
Cache control by Cacholong Security & Risk Analysis
wordpress.org/plugins/cache-control-by-cacholong“Cache control by Cacholong” is a cache control plugin for one or more Nginx servers.
Is Cache control by Cacholong Safe to Use in 2026?
High Risk
Score 43/100Cache control by Cacholong carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The static analysis of cache-control-by-cacholong v5.4.1 reveals a generally strong security posture in terms of direct code vulnerabilities. The plugin demonstrates excellent practices by having no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests further reduces the attack surface. The presence of a nonce check is also a positive indicator of security awareness. However, the complete lack of AJAX handlers, REST API routes, shortcodes, and cron events, while reducing the immediate attack surface, might also suggest limited functionality or a very focused purpose for the plugin.
The primary concern stems from the vulnerability history. The plugin has a history of two known CVEs, both of which are currently unpatched. These vulnerabilities, identified as Cross-site Scripting (XSS) and Cross-Site Request Forgery (CSRF), are of medium severity. The fact that these vulnerabilities are recent (dated 2025-04-01) and remain unpatched indicates a significant risk to users. Even with a secure codebase in other areas, unpatched historical vulnerabilities are a critical weakness that exposes the system to known exploits. This pattern suggests a lack of timely security patching and maintenance, which is a serious concern for any plugin.
In conclusion, while cache-control-by-cacholong v5.4.1 exhibits strong secure coding practices in its static analysis, the presence of two unpatched medium-severity vulnerabilities (XSS and CSRF) significantly undermines its overall security. Users should be highly cautious as these known exploits could be leveraged. The plugin's strengths lie in its clean code regarding SQL and output handling, but its weakness in patch management is a critical issue that outweighs these positives.
Key Concerns
- Unpatched CVEs: 2 medium severity
Cache control by Cacholong Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Cache control by Cacholong <= 5.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Cache control by Cacholong <= 5.4.1 - Cross-Site Request Forgery
Cache control by Cacholong Code Analysis
Cache control by Cacholong Attack Surface
WordPress Hooks 23
Maintenance & Trust
Cache control by Cacholong Maintenance & Trust
Maintenance Signals
Community Trust
Cache control by Cacholong Alternatives
Cache-Control
cache-control
Configurable HTTP Cache-Control response headers for webpages generated by WordPress.
Simple Cache Killer
simple-cache-killer
Allows users to specify that requests to their content not be cached in any way, easily from within the Wordpress admin.
wao.io Cache Control
wao-io-cache-control
wao.io Cache Control is a free plugin to clear your WordPress site's cache at wao.io.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
Cache control by Cacholong Developer Profile
1 plugin · 500 total installs
How We Detect Cache control by Cacholong
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cache-control-by-cacholong/assets/js/script.js/wp-content/plugins/cache-control-by-cacholong/assets/css/style.css/wp-content/plugins/cache-control-by-cacholong/assets/js/script.js/wp-content/plugins/cache-control-by-cacholong/assets/js/script.js?ver=/wp-content/plugins/cache-control-by-cacholong/assets/css/style.css?ver=HTML / DOM Fingerprints
cacholong-cache-control-settings<!-- Cache Control by Cacholong -->data-cacholong-cache-control-settingscacholongCacheControlSettings/wp-json/cacholong-cache-control/v1/settings/wp-json/cacholong-cache-control/v1/purge