Title: PathGuard Redirects
Author: MD. Samrat Hossen
Published: <strong>22. meje 2026</strong>
Last modified: 22. meje 2026

---

Tykače pytać

![](https://ps.w.org/pathguard-redirects/assets/banner-772x250.png?rev=3543071)

![](https://ps.w.org/pathguard-redirects/assets/icon-256x256.png?rev=3543071)

# PathGuard Redirects

 Wot [MD. Samrat Hossen](https://profiles.wordpress.org/emily50/)

[Sćahnyć](https://downloads.wordpress.org/plugin/pathguard-redirects.1.0.0.zip)

 * [Podrobnosće](https://hsb.wordpress.org/plugins/pathguard-redirects/#description)
 * [Pohódnoćenja](https://hsb.wordpress.org/plugins/pathguard-redirects/#reviews)
 *  [Instalacija](https://hsb.wordpress.org/plugins/pathguard-redirects/#installation)
 * [Wuwiće](https://hsb.wordpress.org/plugins/pathguard-redirects/#developers)

 [Podpěra](https://wordpress.org/support/plugin/pathguard-redirects/)

## Wopisanje

URL Blocker is a lightweight, developer-friendly plugin that lets site administrators
block any relative URL on their WordPress site and control exactly what happens 
when a visitor tries to access it.

**How it works**

Add the relative paths you want to block (one per line) and choose what should happen
when someone visits them:

 * **Custom URL redirect** — send visitors to any destination URL with a 302 redirect.
 * **404 Not Found** — serve your theme’s native 404 page with a proper HTTP 404
   status header (no redirect, the URL stays the same).

**Key features**

 * Block any number of relative paths (e.g. `/secret-page/`, `/members-only/`).
 * Choose the redirect action per-site: custom URL or 404 page.
 * **Exclude Admins** — logged-in administrators are bypassed by default so they
   always have access. The option can be unchecked to restrict admins too.
 * One-click access via the **Settings** link on the Plugins list page.
 * All plugin data is removed from the database automatically when the plugin is
   deactivated.
 * Paths matched with and without trailing slash — `/secret-page` and `/secret-page/`
   both work.
 * URL-encoded paths are decoded before matching, preventing bypass attempts like`/%
   73ecret-page/`.

**Security**

 * CSRF protection on every save using WordPress nonces.
 * Strict capability check (`manage_options`) before processing any form data.
 * All input is sanitised (`sanitize_textarea_field`, `esc_url_raw`, `sanitize_key`).
 * All output is escaped (`esc_textarea`, `esc_attr`, `esc_html_e`).
 * Uses `wp_safe_redirect` to prevent open-redirect abuse.

## Instalacija

 1. Upload the `pathguard-redirects` folder to `/wp-content/plugins/`.
 2. Activate the plugin through the **Plugins** screen in WordPress.
 3. Go to **Settings  URL Blocker** (or click the **Settings** link on the Plugins 
    page).
 4. Enter the relative URLs you want to block, choose a redirect action, and click **
    Save Settings**.

## HSP

### What URL format should I use in the blocked URLs list?

Enter relative paths starting with `/`, one per line. Example:

    ```
    /secret-page/
    /members-only/
    /private-area/
    ```

Do not include the domain name. Paths are matched with or without a trailing slash,
so `/secret-page` and `/secret-page/` are treated as the same rule.

### Will administrators be blocked?

No — by default the **Exclude Admins** option is enabled, which means logged-in 
users with the `manage_options` capability can always access blocked URLs. You can
uncheck this option to apply blocking to administrators as well.

### What is the difference between the two redirect actions?

 * **Custom URL (302 redirect)** — the visitor’s browser is redirected to the URL
   you specify. The blocked URL disappears from the address bar.
 * **Not Found (404 page)** — the browser stays on the blocked URL but receives 
   an HTTP 404 status and sees your theme’s 404 template. No redirect occurs.

### What happens if I choose „Custom URL“ but leave the destination field blank?

The plugin falls back to serving the 404 page so the blocked URL is never accidentally
left accessible.

### Does this plugin affect REST API or admin requests?

No. The block logic runs on the `template_redirect` hook which only fires for standard
frontend page requests. REST API, WP-CLI, and admin requests are unaffected.

### Will my settings be lost if I deactivate the plugin?

Yes. The plugin removes all its stored options from the database on deactivation.
This keeps your database clean. If you need to keep your settings, do not deactivate—
simply disable blocking by leaving the blocked URLs list empty.

### Does the plugin block query strings?

No. Only the path portion of the URL is compared (e.g. `/secret-page/`). Query strings
like `?preview=true` are ignored, which means `/secret-page/?anything=value` is 
still blocked by the rule `/secret-page/`.

## Pohódnoćenja

Za tutón tykač pohódnoćenja njejsu.

## Sobuskutkowarjo a wuwiwarjo

„PathGuard Redirects“ je softwara wotewrjeneho žórła. Slědowacy ludźo su k tutomu
tykačej přinošowali.

Sobuskutkowarjo

 *   [ MD. Samrat Hossen ](https://profiles.wordpress.org/emily50/)

[Přełožće „PathGuard Redirects“ do swojeje rěče.](https://translate.wordpress.org/projects/wp-plugins/pathguard-redirects)

### Na wuwiću zajimowany?

[Přehladajće kod](https://plugins.trac.wordpress.org/browser/pathguard-redirects/),
hladajće do [SVN-repozitorija](https://plugins.svn.wordpress.org/pathguard-redirects/)
abo abonujće [wuwiwanski protokol](https://plugins.trac.wordpress.org/log/pathguard-redirects/)
přez [RSS](https://plugins.trac.wordpress.org/log/pathguard-redirects/?limit=100&mode=stop_on_copy&format=rss).

## Protokol změnow

#### 1.0.0

 * Initial release.
 * Block relative URLs with per-line textarea input.
 * Redirect action: Custom URL (302) or 404 page.
 * Exclude Admins option, pre-enabled on activation.
 * Settings link on the Plugins list page.
 * Automatic database cleanup on deactivation.
 * URL-encoding bypass protection via `rawurldecode()`.
 * CSRF, capability, and sanitisation hardening.

## Meta

 *  Version **1.0.0**
 *  Last updated **2 njedźeli**
 *  Active installations **Mjenje hač 10**
 *  WordPress version ** 5.8 abo nowši **
 *  Tested up to **6.9.4**
 *  PHP version ** 7.4 abo nowši **
 *  Language
 * [English (US)](https://wordpress.org/plugins/pathguard-redirects/)
 * Tags
 * [access-control](https://hsb.wordpress.org/plugins/tags/access-control/)[redirect](https://hsb.wordpress.org/plugins/tags/redirect/)
   [security](https://hsb.wordpress.org/plugins/tags/security/)
 *  [Rozšěrjeny napohlad](https://hsb.wordpress.org/plugins/pathguard-redirects/advanced/)

## Pohódnoćenja

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/pathguard-redirects/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/pathguard-redirects/reviews/)

## Sobuskutkowarjo

 *   [ MD. Samrat Hossen ](https://profiles.wordpress.org/emily50/)

## Podpěra

Chceće něšto prajić? Trjebaće pomoc?

 [Forum pomocy pokazać](https://wordpress.org/support/plugin/pathguard-redirects/)