
Auto SRI Security & Risk Analysis
wordpress.org/plugins/auto-sriAutomatically adds Subresource Integrity (SRI) to external scripts/styles and safely excludes Google reCAPTCHA and Google Fonts.
Is Auto SRI Safe to Use in 2026?
Generally Safe
Score 100/100Auto SRI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The auto-sri plugin v2.1 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that are not protected by authentication or permission checks, indicating a minimal attack surface. Furthermore, the code demonstrates robust security practices with 100% of SQL queries using prepared statements and all output being properly escaped. The absence of dangerous functions, file operations, and taint analysis issues further strengthens this positive assessment.
While the plugin's internal code quality appears high, a single external HTTP request is present, which, although not inherently a vulnerability, warrants consideration for potential dependency on external services that could be compromised or become unavailable. The plugin also has one capability check, which is good practice, but the absence of nonce checks on AJAX (though there are no AJAX handlers) is noted as a general best practice to consider. The vulnerability history is completely clean, with no recorded CVEs, which suggests a well-maintained and secure development process over time.
In conclusion, auto-sri v2.1 is commendably secure, with excellent coding practices and no known vulnerabilities. The minimal attack surface and diligent use of security features are significant strengths. The single external HTTP request is a minor point of attention, but overall, the plugin represents a low-risk addition to a WordPress site.
Key Concerns
- External HTTP requests present
- No nonce checks on potential entry points (though none exist)
Auto SRI Security Vulnerabilities
Auto SRI Code Analysis
Output Escaping
Auto SRI Attack Surface
WordPress Hooks 6
Maintenance & Trust
Auto SRI Maintenance & Trust
Maintenance Signals
Community Trust
Auto SRI Alternatives
Subresource Integrity (SRI) Manager
wp-sri
Adds Subresource Integrity (SRI) attributes to your page's elements for better protection against JavaScript DDoS attacks.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
Headers Security Advanced & HSTS WP
headers-security-advanced-hsts-wp
Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.
HTTP Headers
http-headers
HTTP Headers adds CORS & security HTTP headers to your website.
Auto SRI Developer Profile
3 plugins · 1K total installs
How We Detect Auto SRI
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-sri/assets/css/auto-sri-admin.css/wp-content/plugins/auto-sri/assets/js/auto-sri-admin.js/wp-content/plugins/auto-sri/assets/js/auto-sri-admin.jsauto-sri/assets/css/auto-sri-admin.css?ver=auto-sri/assets/js/auto-sri-admin.js?ver=HTML / DOM Fingerprints
auto-sri-admin-settings