Cachify Security & Risk Analysis

wordpress.org/plugins/cachify

Smart, efficient cache solution for WordPress. Use DB, HDD, Redis or Memcached for storing your blog pages. Make WordPress faster!

10K active installs v2.4.2 PHP 5.6+ WP 4.7+ Updated Jun 20, 2025
cachecachingoptimizeperformancespeed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cachify Safe to Use in 2026?

Generally Safe

Score 100/100

Cachify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The Cachify plugin v2.4.2 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, critical or high-severity taint flows, and a robust implementation of output escaping (93%) are significant strengths. Furthermore, the plugin utilizes a good number of capability checks and has only one cron event, which is a manageable attack surface. The presence of a nonce check, even if only one, is also a positive sign of security awareness in its development.

However, there are a few areas that warrant attention. While the overall SQL query usage is decent with 40% using prepared statements, the remaining 60% are not explicitly detailed and could represent a potential risk if not handled securely. The plugin performs file operations, and without further analysis, it's impossible to confirm if these are implemented without vulnerabilities like path traversal. The limited attack surface and lack of known vulnerabilities are commendable, but the development should continue to prioritize secure coding practices across all functions, especially concerning file operations and any SQL queries not using prepared statements.

Key Concerns

  • SQL queries not using prepared statements (40% of 5)
  • File operations present, security not explicitly confirmed
Vulnerabilities
None known

Cachify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cachify Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
2 prepared
Unescaped Output
3
40 escaped
Nonce Checks
1
Capability Checks
9
File Operations
6
External Requests
0
Bundled Libraries
0

SQL Query Safety

40% prepared5 total queries

Output Escaping

93% escaped43 total outputs
Attack Surface

Cachify Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 40
actionplugins_loadedcachify.php:48
actioncli_initcachify.php:78
actioninitinc\class-cachify.php:96
actionpost_updatedinc\class-cachify.php:97
actionpre_post_updateinc\class-cachify.php:98
actioncachify_remove_post_cacheinc\class-cachify.php:99
actioncomment_postinc\class-cachify.php:100
actionedit_commentinc\class-cachify.php:101
actiontransition_comment_statusinc\class-cachify.php:102
actionwoocommerce_product_set_stockinc\class-cachify.php:105
actionwoocommerce_variation_set_stockinc\class-cachify.php:106
actionwoocommerce_product_set_stock_statusinc\class-cachify.php:107
actionwoocommerce_variation_set_stock_statusinc\class-cachify.php:108
actioninitinc\class-cachify.php:111
actioninitinc\class-cachify.php:114
actionadmin_bar_menuinc\class-cachify.php:117
actionwp_enqueue_scriptsinc\class-cachify.php:120
actionrest_api_initinc\class-cachify.php:123
actioninitinc\class-cachify.php:125
filtercron_schedulesinc\class-cachify.php:129
actionhdd_cache_croninc\class-cachify.php:136
actionwpmu_new_bloginc\class-cachify.php:143
actiondelete_bloginc\class-cachify.php:144
actionwp_initialize_siteinc\class-cachify.php:146
actionwp_delete_siteinc\class-cachify.php:147
actionadmin_initinc\class-cachify.php:150
actionadmin_initinc\class-cachify.php:152
actionadmin_menuinc\class-cachify.php:154
actionadmin_enqueue_scriptsinc\class-cachify.php:156
actionadmin_enqueue_scriptsinc\class-cachify.php:158
filterdashboard_glance_itemsinc\class-cachify.php:160
filterplugin_row_metainc\class-cachify.php:162
actiontemplate_redirectinc\class-cachify.php:168
filterrobots_txtinc\class-cachify.php:169
actionadmin_noticesinc\class-cachify.php:394
actionadmin_noticesinc\class-cachify.php:401
actionadmin_noticesinc\class-cachify.php:409
actionadmin_noticesinc\class-cachify.php:417
actionnetwork_admin_noticesinc\class-cachify.php:878
actionadmin_noticesinc\class-cachify.php:885

Scheduled Events 1

hdd_cache_cron
Maintenance & Trust

Cachify Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 20, 2025
PHP min version5.6
Downloads364K

Community Trust

Rating94/100
Number of ratings47
Active installs10K
Developer Profile

Cachify Developer Profile

pluginkollektiv

8 plugins · 846K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
1972 days
View full developer profile
Detection Fingerprints

How We Detect Cachify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cachify/css/admin-dashboard.css/wp-content/plugins/cachify/css/admin.css/wp-content/plugins/cachify/css/flush-admin-bar.css/wp-content/plugins/cachify/js/admin.js/wp-content/plugins/cachify/js/flush-admin-bar.js
Script Paths
/wp-content/plugins/cachify/js/admin.js/wp-content/plugins/cachify/js/flush-admin-bar.js
Version Parameters
cachify/css/admin-dashboard.css?ver=cachify/css/admin.css?ver=cachify/css/flush-admin-bar.css?ver=cachify/js/admin.js?ver=cachify/js/flush-admin-bar.js?ver=

HTML / DOM Fingerprints

CSS Classes
cachify-admin-bar-flush
HTML Comments
Copyright (C) 2011-2015 Sergej MüllerThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License along+6 more
Data Attributes
data-cachify-action
JS Globals
cachify_admin_bar_flush_params
REST Endpoints
/wp-json/cachify/v1/flush
FAQ

Frequently Asked Questions about Cachify