Descripción
DevDome Redirect Manager handles URL redirect rules for your entire site, selected content, custom paths or 404 pages. Send visitors to a destination URL, a rotating list, a link on the page or the same path on another domain, with separate targeting, schedules and statistics for each rule. Configure everything from one screen without coding; all features are free, with unlimited rules and no paid tier.
Redirect Setup: choose what to redirect
Use this redirector for a page redirect, post redirect or category redirect, or select your entire website for a site redirect. The highest-priority running rule that matches handles the request.
Under What To Redirect, choose:
- Entire website – runs on every public page for a website redirect.
- Selected existing URLs – search Categories, Pages and Posts with a live picker. Selected items appear as chips with per-item hit counts; drag them to set priority for the "found" mode.
- Custom URLs – enter exact paths, one per line, such as
/blog/or/blog/best-headphones/, whether the page exists or not. A trailing slash matches that page and everything under it. - All 404’s – runs on every not-found page to catch dead links. For a 404 to homepage rule, set your homepage as the destination.
- Referring websites – match listed websites against the browser’s referrer. A domain such as reddit.com covers that site and its subdomains; a word such as reddit matches referring addresses containing it. Without UTM source matching, visits with no referrer or an internal referrer do not match. "Only on selected pages" restricts the rule to chosen categories, pages or posts.
For a homepage redirect, target the homepage through Selected existing URLs. To make short links, manually choose a custom path and its destination: a short URL or vanity URL uses a path you supply, without generated slugs.
Referring websites and UTM Source
"Only visitors arriving from outside" redirects external arrivals, including visits with no referrer, while leaving visitors moving between your own pages on the page.
UTM Source – "Also match the link’s UTM source" lets a Referring websites rule match tagged links from apps and other sources without a referrer. For a listed source of reddit.com, both ?utm_source=reddit.com and ?utm_source=reddit match. Anyone can set this label; it does not verify where a visitor came from.
Redirect Method and URL forwarding
Choose JavaScript Redirect, 301 Permanent, 302 Temporary, 307 Temporary, 308 Permanent or Meta Refresh per rule. Use a 301 redirect for permanent redirection or a 302 redirect for temporary URL forwarding. New-tab opening and client-side delays require JavaScript; server and meta methods always open in the same tab.
Under Where To Send Traffic, choose:
- To provided links – enter one or more destination URLs.
- To links or buttons on the page – enter a fragment such as
amazon.comto find a matching link/button already on the page. You can target the N-th match. - To same path on another domain – preserve the visitor’s path and query for a domain redirect. For example,
yoursite.com/post/123becomesotherdomain.com/post/123.
Link rotation and traffic distribution
The URL rotator supports First to last, Random and Weighted distribution for provided links. The Click Distribution slider gives the first link most traffic, an even split or the last link most traffic, with a live preview. Repeat List restarts from the first URL when the list is exhausted.
For basic AB testing or split testing of destinations, the rotator can split traffic between links. It does not measure conversions or determine a winning destination.
How often to redirect
Choose Every visit, Once per visitor or After a delay. For the latter two, recognise returning visitors by IP address or IP + browser/device, and optionally redirect only every N-th unique visitor. After a delay lets you set the gap in minutes, hours or days before redirecting the same visitor again.
Daily Redirect Limit – "Limit redirects per day" sets a per-rule cap. Enter two positive whole numbers; the daily cap is chosen randomly between them. Use the same number twice for a fixed cap.
A redirect counts when the rule makes it, not when someone reaches the destination. With Visitor Check enabled, it counts when the pass is accepted, so merely loading a page costs nothing.
Known Bots, Outdated Browsers and Visitor Check
Known Bots – "Don’t redirect known bots" is on by default. Matching requests are not redirected, sent to the bypass link or counted as visitors. Local checks use built-in browser identifiers and any shared DevDome bot data already stored locally. This build downloads no bot feeds. Unrecognised bots can still be redirected.
Outdated Browsers – "Don’t redirect outdated browsers" skips reported Chrome/Chromium versions below 125, except 109, and Firefox versions below 125, except 115. Edge is checked through its Chrome version identifier. Browser identifiers containing Mobile, Android, iPhone or iPad are excluded from this check. Older versions can belong to real visitors.
Visitor Check – "Require the same IP address to continue" checks that a single-use pass returns from the same IP address and browser. It applies only to JavaScript redirects to provided links or the same path on another domain, not links found on the page.
The pass record stays in your database with a keyed hash of the visitor’s IP address and browser, never those raw values. It is deleted when used and expires within minutes, with extra time for configured delays.
Visitor Check, Outdated Browsers, Daily Redirect Limit and UTM source matching are off by default. All four run locally without an external service, as do the dashboard count and developer hooks.
Open Link Settings: automatic redirect or click
Choose an automatic redirect or wait for a visitor’s click. For an auto redirect with a delay, use the JavaScript method and configure the timing below.
- Open Link In – Same Tab or New Tab. New Tab requires JavaScript.
- Same Tab Link Delay – instant or a random delay in seconds within a range.
- Redirect On Click – wait for a click/tap anywhere before redirecting.
- After Click Delay – wait a random time up to 4 seconds after the click.
- New Tab Link Delay – instant or a random delay before the new tab is armed. The destination opens on the visitor’s next real click after that delay because browsers block tabs that open by themselves.
Geo Filter Settings: country redirect and geolocation
Use geotargeting for a country redirect based on IP geolocation. This GeoIP lookup supplies a country code for geo targeting; a geo IP redirect can include or exclude listed countries.
- Test geo service – check that the service is reachable from your server before relying on it.
- Geo Filtering – enable or disable the country filter; off by default.
- Filter mode – redirect only listed countries or everyone except them. If the country cannot be resolved, an "except listed" blacklist rule does not redirect that visitor.
- Site Behind Proxy / CDN – behind Cloudflare or another proxy, enable "Trust forwarded IP headers" to use the real visitor IP for country lookup. "Detect automatically" inspects the current request and ticks the box for you.
See External services for what a geo redirect sends and where.
Optional Settings: devices, cache and schedules
- Devices to Redirect – select Desktop, Mobile or Tablet. For a mobile redirect, check Mobile; other devices follow Not Redirected Visitors.
- Purge Page Cache On Save – clear cached copies of targeted pages when saving/running a rule so it takes effect immediately. Supports WP Rocket, LiteSpeed Cache, W3 Total Cache, WP Super Cache, WP Fastest Cache, SiteGround Optimizer, WP-Optimize, Cache Enabler, Hummingbird and Breeze.
- Not Redirected Visitors – Leave On Page or Send To Bypass Link, using a URL you choose.
- Schedule Mode – Always Active or Custom Schedule, with a run time, selected weekdays and up to three specific time windows.
Optional Settings: visitor exclusions
Exclude your own address, selected browsers or logged-in roles such as Administrator.
- Excluded IP Addresses – one IPv4 or IPv6 address or CIDR range per line. This cannot stop bots that change address on every visit.
- Excluded Browser Strings – skip User-Agent strings containing listed text, ignoring upper and lower case. Entries under 5 characters are not saved.
- Excluded User Roles – skip logged-in users with a ticked role. A page cache may still serve a stored redirect.
All three exclusions are per rule and off by default. Matching visitors see the page as usual and are counted with skipped bots.
Rules, run state and link tracking
Add, duplicate, delete, start and stop rules independently. Each has a nickname and priority; drag rules to reorder redirections.
- Save & Run starts a rule; Stop stops it. Live status shows Running/Stopped, run time and time left.
- Save Settings saves without changing run state. Return to Default resets the current rule’s settings.
- Reset Stats clears the current rule’s statistics and rotation position, but not today’s daily-limit count.
- Export downloads every rule and its configuration as JSON, without statistics or run state. Import replaces every rule on the site; imported rules arrive stopped.
Each rule records visitors, page views, unique users, unique IPs, redirects, bypassed visitors, device and country counts, and source/destination breakdowns, with a time-range filter. As a link tracker, it provides link tracking for rule activity, not confirmation that visitors reached a destination.
Bots Skipped includes bot matches, outdated-browser matches, IP address, browser string and user role exclusions, and expired or mismatched Visitor Check passes. The DevDome dashboard totals these across rules. It is not a count of confirmed bots.
Developer hooks
devdredi_redirect_targetfilters destinations for provided links and same-path redirects.devdredi_pass_bind_addressfilters the address a Visitor Check pass is bound to, for example a network range instead of an exact address.devdredi_redirectedresponds to redirect events.
These hooks do not confirm arrival at the destination.
AI and Agent Support
On WordPress 6.9+, compatible AI agents and MCP clients can use WordPress Abilities when your site exposes them, for example through the WordPress MCP Adapter. Abilities cover rule configuration, statistics, content search, 404 suggestions with DevDome Link Monitor, geo status, export and rule management. Administrator access is required.
New fields are skip_ips, skip_user_agents, skip_roles, visitor_check, skip_old_browsers, daily_limit_enabled, daily_limit_min, daily_limit_max and referrer_utm_scan. A list entry that is not valid is refused and nothing is changed; a list with entries switches its exclusion on, an empty list switches it off. Statistics include bots_skipped. Agents must obtain user agreement and send confirm: true when turning an enabled Visitor Check or Outdated Browsers setting off. Turning Known Bots off does not currently require that flag.
New rules start stopped unless requested otherwise. Updates are all or nothing. Enabling geo targeting, deleting rules and resetting statistics also require confirmation.
External services
Plugin catalog (devdome.com). The DevDome Dashboard inside wp-admin fetches the list of DevDome plugins (names, descriptions, logos, links, WordPress.org slugs) from https://devdome.com/wp-plugins/catalog.json at most once every 12 hours, so the list stays current. Only the bundled core version is sent in the request; no site or visitor data. Service provider: DevDome. Terms: https://devdome.com/terms-of-service Privacy policy: https://devdome.com/privacy-policy
This plugin can talk to two DevDome services, both optional and described below. Service provider for both: DevDome. Terms of service: https://devdome.com/terms-of-service . Privacy policy: https://devdome.com/privacy-policy .
Geo lookup (api.devdome.com/geo-resolve)
The plugin connects to the DevDome geo-resolution service only when you use the optional Geo Filter feature. With Geo Filtering turned off (the default), the plugin does not contact this service.
What it is used for: turning a visitor’s IP address into a two-letter country code so a rule can include or exclude countries.
What is sent and when:
- When a rule with Geo Filtering enabled handles a front-end request, the visitor’s IP address is sent to
https://api.devdome.com/geo-resolve/classify(POST, body{"ips":[<ip>]}) to look up a country code. Results are cached so the same IP is not looked up repeatedly. - The Test geo service button requests
https://api.devdome.com/geo-resolve/healthto check availability. No visitor data is sent. - The Detect automatically (proxy/CDN) button runs locally on your server and sends no data to any external service.
Bot detection feeds (api.devdome.com/bot-protection)
The plugin bundles the shared DevDome bot-detection library, which can download three block lists so known bots can be matched locally on your server: https://api.devdome.com/bot-protection/list (bot user-agent patterns), https://api.devdome.com/bot-protection/asns (data-center network list) and https://api.devdome.com/bot-protection/drop (Spamhaus DROP IP ranges).
These requests would be scheduled downloads of the lists themselves; no visitor data is ever sent to these endpoints. On this WordPress.org build the feed downloads are disabled entirely: no request is made and no download is scheduled, whether or not a DevDome account is connected.
Optional DevDome account connection (devdome.com and api.devdome.com)
The bundled DevDome library can link this site to a free DevDome account. This is optional and nothing is sent until you press the Connect button on the DevDome screen. Connecting opens devdome.com in your browser to sign in; after approval the plugin stores your public DevDome Account ID and a site token, and verifies the link against https://api.devdome.com/plugin/account (sending the site domain and the site token). When you connect from the DevDome Tools dashboard, whose Connect card states this before you press the button, those account checks also send the slug and version of each active DevDome plugin plus the DevDome library, WordPress and PHP versions, so your account can show which of your sites run which DevDome plugins. Sites connected earlier, or from a button without that text, do not send the list. Disconnecting sends the site domain and site token once to https://api.devdome.com/plugin/disconnect to unlink the site. Disconnecting also stops the plugin list. No visitor data, content or redirect rules are sent.
Source code
All of this plugin’s PHP and JavaScript ships unminified and human-readable.
One file is generated: assets/devdome-tools-tw.css, the admin screen’s utility stylesheet (assets/admin.css is hand-written and ships as-is). It is a Tailwind CSS v3 utility bundle built from src/tw.css and tailwind.config.cjs with:
npx tailwindcss -c tailwind.config.cjs -i src/tw.css -o assets/devdome-tools-tw.css --minify
Those two build inputs are not included in the distributed package. Ask for them at https://devdome.com/contact and we will send them.
Capturas





Instalación
- Upload the plugin to
/wp-content/plugins/(or install it from the Plugins screen) and activate it. - Open Tools -> DevDome Redirect Manager (the DevDome Tools menu).
- Pick what to redirect, choose a redirect method and where to send traffic, then set any targeting, timing and schedule you need.
- Click Save & Run to start the rule. Use Save Settings to save changes without changing the run state.
No account is required for the redirect features. The geo filter is optional and off by default.
FAQ
-
Does the redirect work without JavaScript, and why is "New Tab" greyed out or reverting to "Same Tab"?
-
Choose 301, 302, 307, 308 or Meta Refresh to redirect without JavaScript. These methods always open in the same tab, so New Tab is unavailable.
JavaScript is required for Visitor Check, new-tab opening, "wait for a click" and client-side delays. On fully cached pages, Referring websites and Only visitors arriving from outside rules also use JavaScript to detect the landing.
-
My redirect does not fire immediately after saving. Why?
-
A caching plugin or server cache may still serve a stored copy of the page. Keep "Purge Page Cache On Save" enabled so targeted pages are cleared when you save or run the rule.
-
Can I run more than one rule at the same time?
-
Yes. Rules are independent and ordered by priority. For each request, the highest-priority running rule that matches handles it.
-
What does "Once per visitor" mean?
-
The visitor is redirected only the first time, then left on the page on later visits until you reset the rule’s statistics. Choose "After a delay" to make the redirect available again after a set time. Visitors are identified by IP or IP + browser/device.
-
Does the plugin recognise every bot, and what should I switch on if bots inflate affiliate or ad clicks?
-
No. "Don’t redirect known bots" skips requests matching local checks, but bots with unrecognised browser identifiers can still be redirected. Visitor Check compares the IP address and browser between two requests; it does not prove that a visitor is human.
Keep "Don’t redirect known bots" enabled. For supported JavaScript redirects, try Visitor Check. Consider Outdated Browsers if excluding older browsers suits your audience. These settings can reduce some automated redirects, but cannot prevent direct visits to the destination or guarantee valid clicks.
-
Will Visitor Check slow real visitors down?
-
It adds one request to your site before opening the destination, so some extra loading time is possible. There is no CAPTCHA. A visitor using the same IP address and browser continues automatically if the pass is still valid.
-
What happens if a visitor’s network changes?
-
If the IP address or browser identifier changes between loading the page and returning the pass, the redirect is refused. The visitor sees an expired-link message asking them to go back and open the page again. This can happen to real visitors switching networks.
-
What happens when the daily limit is reached?
-
Further visitors handled by that rule stay on the page or go to its bypass link. A new daily allowance becomes available at midnight in the site’s timezone, subject to the rule’s schedule. Resetting statistics does not reset today’s allowance.
-
Does the geo filter send any data off my site?
-
Country lookups send visitor IP addresses to the geo service when Geo Filtering is enabled. "Test geo service" also contacts that service. The plugin catalog and optional account connection have separate external requests. See External services for details.
Visitor Check, Outdated Browsers, Daily Redirect Limit and UTM source matching run locally without an external service.
-
How do I stop being redirected on my own site?
-
Edit each rule that could redirect you. Under Optional Settings, tick "Don’t redirect users with these roles", tick your role, such as Administrator or Editor, then save. This applies only while logged in.
To skip redirects while logged out too, tick "Don’t redirect these IP addresses or ranges" and add your public IPv4 or IPv6 address, one address or CIDR range per line. Update the entry if your public address changes. Everyone sharing a listed address is also skipped.
Matching visits stay on the page, never go to the bypass link and are counted with skipped bots instead of visitors. Cached pages may still contain a redirect, so clear the page cache after saving if needed.
-
How do I move my rules to another site?
-
Use Export to download a JSON file of all rules, then Import on the other site. Imported rules arrive stopped, so you can review them before starting.
-
How do I set up 301 redirects when I change domain, change URL or change permalink?
-
For the redirect part of a site migration, choose "To same path on another domain" to use domain forwarding while preserving paths and queries. Configure 301 redirects for a permanent move.
After you change URL paths or change permalink settings in WordPress, enter the old paths under Custom URLs and provide their new destinations. This sets up a link redirect from an old address; it does not change permalink settings or move your site’s files and database.
Reseñas
No hay reseñas para este plugin.
Colaboradores y desarrolladores
"DevDome Redirect Manager: Redirector, Link Rotator & Geo Redirect" es un software de código abierto. Las siguientes personas han colaborado con este plugin.
ColaboradoresTraduce "DevDome Redirect Manager: Redirector, Link Rotator & Geo Redirect" a tu idioma.
¿Interesado en el desarrollo?
Revisa el código , echa un vistazo al repositorio SVN o suscríbete al registro de desarrollo por RSS.
Registro de cambios
1.5.5
- New per-rule exclusions under Optional Settings, each with its own checkbox and off by default: IP addresses and CIDR ranges (IPv4 and IPv6), browser strings (User-Agent), and logged-in WordPress user roles.
- Excluded visitors see the page as usual, are not sent to the bypass link and are counted with the skipped bots instead of visitors.
- Browser string exclusions match any listed text, ignoring upper and lower case. IP and browser string exclusions depend on the visitor continuing to match; role exclusions apply only while logged in, and cached pages may still be served.
- The rule settings are also available to AI agents as
skip_ips,skip_user_agentsandskip_roles. - For developers: new
devdredi_pass_bind_addressfilter for the address a Visitor Check pass is bound to. - Bundled DevDome library 1.7.6: the optional Connect card now says exactly what a connected site shares, including the list of active DevDome plugins. Sites already connected send nothing new. See External services.
1.5.4
- New "Require the same IP address to continue" checkbox (Visitor Check, off by default): a JavaScript redirect to a provided or transit destination continues only from the IP address and browser that opened the page. The destination no longer appears in the page; a single-use pass does, checked on your own site. A pass that comes back from another address is not redirected and is counted with the skipped bots.
- New "Don’t redirect outdated browsers" checkbox (off by default): desktop Chrome below version 125 (Edge is checked through its Chrome version) and Firefox below version 125, except versions 109 and 115, see the page as usual and are counted with the skipped bots.
- New "Daily Redirect Limit" (off by default): the rule stops redirecting for the day once the limit is reached and starts again at midnight, site time. The limit is picked each day between two numbers; the same number twice is a fixed limit. Visitors over the limit stay on the page or go to the bypass link.
- New "Also match the link’s UTM source" checkbox for Referring websites (off by default): the rule also fires for a tagged link such as ?utm_source=reddit.com, for sources that send no referrer.
- The DevDome dashboard tile and digest now also show Bots Skipped across all rules.
- All of these are also available to AI agents as the
visitor_check,skip_old_browsers,daily_limit_enabled,daily_limit_min,daily_limit_maxandreferrer_utm_scanrule fields. Switchingvisitor_checkorskip_old_browsersoff needsconfirm: true. - For developers: new
devdredi_redirect_targetfilter anddevdredi_redirectedaction. - Reworded the Known Bots texts: the switch keeps automated traffic out of your redirects and statistics.
1.5.3
- Fixed: country targeting redirected nobody. The plugin asked the DevDome geo service through a call reserved for connected accounts and always got no country back; it now uses the open lookup, so allow and block country lists work again on every site.
1.5.2
- New "Only visitors arriving from outside" checkbox under What To Redirect (every scope except Referring websites, which already works this way): the rule redirects a visitor who lands on the page from another website or with no referrer at all, and leaves a visitor who moves between pages of this site on the page. Works on cached pages through the same small footer script as Referring websites. The create-redirect and update-redirect abilities accept outside_only and get-redirect returns it.
1.5.1
- New "Don’t redirect known bots" checkbox under How Often To Redirect, on by default: crawlers, monitors and scrapers see the page as usual and are never redirected, so automated traffic stays out of your redirects and statistics. Skipped bots are not counted as visitors and appear as Bots Skipped in the rule statistics. The create-redirect and update-redirect abilities accept skip_bots and get-redirect returns it together with bots_skipped.
1.5.0
- What To Redirect: every option now carries a one-line hint under it, so the choice is clear without opening the info icon.
- New "What To Redirect" option: Referring websites. The rule runs only for visitors who arrive from the websites you list, one per line: a domain (reddit.com) covers that site and its subdomains, a word (reddit) covers every referring site whose address contains it. Works on cached pages through a small footer script. Tick Only on selected pages to redirect them only on the categories, pages or posts you pick. The websites are entered like the other lists: type, Add, remove one by one. The create-redirect and update-redirect abilities accept what = referring_sites with the list in from and the pages in referrer_pages.
- Picking a category under URLs To Redirect now redirects every post in it and in its subcategories, and picking a product category or the shop archive redirects every product in it. Before, only the category’s own archive pages were redirected. On sites with plain permalinks a picked category or page no longer matches every page of the site.
- Fixed: on sites with plain permalinks the "Selected existing URLs" picker found nothing (its search request was built with a second question mark and answered 404).
- The URLs To Redirect picker now lists every grouping of the site under Categories: blog categories and tags, WooCommerce product categories, brands and tags, custom taxonomies and the shop archive (a shop whose product base is /product-reviews/ appears there). It finds a title, a slug, a path or a full address, a hyphen no longer ends the suggestions, matches from the other tabs show up too, marked Page, Post or Category, and the Posts tab also finds single WooCommerce products and other public content. The search-content ability returns the same results.
- Updates now work when the plugin folder belongs to another system user, for example after an install from a root shell or by an AI agent. Before, the update failed with Retry update, or an uploaded zip kept the old version (shared DevDome core 1.7.2).
1.4.1
- Connect fix (shared DevDome core 1.6.6): the connect claim now waits up to 30 seconds and keeps the handshake for 20 minutes so a refresh retries it, the DevDome hub shows why a connect failed with a Try again link, and the verify file is served through a query form for hosts that answer /.well-known/ before WordPress.
1.4.0
- WordPress Abilities API support (WordPress 6.9+): fifteen abilities for AI agents and MCP clients covering every feature: list-redirects, get-redirect-details, get-redirect-stats, find-404-redirect-candidates, search-site-content, get-geo-status, export-redirects, create-redirect (full option set), update-redirect, set-redirect-state, duplicate-redirect, reorder-redirects, delete-redirect, reset-redirect-stats, purge-redirect-cache.
1.3.5
- Settings: every option now shows a one line hint under the control, with the info icon holding the full explanation, the same layout as DevDome Malware Scanner.
- DevDome Dashboard: installing another DevDome plugin from the dashboard no longer activates it, you activate it yourself from its card. Output escaping tightened.
1.3.4
- DevDome Dashboard: plugin list, descriptions, logos and versions now come from devdome.com, one-click install of DevDome plugins from WordPress.org, Docs link and Fix buttons, Activate stays on the dashboard.
1.3.3
- Updated the bundled DevDome suite core: redesigned DevDome Dashboard with cleaner cards, your account email and plan on the overview, and update buttons shown only when an update really exists.
- One button system across the suite: the same Connect button and the same Save Settings button in every DevDome plugin.
1.3.2
- Every output buffer used to build the page scripts is now opened and closed inside a single function, so it can never be left open.
- Removed two manually fired activation/deactivation hook calls from the internal version check.
1.3.1
- The suite hub no longer installs or activates any plugin: its installer is removed from this build and the DevDome screen links out to the plugin’s page instead.
- Removed the crawler-specific serving, search-engine hiding, referrer targeting, referrer stripping, back-button and daily-cap code paths entirely, along with the log-cleanup routine.
- The settings screen’s styles and scripts are now enqueued instead of being written into the page, so caching and optimisation plugins can handle them properly.
- Importing a settings file now accepts only known settings and cleans every value for the type it stores; switching the rule you are editing is protected like every other action.
1.3.0
- Every feature is now free and unlimited: the rule limit and the Pro locks on geo targeting, device targeting and scheduling are gone.
- Internal identifier rename to a unique plugin prefix (WordPress.org requirement). Existing rules, statistics and settings are carried over automatically by a one-time migration on self-hosted builds.
- Unified DevDome suite icons and suite hub.
Older entries: see changelog.txt in the plugin folder.
