{"id":315366,"date":"2026-05-22T03:49:59","date_gmt":"2026-05-22T03:49:59","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/easy-url-blocker\/"},"modified":"2026-09-27T12:36:48","modified_gmt":"2026-09-27T12:36:48","slug":"pathguard-redirects","status":"publish","type":"plugin","link":"https:\/\/haz.wordpress.org\/plugins\/pathguard-redirects\/","author":23189174,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"PathGuard Redirects","header_author":"Samrat Hossen","header_description":"Block specific relative URLs and redirect visitors to a custom destination. Admins are never redirected.","assets_banners_color":"3b9aca","last_updated":"2026-09-27 12:36:48","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":260,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"emily50","date":"2026-05-22 03:49:41","revision":3543049},"1.1.0":{"tag":"1.1.0","author":"emily50","date":"2026-09-27 12:36:48","revision":3715486}},"upgrade_notice":{"1.1.0":"<p>Fixes external redirects and URL-encoded path matching. Settings are now kept on deactivation. Saved rules are normalised to lowercase paths the next time you save.<\/p>","1.0.0":"<p>Initial release \u2014 no upgrade steps required.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3543071,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-772x250.png":{"filename":"banner-772x250.png","revision":3543071,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"The PathGuard Redirects settings page showing the blocked URLs list, redirect action selector, and Exclude Admins option.","2":"The Settings action link on the WordPress Plugins list page."}},"plugin_section":[],"plugin_tags":[1912,263896,727,600,263895],"plugin_category":[54],"plugin_contributors":[254156],"plugin_business_model":[],"class_list":["post-315366","plugin","type-plugin","status-publish","hentry","plugin_tags-access-control","plugin_tags-block-pages","plugin_tags-redirect","plugin_tags-security","plugin_tags-url-blocker","plugin_category-security-and-spam-protection","plugin_contributors-emily50","plugin_committers-emily50"],"banners":{"banner":"https:\/\/ps.w.org\/pathguard-redirects\/assets\/banner-772x250.png?rev=3543071","banner_2x":false,"banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/pathguard-redirects\/assets\/icon-256x256.png?rev=3543071","icon_2x":"https:\/\/ps.w.org\/pathguard-redirects\/assets\/icon-256x256.png?rev=3543071","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>PathGuard Redirects is a lightweight, developer-friendly plugin that lets site administrators block any relative URL on their WordPress site and control exactly what happens when a visitor tries to access it.<\/p>\n\n<p><strong>How it works<\/strong><\/p>\n\n<p>Add the relative paths you want to block (one per line) and choose what should happen when someone visits them:<\/p>\n\n<ul>\n<li><strong>Custom URL redirect<\/strong> \u2014 send visitors to any destination URL with a 302 redirect.<\/li>\n<li><strong>404 Not Found<\/strong> \u2014 serve your theme's native 404 page with a proper HTTP 404 status header (no redirect, the URL stays the same).<\/li>\n<\/ul>\n\n<p><strong>Key features<\/strong><\/p>\n\n<ul>\n<li>Block any number of relative paths (e.g. <code>\/secret-page\/<\/code>, <code>\/members-only\/<\/code>).<\/li>\n<li>Choose the redirect action per-site: custom URL or 404 page.<\/li>\n<li><strong>Exclude Admins<\/strong> \u2014 logged-in administrators are bypassed by default so they always have access. The option can be unchecked to restrict admins too.<\/li>\n<li>One-click access via the <strong>Settings<\/strong> link on the Plugins list page.<\/li>\n<li>Settings are kept when the plugin is deactivated and removed from the database when it is deleted.<\/li>\n<li>Paths are matched with or without a trailing slash and regardless of case \u2014 <code>\/secret-page<\/code>, <code>\/secret-page\/<\/code> and <code>\/Secret-Page\/<\/code> all match.<\/li>\n<li>URL-encoded paths are decoded before matching, preventing bypass attempts like <code>\/%73ecret-page\/<\/code>. Non-ASCII paths (e.g. <code>\/caf\u00e9\/<\/code>) are supported.<\/li>\n<li>Full URLs pasted into the list are converted to paths on save.<\/li>\n<li>Page caches are purged when the rules change (WP Super Cache, WP Rocket, W3 Total Cache, LiteSpeed Cache; other caches can use the <code>pathguard_redirects_rules_updated<\/code> action).<\/li>\n<\/ul>\n\n<p><strong>Security<\/strong><\/p>\n\n<ul>\n<li>CSRF protection on every save using WordPress nonces.<\/li>\n<li>Strict capability check (<code>manage_options<\/code>) before processing any form data.<\/li>\n<li>All input is sanitised (<code>sanitize_text_field<\/code>, <code>esc_url_raw<\/code>, <code>sanitize_key<\/code>).<\/li>\n<li>All output is escaped (<code>esc_textarea<\/code>, <code>esc_attr<\/code>, <code>esc_html_e<\/code>).<\/li>\n<li>The redirect destination can only be set by administrators; visitors cannot influence where they are sent.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>pathguard-redirects<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen in WordPress.<\/li>\n<li>Go to <strong>Settings \u2192 PathGuard Redirects<\/strong> (or click the <strong>Settings<\/strong> link on the Plugins page).<\/li>\n<li>Enter the relative URLs you want to block, choose a redirect action, and click <strong>Save Settings<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20url%20format%20should%20i%20use%20in%20the%20blocked%20urls%20list%3F\"><h3>What URL format should I use in the blocked URLs list?<\/h3><\/dt>\n<dd><p>Enter paths relative to your site home, one per line. Example:<\/p>\n\n<pre><code>\/secret-page\/\n\/members-only\/\n\/private-area\/\n<\/code><\/pre>\n\n<p>If you paste a full URL, it is converted to its path when you save. Paths are matched with or without a trailing slash and regardless of case.<\/p>\n\n<p>If WordPress is installed in a subdirectory (e.g. <code>https:\/\/example.com\/blog\/<\/code>), enter paths relative to that directory: <code>\/secret-page\/<\/code>, not <code>\/blog\/secret-page\/<\/code>.<\/p><\/dd>\n<dt id=\"will%20administrators%20be%20blocked%3F\"><h3>Will administrators be blocked?<\/h3><\/dt>\n<dd><p>No \u2014 by default the <strong>Exclude Admins<\/strong> option is enabled, which means logged-in users with the <code>manage_options<\/code> capability can always access blocked URLs. You can uncheck this option to apply blocking to administrators as well.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20the%20two%20redirect%20actions%3F\"><h3>What is the difference between the two redirect actions?<\/h3><\/dt>\n<dd><ul>\n<li><strong>Custom URL (302 redirect)<\/strong> \u2014 the visitor's browser is redirected to the URL you specify. The blocked URL disappears from the address bar.<\/li>\n<li><strong>Not Found (404 page)<\/strong> \u2014 the browser stays on the blocked URL but receives an HTTP 404 status and sees your theme's 404 template. No redirect occurs.<\/li>\n<\/ul><\/dd>\n<dt id=\"can%20i%20redirect%20to%20another%20website%3F\"><h3>Can I redirect to another website?<\/h3><\/dt>\n<dd><p>Yes. Enter any full URL (e.g. <code>https:\/\/example.com\/<\/code>). You can also enter a path such as <code>\/home\/<\/code>, which is resolved against your site home.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20choose%20%22custom%20url%22%20but%20leave%20the%20destination%20field%20blank%3F\"><h3>What happens if I choose \"Custom URL\" but leave the destination field blank?<\/h3><\/dt>\n<dd><p>The plugin falls back to serving the 404 page so the blocked URL is never accidentally left accessible. The same happens if the destination is itself a blocked URL, which would otherwise cause a redirect loop; the settings page shows a warning in that case.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20affect%20rest%20api%20or%20admin%20requests%3F\"><h3>Does this plugin affect REST API or admin requests?<\/h3><\/dt>\n<dd><p>No. The block logic runs on the <code>template_redirect<\/code> hook which only fires for standard frontend page requests. REST API, WP-CLI, and admin requests are unaffected.<\/p><\/dd>\n<dt id=\"does%20blocking%20a%20url%20make%20its%20content%20private%3F\"><h3>Does blocking a URL make its content private?<\/h3><\/dt>\n<dd><p>No. PathGuard Redirects blocks the URL, not the content. A blocked page's content can still be reachable through the REST API (e.g. <code>\/wp-json\/wp\/v2\/pages<\/code>), RSS feeds, site search, and XML sitemaps. To keep content private, set the post to Private or password-protect it.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20page%20caching%3F\"><h3>Does it work with page caching?<\/h3><\/dt>\n<dd><p>The plugin purges supported page caches when you save, so pages cached before a rule was added are not served. Caches that run outside WordPress (server-level caches such as Varnish or Nginx FastCGI cache, or a CDN) must be purged manually after changing rules.<\/p><\/dd>\n<dt id=\"will%20my%20settings%20be%20lost%20if%20i%20deactivate%20the%20plugin%3F\"><h3>Will my settings be lost if I deactivate the plugin?<\/h3><\/dt>\n<dd><p>No. Settings are kept on deactivation. They are removed from the database only when you delete the plugin from the Plugins screen.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20block%20query%20strings%3F\"><h3>Does the plugin block query strings?<\/h3><\/dt>\n<dd><p>No. Only the path portion of the URL is compared (e.g. <code>\/secret-page\/<\/code>). Query strings like <code>?preview=true<\/code> are ignored, which means <code>\/secret-page\/?anything=value<\/code> is still blocked by the rule <code>\/secret-page\/<\/code>.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Fix: Custom URL redirects to external domains no longer send visitors to wp-admin.<\/li>\n<li>Fix: Percent-encoded paths (e.g. <code>\/%73ecret-page\/<\/code>) and non-ASCII paths (e.g. <code>\/caf\u00e9\/<\/code>) are now matched correctly.<\/li>\n<li>Fix: 404 action no longer breaks on classic themes without a 404.php template.<\/li>\n<li>Fix: Relative redirect destinations such as <code>\/home\/<\/code> can now be saved.<\/li>\n<li>Fix: Destination URLs keep their percent-encoding when saved.<\/li>\n<li>Change: Settings are kept on deactivation and removed only when the plugin is deleted.<\/li>\n<li>New: Path matching is case-insensitive and supports WordPress installed in a subdirectory.<\/li>\n<li>New: Full URLs and paths without a leading slash are normalised on save; duplicates are removed.<\/li>\n<li>New: Relative redirect destinations are resolved against the site home.<\/li>\n<li>New: Falls back to the 404 page, with a settings warning, if the destination is itself blocked.<\/li>\n<li>New: Supported page caches are purged when rules change; new <code>pathguard_redirects_rules_updated<\/code> action.<\/li>\n<li>Tweak: Settings page script is now enqueued properly.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Block relative URLs with per-line textarea input.<\/li>\n<li>Redirect action: Custom URL (302) or 404 page.<\/li>\n<li>Exclude Admins option, pre-enabled on activation.<\/li>\n<li>Settings link on the Plugins list page.<\/li>\n<li>Automatic database cleanup on deactivation.<\/li>\n<li>URL-encoding bypass protection via <code>rawurldecode()<\/code>.<\/li>\n<li>CSRF, capability, and sanitisation hardening.<\/li>\n<\/ul>","raw_excerpt":"Block specific relative URLs on your site and redirect visitors to a custom destination or your theme&#039;s 404 page.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/315366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=315366"}],"author":[{"embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/emily50"}],"wp:attachment":[{"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=315366"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=315366"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=315366"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=315366"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=315366"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/haz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=315366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}