
CloudFlare URL Replacement Security & Risk Analysis
wordpress.org/plugins/cloudflare-url-replacementThis plugin will help you replace link to the CloudFlare server.
Is CloudFlare URL Replacement Safe to Use in 2026?
Generally Safe
Score 85/100CloudFlare URL Replacement has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cloudflare-url-replacement" v0.7 plugin presents a mixed security picture. On the positive side, it exhibits an extremely small attack surface with zero identified entry points (AJAX, REST API, shortcodes, cron). Furthermore, all SQL queries utilize prepared statements, which is a strong security practice. The plugin also has no known vulnerability history, suggesting a relatively stable past. However, significant concerns arise from the code analysis. The presence of the `create_function` is a critical security risk, as it can lead to arbitrary code execution if user-supplied data is used within its parameters. Additionally, 100% of output is unescaped, meaning any dynamic content displayed by the plugin is vulnerable to Cross-Site Scripting (XSS) attacks. The absence of nonce and capability checks, while not directly exploitable due to the lack of other entry points, indicates a potential weakness if new entry points were added without proper security considerations. The lack of taint analysis flows could be due to the limited scope of the analysis or genuinely clean code in that regard, but it doesn't mitigate the risks identified by code signals.
Key Concerns
- Dangerous function create_function used
- All outputs unescaped (XSS risk)
- Missing nonce checks
- Missing capability checks
CloudFlare URL Replacement Security Vulnerabilities
CloudFlare URL Replacement Release Timeline
CloudFlare URL Replacement Code Analysis
Dangerous Functions Found
Output Escaping
CloudFlare URL Replacement Attack Surface
WordPress Hooks 7
Maintenance & Trust
CloudFlare URL Replacement Maintenance & Trust
Maintenance Signals
Community Trust
CloudFlare URL Replacement Alternatives
Media Cloud for Bunny CDN, Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean and more
ilab-media-tools
Automatically store media on Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean Spaces + others. Serve CSS/JS assets through CDNs.
Offload, AI & Optimize with Cloudflare Images
cf-images
Offload you media library images to the Cloudflare Images service. Store, resize, optimize and deliver images in a fast and secure manner.
Purge Cloud Flare
purge-cloud-flare
Purge CloudFlare makes clearing CloudFlare cache as simple as one click.
Yctvn Media Offload for Cloudflare R2
yctvn-media-offload-cloudflare-r2
Automatically offload your WordPress media library to Cloudflare R2 Storage for improved performance and reduced hosting costs.
WP cdnjs
wp-cdnjs
Integrates easily CSS and JavaScript Libraries hosted by CDNjs.com. Browse, select version and sub-assets to fit your needs.
CloudFlare URL Replacement Developer Profile
3 plugins · 30 total installs
How We Detect CloudFlare URL Replacement
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cloudflare-url-replacement/js/cloudflare-url-replacement.js/wp-content/plugins/cloudflare-url-replacement/js/cloudflare-url-replacement.jsHTML / DOM Fingerprints
blank template per create options page inside wordpress backendhttp://codex.wordpress.org/Creating_Options_Pageshttp://ottodestruct.com/blog/2009/wordpress-settings-api-tutorial/http://codex.wordpress.org/Settings_API+7 moredata-setting_namevar adminpage