How to Create and Manage Redirects in EmDash Without a Plugin

Discover how EmDash's built-in redirect manager eliminates plugin vulnerabilities and boosts site security.

By Central
EmDash includes redirect management as a core feature, removing the need for vulnerable plugins.
Highlights
  • EmDash redirects run on Cloudflare Workers at the edge, not in a plugin's PHP code.
  • 96% of all WordPress security issues come from plugins, according to Cloudflare's analysis.
  • EmDash's MCP server allows AI agents to create redirects from 404 logs without any plugin.

The most common reason WordPress site owners install a plugin is to manage redirects. That plugin, like every other, is a vulnerability vector. In WordPress, plugins have unrestricted access to your database and file system. One compromised redirect plugin can expose your entire site.

EmDash, Cloudflare’s new CMS, includes redirect management as a core feature. No plugin required. The architecture makes this possible: redirects live at the serverless edge, not in a plugin’s PHP code. Here’s exactly how to create, manage, and test them.

96% of all WordPress security issues come from plugins.

To create a redirect in EmDash, navigate to the Redirects section in the admin panel, click “Add Redirect”, enter the source URL, target URL, and choose the HTTP status code (301 or 302). No plugin installation, no additional configuration. The redirect runs on Cloudflare’s infrastructure, not inside a plugin sandbox.

Why Built-in Redirects Matter

WordPress redirect plugins are a classic example of the plugin paradox. You install one because the core CMS lacks a feature. But that plugin now has full database access. It can read every table, execute arbitrary queries, and connect to external servers. A bug in a redirect plugin can let an attacker exfiltrate your entire user database.

According to Cloudflare’s analysis, 96% of all WordPress security issues come from plugins. In 2025 alone, researchers discovered over 11,000 new WordPress vulnerabilities — nearly half exploitable without any authentication. Redirect plugins are part of that problem.

EmDash solves this by making redirects a first-class feature of the CMS itself. No plugin, no sandbox, no attack surface. The redirect logic runs on Cloudflare Workers, which scale to zero when idle and spin up in milliseconds. You get built-in security without sacrificing performance.

Accessing the Redirect Manager

The redirect manager lives in the EmDash admin panel under “Manage” > “Redirects”. You’ll see a clean interface with a table of existing redirects. The layout mirrors WordPress conventions, so muscle memory transfers. But the behavior is different — these redirects are applied at the edge, not in a PHP process.

From this screen you can:

  • View all active and inactive redirects
  • Filter by source URL, target URL, or status code
  • Search for specific redirects
  • Sort by creation date, last used, or hit count

Hit count tracking is built in. You can see which redirects are actually being used and which ones are stale. This data helps clean up old redirects that slow down your crawl budget.

Creating a Redirect

Click “Add Redirect” to open a simple form. You’ll need three pieces of information:

Source URL: The path you want to redirect from. This is relative to your site root. For example, /old-blog-postcodecodecode or /about-uscodecodecode. EmDash automatically handles trailing slashes — you can include or omit them and the redirect will still match.

Target URL: The destination. This can be a relative path like /new-blog-postcodecodecode or an absolute URL like https://example.com/new-pagecodecodecode. Internal redirects resolve faster because they stay within the same Worker context.

HTTP Status Code: Two options — 301 (permanent) and 302 (temporary). 301 tells search engines the page has moved permanently and passes link equity. 302 is for temporary moves where you might revert later. Most sites should use 301.

That’s it. Click “Save” and the redirect is live. No cache purge, no restart, no waiting. The redirect takes effect globally within seconds because it runs on Cloudflare’s edge network across 300+ data centers.

One detail WordPress users will appreciate: EmDash automatically creates a redirect when you change a post’s slug. If you update a post URL in the editor, the system offers to add a 301 from the old URL. This prevents broken links and preserves SEO value.

Managing and Testing Redirects

After creating redirects, you need to verify they work. EmDash doesn’t include a built-in redirect tester, but the process is straightforward.

Open a new browser tab and navigate to the source URL. If the redirect is a 301, your browser should immediately land on the target. Chrome DevTools’ Network tab will show the initial request returning a 301 status code, then a second request to the new URL.

For bulk verification, use a tool like curlcodecodecode with the --locationcodecodecode flag disabled to see the actual redirect response:

“`

curl -I https://yoursite.com/old-page

“`

The response headers will show HTTP/2 301codecodecode and a Locationcodecodecode header pointing to the target.

EmDash also logs redirect hits. Visit the Redirects screen and check the “Hits” column. A growing count confirms traffic is flowing through the redirect. If a redirect has zero hits after a week, consider removing it — it’s not serving a purpose and may confuse crawlers.

Bulk Importing Redirects

Migrating from WordPress? You’ll likely have hundreds of redirects from your old site. EmDash supports importing redirects in bulk via a CSV file.

The format is simple: one redirect per line with three columns — source, target, status code. For example:

“`

/old-article,/new-article,301

/contact-us,/get-in-touch,301

/temp-offer,/permanent-offer,302

“`

Upload the CSV from the Redirects screen. The system validates each row and reports any conflicts. Duplicate source URLs are flagged — you can choose which one to keep. After import, all redirects go live immediately.

This import feature is especially useful when moving from a WordPress site that used a redirect plugin. Export your existing redirects from the plugin (most support CSV export), clean up the format to match EmDash’s columns, and import. Your redirect history survives the migration.

Best Practices for Redirects in EmDash

Use 301 for permanent moves only. A 301 redirect tells search engines the old page no longer exists. If you later need the old URL back, it takes months for search engines to recrawl and update their index. For short-term campaigns or A/B tests, use 302.

Avoid redirect chains. A redirect from A to B that then redirects to C wastes crawl budget and slows page loads. EmDash doesn’t prevent chains, but you can review them in the redirect list. Look for entries where the target URL is itself a source URL for another redirect. Consolidate these into a single hop.

Leverage wildcard redirects. EmDash supports pattern matching with asterisks. A source URL like /category/*codecodecode redirects every post in that category to a new path. Use this sparingly — broad wildcards can inadvertently redirect valid content.

Monitor hit counts regularly. A redirect that’s never used adds unnecessary complexity. Set a quarterly reminder to review your redirect list and prune dead entries. Fewer redirects mean faster edge processing and cleaner crawl paths for search engines.

Combine with 404 tracking. EmDash includes basic 404 logging. Check which pages are returning 404 errors and create redirects for them. This recovers lost traffic and prevents visitors from hitting dead ends.

The Edge Case: Redirects and AI Agents

Here’s where EmDash’s built-in redirects become more than a convenience feature. The CMS ships with an integrated MCP server and agent skills files. AI coding tools like Claude or Cursor can interact directly with the redirect manager.

You can ask an agent: “Find all 404s from last week and create 301 redirects to the most relevant live page.” The agent queries the 404 log, matches each broken URL to a likely target, and creates the redirects — all without touching a plugin. This workflow is impossible in WordPress without a custom plugin that exposes an API endpoint.

In EmDash, it works out of the box because redirects are part of the core data model. The MCP server exposes redirect CRUD operations. The agent reads the skills file, understands the permission model, and executes within its scoped capabilities. No plugin sandbox needed because there’s no plugin.

This is what “AI-native” actually means for a CMS. Not an AI chatbot bolted onto the admin panel, but an architecture where every feature is accessible to agents through a consistent protocol. Redirects are just one example.

Questions answered
  • How do you create a redirect in EmDash?Navigate to the Redirects section in the admin panel, click 'Add Redirect', enter the source URL, target URL, and choose the HTTP status code (301 or 302).
  • Why are built-in redirects more secure than plugins?Built-in redirects eliminate the plugin attack surface because redirects run on Cloudflare's infrastructure, not in a plugin sandbox with full database access.
Share This Article