
Async JavaScript Security & Risk Analysis
wordpress.org/plugins/async-javascriptAsync Javascript lets you add 'async' or 'defer' attribute to scripts to exclude to help increase the performance of your WordPres …
Is Async JavaScript Safe to Use in 2026?
Mostly Safe
Score 84/100Async JavaScript is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The 'async-javascript' plugin version 2.21.08.31 presents a mixed security posture. While the static analysis reveals a generally low number of critical code-level vulnerabilities, with no identified critical or high severity taint flows and a good percentage of SQL queries utilizing prepared statements, there are notable concerns. The presence of an unprotected AJAX handler significantly increases the attack surface, as it lacks authentication checks, making it a potential entry point for unauthorized actions. Furthermore, the output escaping is only properly implemented in 43% of cases, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. The vulnerability history indicates two past medium severity CVEs, both related to Cross-Site Scripting, and while currently unpatched, this pattern suggests a recurring susceptibility to injection attacks. In conclusion, the plugin shows some good practices like using prepared statements and nonce checks, but the unprotected AJAX endpoint and insufficient output escaping, coupled with a history of XSS vulnerabilities, warrant careful consideration and mitigation.
Key Concerns
- Unprotected AJAX handler found
- Output escaping only 43% proper
- Two past medium CVEs (XSS)
Async JavaScript Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Async Javascript <= 2.20.12.09 - Authenticated (Admin+) Cross-Site Scripting
Async JavaScript <= 2.19.07.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Async JavaScript Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Async JavaScript Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Async JavaScript Maintenance & Trust
Maintenance Signals
Community Trust
Async JavaScript Alternatives
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
Autoptimize
autoptimize
Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
Aruba HiSpeed Cache
aruba-hispeed-cache
Aruba HiSpeed Cache interfaces directly with an Aruba hosting platform's HiSpeed Cache service and automates its management.
Async JavaScript Developer Profile
2 plugins · 80K total installs
How We Detect Async JavaScript
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/async-javascript/css/admin.min.css/wp-content/plugins/async-javascript/js/admin.min.js/wp-content/plugins/async-javascript/assets/lib/chosen/chosen.jquery.min.js/wp-content/plugins/async-javascript/js/admin.min.jsasync-javascript/css/admin.min.css?ver=async-javascript/js/admin.min.js?ver=HTML / DOM Fingerprints
aj_admin_styles<!--AJAX OPTIONS-->data-suffixaj_localize_admin