2.2.2 – 2025-02-05
- Added: Add author ID as a new, optional argument to the
srm_create_redirectfunction. If passed, will associate this author ID to the newly created redirect (props @norcross, @dkotter via #408). - Fixed: Fix a few typos (props @szepeviktor, @jeffpaul via #407).
2.2.1 – 2024-11-13
- Changed: Bump WordPress “tested up to” version 6.7 (props @sudip-md, @jeffpaul, @mehidi258 via #403).
- Changed: Bump WordPress minimum supported version to 6.5 (props @sudip-md, @jeffpaul, @mehidi258 via #403).
- Fixed: Prevent undefined property warnings when searching redirects (props @chermant, @Sidsector9, @peterwilsoncc via #400).
- Fixed: Ensure the add new button shows proper text (props [@dkotter, @jeffpaul via #404).
2.2.0 – 2024-09-19
- Added: Option to Quick Edit and Bulk Edit redirect’s https status and force https meta (props @dhanendran, @ravinderk, @faisal-alvi, @dkotter, @qasumitbagthariya, @mehul0810, @espellcaste via #350).
- Added: Screenshots for WP.org plugin page (props @faisal-alvi, @jeffpaul, @iamdharmesh via #394).
- Changed: Bump WordPress “tested up to” version 6.6 (props @ankitguptaindia, @sudip-md via #386).
- Changed: Bump WordPress minimum supported version from 6.3 to 6.4 (props @ankitguptaindia, @sudip-md via #386).
- Changed: Update documentation (props @szepeviktor, @jeffpaul, @iamdharmesh, @dkotter via #384, #388, #391).
- Fixed: Allows use of full URLs as redirect targets when using absolute URLs (props @benlk, @peterwilsoncc via #395).
- Security: Bump
bracesfrom 3.0.2 to 3.0.3 (props @dependabot, @faisal-alvi via #383). - Security: Bump
jsdocfrom 3.6.11 to 4.0.3 (props @dependabot, @faisal-alvi via #383).
Earlier versions
For the changelog of earlier versions, please refer to the changelog on github.com.
