
bunny.net – WordPress CDN Plugin Security & Risk Analysis
wordpress.org/plugins/bunnycdnEnable Bunny CDN to speed up your WordPress website and enjoy greatly improved loading times around the world.
Is bunny.net – WordPress CDN Plugin Safe to Use in 2026?
Generally Safe
Score 96/100bunny.net – WordPress CDN Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The bunnycdn plugin v3.0.0 presents a mixed security posture. While it demonstrates good practices in areas like using prepared statements for all SQL queries and a significant percentage of properly escaped output, there are notable areas of concern. The presence of two unprotected entry points (one AJAX handler and one REST API route) is a significant risk, as these could be exploited by unauthenticated users. The taint analysis, while not revealing critical or high severity issues, did find 8 flows with unsanitized paths, indicating potential for information disclosure or unexpected behavior if specific input vectors are leveraged.
The vulnerability history shows two known medium severity CVEs, both related to Cross-site Scripting. The fact that the last vulnerability was dated in the future (2025-05-19) suggests this data might be hypothetical or a future projection. If these CVEs were indeed in the wild, it indicates a past struggle with input validation leading to XSS. The absence of currently unpatched vulnerabilities is a positive sign, but the pattern of XSS vulnerabilities warrants continued vigilance. Overall, the plugin has strengths in its database query security but needs to address its exposed entry points and the identified unsanitized paths to improve its security.
Key Concerns
- Unprotected AJAX handler
- REST API route without permission callback
- Taint flows with unsanitized paths detected
- Medium severity XSS vulnerabilities historically
bunny.net – WordPress CDN Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
bunny.net – WordPress CDN Plugin <= 2.3.6 - Missing Authorization
bunny.net <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
bunny.net – WordPress CDN Plugin <= 2.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
bunny.net – WordPress CDN Plugin Release Timeline
bunny.net – WordPress CDN Plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
bunny.net – WordPress CDN Plugin Attack Surface
AJAX Handlers 1
REST API Routes 5
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
bunny.net – WordPress CDN Plugin Maintenance & Trust
Maintenance Signals
Community Trust
bunny.net – WordPress CDN Plugin Alternatives
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
Breeze Cache
breeze
Breeze is a caching plugin developed by Cloudways. Breeze uses advance caching systems to improve site loading times exponentially.
Super Page Cache – Cloudflare Cache, Page Speed & Core Web Vitals
wp-cloudflare-page-cache
Boost PageSpeed, SEO, and Core Web Vitals with full page caching, JS/CSS optimization, media optimization, and Cloudflare CDN.
WP YouTube Lyte
wp-youtube-lyte
High performance YouTube video, playlist and audio-only embeds which don't slow down your blog and offer optimal accessibility.
Use Google Libraries
use-google-libraries
Allows your site to use common javascript libraries from Google's AJAX Libraries CDN, rather than from WordPress's own copies.
bunny.net – WordPress CDN Plugin Developer Profile
1 plugin · 10K total installs
How We Detect bunny.net – WordPress CDN Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bunnycdn/assets/css/admin-thickbox.css/wp-content/plugins/bunnycdn/assets/css/admin.css/wp-content/plugins/bunnycdn/assets/css/slimselect.min.css/wp-content/plugins/bunnycdn/assets/js/admin-redirect.js/wp-content/plugins/bunnycdn/assets/js/admin-thickbox.js/wp-content/plugins/bunnycdn/assets/js/admin.js/wp-content/plugins/bunnycdn/assets/js/slimselect.min.js/wp-content/plugins/bunnycdn/assets/js/admin.js/wp-content/plugins/bunnycdn/assets/js/admin-redirect.js/wp-content/plugins/bunnycdn/assets/js/admin-thickbox.js/wp-content/plugins/bunnycdn/assets/js/slimselect.min.jsbunnycdn/assets/css/admin-thickbox.css?ver=bunnycdn/assets/css/admin.css?ver=bunnycdn/assets/css/slimselect.min.css?ver=bunnycdn/assets/js/admin-redirect.js?ver=bunnycdn/assets/js/admin-thickbox.js?ver=bunnycdn/assets/js/admin.js?ver=bunnycdn/assets/js/slimselect.min.js?ver=HTML / DOM Fingerprints
bunnycdn-admin-settingsbunny.net WordPress PluginCopyright (C) 2024-2025 BunnyWay d.o.o.This program is free software: you can redistribute it and/or modifyit under the terms of the GNU General Public License as published by+8 moredata-nonceBunnyCDNAdmin/wp-json/bunnycdn/v1/settings/wp-json/bunnycdn/v1/scanner/wp-json/bunnycdn/v1/zones/wp-json/bunnycdn/v1/assets/wp-json/bunnycdn/v1/pullzones/wp-json/bunnycdn/v1/pullzone/assets[bunnycdn_stream_video