5centsCDN – WordPress CDN Plugin Security & Risk Analysis

wordpress.org/plugins/5centscdn

Optimize WordPress speed and performance with 5centsCDN plugin. Get advanced caching, CDN, and seamless optimization today!

10 active installs v25.4.15 PHP 5.3+ WP 3.8+ Updated Apr 15, 2025
cachingcdncontent-delivery-networkoptimizeperformance
71
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJan 3, 2025
Download
Safety Verdict

Is 5centsCDN – WordPress CDN Plugin Safe to Use in 2026?

Mostly Safe

Score 71/100

5centsCDN – WordPress CDN Plugin is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Jan 3, 2025Updated 1yr ago
Risk Assessment

The 5centscdn plugin version 25.4.15 presents a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and avoids file operations and external HTTP requests, significant concerns arise from its attack surface and output escaping. The presence of six AJAX handlers, all lacking authentication checks, creates a substantial risk of unauthorized actions. Furthermore, the low percentage of properly escaped output (22%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, a concern amplified by the plugin's historical vulnerability pattern. The plugin has a history of Medium severity XSS vulnerabilities, and the current static analysis indicates a weakness in output sanitization that could facilitate such attacks. The taint analysis showing a high number of flows with unsanitized paths further validates these concerns regarding data handling and potential injection points.

While the absence of dangerous functions and raw SQL queries is positive, the critical lack of authorization on AJAX endpoints and insufficient output escaping are major weaknesses. The plugin's historical vulnerability to XSS, combined with the current code signals, strongly indicates that an attacker could exploit these weaknesses to perform unauthorized actions or inject malicious code. The bundled Guzzle library, though not explicitly flagged as outdated, warrants a review to ensure it's kept up-to-date. The plugin's overall security is significantly compromised by the unprotected AJAX endpoints and the potential for XSS due to poor output escaping.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • Flows with unsanitized paths detected
  • Unpatched vulnerability (medium severity)
  • Lack of nonce checks on AJAX handlers
  • Capability checks are limited
Vulnerabilities
1 published

5centsCDN – WordPress CDN Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22326medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

5centsCDN <= 25.4.15 - Reflected Cross-Site Scripting

Jan 3, 2025Unpatched
Version History

5centsCDN – WordPress CDN Plugin Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

5centsCDN – WordPress CDN Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

22% escaped50 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

6 flows5 with unsanitized paths
fivecentscdn_cname_update (5centscdn.php:194)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

5centsCDN – WordPress CDN Plugin Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_fivecentscdn_purge5centscdn.php:63
authwp_ajax_fivecentscdn_zone5centscdn.php:64
authwp_ajax_fivecentscdn_all_zones5centscdn.php:65
authwp_ajax_fivecentscdn_update_zone_ssl5centscdn.php:66
authwp_ajax_fivecentscdn_purge_file5centscdn.php:67
authwp_ajax_fivecentscdn_cname_update5centscdn.php:68
WordPress Hooks 9
actionadmin_enqueue_scripts5centscdn.php:57
actionadmin_bar_menu5centscdn.php:58
actionadmin_menu5centscdn.php:59
actionadmin_init5centscdn.php:60
actionwp_head5centscdn.php:62
actionenqueue_block_editor_assets5centscdn.php:70
actionpost_submitbox_misc_actions5centscdn.php:71
actiontemplate_redirect5centscdn.php:72
actionadmin_notices5centscdn.php:73
Maintenance & Trust

5centsCDN – WordPress CDN Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 15, 2025
PHP min version5.3
Downloads3K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

5centsCDN – WordPress CDN Plugin Developer Profile

5centsCDN

1 plugin · 10 total installs

74
trust score
Avg Security Score
71/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 5centsCDN – WordPress CDN Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/5centscdn/assets/css/5centcdn.css
Version Parameters
/wp-content/plugins/5centscdn/assets/css/5centcdn.css?v=

HTML / DOM Fingerprints

JS Globals
fivecentscdnSettingsFivecentsCDN
REST Endpoints
/wp-json/fivecentscdn
FAQ

Frequently Asked Questions about 5centsCDN – WordPress CDN Plugin