Bandwidth Saver: Image CDN Security & Risk Analysis

wordpress.org/plugins/bandwidth-saver

Image CDN for WordPress. Serve images from 300+ global edge servers. Faster Core Web Vitals, better SEO. $9.99/mo.

0 active installs v1.1.3 PHP 7.4+ WP 6.2+ Updated Unknown
cdncore-web-vitalsimage-cdnimage-optimizationpage-speed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bandwidth Saver: Image CDN Safe to Use in 2026?

Generally Safe

Score 100/100

Bandwidth Saver: Image CDN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "bandwidth-saver" plugin v1.1.3 demonstrates a strong security posture based on the provided static analysis. All identified entry points, including 22 AJAX handlers, are protected by authentication checks, and there are no unescaped outputs or raw SQL queries. The complete absence of taint analysis findings for critical or high severity issues, coupled with zero known CVEs in its history, further suggests a robustly developed and maintained plugin. The presence of 25 nonce checks and 5 capability checks indicates a deliberate effort to secure critical operations.

While the overall security is excellent, a minor concern could be the single external HTTP request, which represents a potential, albeit small, attack vector if the external service is compromised or maliciously crafted. However, given the lack of other vulnerabilities and the plugin's overall thoroughness in other security aspects, this is a low risk. The consistent absence of past vulnerabilities and the strong static analysis results point to a well-coded plugin with a strong commitment to security best practices.

Key Concerns

  • Single external HTTP request detected
Vulnerabilities
None known

Bandwidth Saver: Image CDN Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bandwidth Saver: Image CDN Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
156 escaped
Nonce Checks
25
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped156 total outputs
Attack Surface

Bandwidth Saver: Image CDN Attack Surface

Entry Points22
Unprotected0

AJAX Handlers 22

authwp_ajax_imgpro_cdn_toggle_enabledincludes\class-imgpro-cdn-admin-ajax.php:57
authwp_ajax_imgpro_cdn_checkoutincludes\class-imgpro-cdn-admin-ajax.php:58
authwp_ajax_imgpro_cdn_manage_subscriptionincludes\class-imgpro-cdn-admin-ajax.php:59
authwp_ajax_imgpro_cdn_request_recoveryincludes\class-imgpro-cdn-admin-ajax.php:60
authwp_ajax_imgpro_cdn_verify_recoveryincludes\class-imgpro-cdn-admin-ajax.php:61
authwp_ajax_imgpro_cdn_add_custom_domainincludes\class-imgpro-cdn-admin-ajax.php:62
authwp_ajax_imgpro_cdn_check_custom_domainincludes\class-imgpro-cdn-admin-ajax.php:63
authwp_ajax_imgpro_cdn_remove_custom_domainincludes\class-imgpro-cdn-admin-ajax.php:64
authwp_ajax_imgpro_cdn_remove_cdn_domainincludes\class-imgpro-cdn-admin-ajax.php:65
authwp_ajax_imgpro_cdn_free_registerincludes\class-imgpro-cdn-admin-ajax.php:68
authwp_ajax_imgpro_cdn_update_onboarding_stepincludes\class-imgpro-cdn-admin-ajax.php:69
authwp_ajax_imgpro_cdn_complete_onboardingincludes\class-imgpro-cdn-admin-ajax.php:70
authwp_ajax_imgpro_cdn_sync_statsincludes\class-imgpro-cdn-admin-ajax.php:71
authwp_ajax_imgpro_cdn_sync_accountincludes\class-imgpro-cdn-admin-ajax.php:72
authwp_ajax_imgpro_cdn_health_checkincludes\class-imgpro-cdn-admin-ajax.php:73
authwp_ajax_imgpro_cdn_get_usageincludes\class-imgpro-cdn-admin-ajax.php:76
authwp_ajax_imgpro_cdn_get_insightsincludes\class-imgpro-cdn-admin-ajax.php:77
authwp_ajax_imgpro_cdn_get_daily_usageincludes\class-imgpro-cdn-admin-ajax.php:78
authwp_ajax_imgpro_cdn_get_usage_periodsincludes\class-imgpro-cdn-admin-ajax.php:79
authwp_ajax_imgpro_cdn_get_source_urlsincludes\class-imgpro-cdn-admin-ajax.php:82
authwp_ajax_imgpro_cdn_add_source_urlincludes\class-imgpro-cdn-admin-ajax.php:83
authwp_ajax_imgpro_cdn_remove_source_urlincludes\class-imgpro-cdn-admin-ajax.php:84
WordPress Hooks 19
actionadmin_noticesimgpro-cdn.php:25
actionadmin_noticesimgpro-cdn.php:37
actionplugins_loadedimgpro-cdn.php:77
actionwp_footerimgpro-cdn.php:95
actionsend_headersimgpro-cdn.php:109
actionadmin_menuincludes\class-imgpro-cdn-admin.php:75
actionadmin_initincludes\class-imgpro-cdn-admin.php:76
actionadmin_initincludes\class-imgpro-cdn-admin.php:77
actionadmin_initincludes\class-imgpro-cdn-admin.php:78
actionadmin_enqueue_scriptsincludes\class-imgpro-cdn-admin.php:79
actionadmin_initincludes\class-imgpro-cdn-core.php:123
actionwp_enqueue_scriptsincludes\class-imgpro-cdn-core.php:126
filterwp_get_attachment_urlincludes\class-imgpro-cdn-rewriter.php:213
filterwp_get_attachment_image_srcincludes\class-imgpro-cdn-rewriter.php:214
filterwp_calculate_image_srcsetincludes\class-imgpro-cdn-rewriter.php:215
filterwp_get_attachment_image_attributesincludes\class-imgpro-cdn-rewriter.php:217
filterthe_contentincludes\class-imgpro-cdn-rewriter.php:220
filterpost_thumbnail_htmlincludes\class-imgpro-cdn-rewriter.php:221
filterwidget_textincludes\class-imgpro-cdn-rewriter.php:222
Maintenance & Trust

Bandwidth Saver: Image CDN Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Bandwidth Saver: Image CDN Developer Profile

imgpro

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bandwidth Saver: Image CDN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bandwidth-saver/assets/css/onboarding.css/wp-content/plugins/bandwidth-saver/assets/css/settings.css/wp-content/plugins/bandwidth-saver/assets/js/onboarding.js/wp-content/plugins/bandwidth-saver/assets/js/settings.js
Script Paths
/wp-content/plugins/bandwidth-saver/assets/js/onboarding.js/wp-content/plugins/bandwidth-saver/assets/js/settings.js
Version Parameters
bandwidth-saver/assets/css/onboarding.css?ver=bandwidth-saver/assets/css/settings.css?ver=bandwidth-saver/assets/js/onboarding.js?ver=bandwidth-saver/assets/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
imgpro-cdn-settings-pageimgpro-cdn-noticeimgpro-onboarding-stepsimgpro-onboarding-step-complete
HTML Comments
<!-- Image CDN by ImgPro v1.1.3 -->
Data Attributes
data-imgpro-cdn-tabdata-imgpro-cdn-tab-content
JS Globals
imgpro_cdn_settings_params
REST Endpoints
/wp-json/imgpro-cdn/v1/settings
FAQ

Frequently Asked Questions about Bandwidth Saver: Image CDN