
Clear Cache for Me Security & Risk Analysis
wordpress.org/plugins/clear-cache-for-widgetsPurges cache on WPEngine, W3TC, WP Super Cache, WP Fastest Cache when widgets, menus, settings update. Forces browsers to reload CSS and JS files.
Is Clear Cache for Me Safe to Use in 2026?
Generally Safe
Score 100/100Clear Cache for Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "clear-cache-for-widgets" plugin version 2.4.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, having no SQL queries that aren't prepared, and no file operations or external HTTP requests. The absence of known CVEs and a clear vulnerability history also suggests a reasonably well-maintained codebase.
However, significant concerns arise from the attack surface. The plugin exposes four AJAX handlers, with a notable two lacking any authentication checks. This directly translates to potential vulnerabilities where unauthenticated users could trigger these functions, leading to unexpected behavior or denial of service. While the static analysis did not reveal specific taint flows, the unprotected AJAX endpoints are a critical concern that bypasses the need for taint analysis to identify a risk. The limited output escaping (40% properly escaped) is another area for potential weakness, although without specific taint flows, the direct impact is harder to quantify.
In conclusion, while the plugin avoids several common pitfalls like raw SQL and dangerous functions, the unprotected AJAX handlers represent a clear and present security risk. The plugin's strengths lie in its clean code regarding database operations and external interactions, but the identified attack surface weakness significantly detracts from its overall security. Further investigation into what these unprotected AJAX handlers do would be crucial for a complete risk assessment.
Key Concerns
- Unprotected AJAX handlers (2)
- Insufficient output escaping (40%)
Clear Cache for Me Security Vulnerabilities
Clear Cache for Me Code Analysis
Output Escaping
Clear Cache for Me Attack Surface
AJAX Handlers 4
WordPress Hooks 45
Maintenance & Trust
Clear Cache for Me Maintenance & Trust
Maintenance Signals
Community Trust
Clear Cache for Me Alternatives
Disable CSS JS Cache
disable-css-js-cache
This plugin helps prevent browser caching of CSS and JS files from theme in WordPress.
Auto Update Cache
auto-update-cache
Update the version of all CSS and JS files. Show the latest changes on the site without asking the client to clear browse
CSS & JS Refresher
css-js-refresher
CSS & JS Refresher is a WordPress plugin that ensures the latest CSS and JavaScript changes are always reflected without being cached by browsers.
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Jetpack Boost – Website Speed, Performance and Critical CSS
jetpack-boost
Speed up your WordPress site with one-click optimizations like Page Cache, Critical CSS, and Image CDN to improve Core Web Vitals.
Clear Cache for Me Developer Profile
6 plugins · 95K total installs
How We Detect Clear Cache for Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clear-cache-for-widgets/js/admin-bar.js/wp-content/plugins/clear-cache-for-widgets/js/admin-bar.jsclear-cache-for-widgets/js/admin-bar.js?ver=HTML / DOM Fingerprints
ccfm