Open redirects are a security threat and redirect.php is wide open.
Why is it even needed? In any case, it must be closed. Limiting it to paypal.com can be a stop-gap measure to closing it. However, the redirect also isn’t used over HTTPS, so the best thing is to just get rid of it.