Clear Cache for Me Security & Risk Analysis

wordpress.org/plugins/clear-cache-for-widgets

Purges cache on WPEngine, W3TC, WP Super Cache, WP Fastest Cache when widgets, menus, settings update. Forces browsers to reload CSS and JS files.

40K active installs v2.4.2 PHP + WP 3.8+ Updated Jun 9, 2025
cacheclearcssjspurge
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Clear Cache for Me Safe to Use in 2026?

Generally Safe

Score 100/100

Clear Cache for Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "clear-cache-for-widgets" plugin version 2.4.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, having no SQL queries that aren't prepared, and no file operations or external HTTP requests. The absence of known CVEs and a clear vulnerability history also suggests a reasonably well-maintained codebase.

However, significant concerns arise from the attack surface. The plugin exposes four AJAX handlers, with a notable two lacking any authentication checks. This directly translates to potential vulnerabilities where unauthenticated users could trigger these functions, leading to unexpected behavior or denial of service. While the static analysis did not reveal specific taint flows, the unprotected AJAX endpoints are a critical concern that bypasses the need for taint analysis to identify a risk. The limited output escaping (40% properly escaped) is another area for potential weakness, although without specific taint flows, the direct impact is harder to quantify.

In conclusion, while the plugin avoids several common pitfalls like raw SQL and dangerous functions, the unprotected AJAX handlers represent a clear and present security risk. The plugin's strengths lie in its clean code regarding database operations and external interactions, but the identified attack surface weakness significantly detracts from its overall security. Further investigation into what these unprotected AJAX handlers do would be crucial for a complete risk assessment.

Key Concerns

  • Unprotected AJAX handlers (2)
  • Insufficient output escaping (40%)
Vulnerabilities
None known

Clear Cache for Me Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Clear Cache for Me Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
4 escaped
Nonce Checks
3
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped10 total outputs
Attack Surface
2 unprotected

Clear Cache for Me Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_save-widgetclear-cache-for-widgets.php:59
authwp_ajax_widgets-orderclear-cache-for-widgets.php:60
authwp_ajax_ccfm-ajax-ccfmclear-cache-for-widgets.php:551
authwp_ajax_ccfm-notice-responseoptions-page.php:47
WordPress Hooks 45
filterwp_die_ajax_handlerclear-cache-for-action.php:23
actionshutdownclear-cache-for-action.php:142
actionactivated_pluginclear-cache-for-widgets.php:24
actiondeactivated_pluginclear-cache-for-widgets.php:25
actionupgrader_process_completeclear-cache-for-widgets.php:26
action_core_updated_successfullyclear-cache-for-widgets.php:28
actionplugins_loadedclear-cache-for-widgets.php:31
actionwp_dashboard_setupclear-cache-for-widgets.php:42
actionadmin_headclear-cache-for-widgets.php:45
actionsidebar_admin_setupclear-cache-for-widgets.php:61
actioncustomize_save_afterclear-cache-for-widgets.php:63
actionwp_update_nav_menuclear-cache-for-widgets.php:66
filterpre_set_transient_settings_errorsclear-cache-for-widgets.php:69
actionwpcf7_save_contact_formclear-cache-for-widgets.php:72
actionupdate_option_woo_optionsclear-cache-for-widgets.php:75
actionsave_postclear-cache-for-widgets.php:79
actionsave_postclear-cache-for-widgets.php:84
actionngg_update_galleryclear-cache-for-widgets.php:88
actionngg_delete_galleryclear-cache-for-widgets.php:89
actionngg_update_albumclear-cache-for-widgets.php:90
actionngg_update_album_sortorderclear-cache-for-widgets.php:91
actionngg_delete_albumclear-cache-for-widgets.php:92
actionfrm_update_formclear-cache-for-widgets.php:95
actionwpforms_builder_save_formclear-cache-for-widgets.php:98
actionupdate_option_ihaf_insert_headerclear-cache-for-widgets.php:101
actionupdate_option_ihaf_insert_footerclear-cache-for-widgets.php:102
actionupdate_option_ihaf_insert_bodyclear-cache-for-widgets.php:103
actionccfm_clear_cache_for_meclear-cache-for-widgets.php:106
actionadmin_initclear-cache-for-widgets.php:111
actionwoocommerce_settings_savedclear-cache-for-widgets.php:118
actionadmin_bar_menuclear-cache-for-widgets.php:123
actioninitclear-cache-for-widgets.php:129
actionwp_enqueue_scriptsclear-cache-for-widgets.php:150
actionadmin_enqueue_scriptsclear-cache-for-widgets.php:151
actionshutdownclear-cache-for-widgets.php:181
actionadmin_noticesclear-cache-for-widgets.php:394
actionadmin_noticesclear-cache-for-widgets.php:397
actionadmin_noticesclear-cache-for-widgets.php:405
actionadmin_noticesclear-cache-for-widgets.php:408
filterstyle_loader_srcclear-cache-for-widgets.php:450
filterscript_loader_srcclear-cache-for-widgets.php:451
actionwp_headclear-cache-for-widgets.php:453
actionadmin_menuoptions-page.php:19
actionadmin_initoptions-page.php:27
actionadmin_enqueue_scriptsoptions-page.php:248
Maintenance & Trust

Clear Cache for Me Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 9, 2025
PHP min version
Downloads729K

Community Trust

Rating96/100
Number of ratings29
Active installs40K
Developer Profile

Clear Cache for Me Developer Profile

webheadcoder

6 plugins · 95K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
649 days
View full developer profile
Detection Fingerprints

How We Detect Clear Cache for Me

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clear-cache-for-widgets/js/admin-bar.js
Script Paths
/wp-content/plugins/clear-cache-for-widgets/js/admin-bar.js
Version Parameters
clear-cache-for-widgets/js/admin-bar.js?ver=

HTML / DOM Fingerprints

JS Globals
ccfm
FAQ

Frequently Asked Questions about Clear Cache for Me