Fastcache by Host.it Security & Risk Analysis

wordpress.org/plugins/fastcache-by-host-it

FastCache è un plugin WordPress per caching avanzato, CDN e ottimizzazione delle prestazioni, sviluppato e supportato interamente in Italia.

300 active installs v1.6.7 PHP 8.0+ WP 6.0.0+ Updated Apr 14, 2026
cachecdnseospeedvarnish
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fastcache by Host.it Safe to Use in 2026?

Generally Safe

Score 100/100

Fastcache by Host.it has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'fastcache-by-host-it' v1.5.20 presents a mixed security posture. On the positive side, it has no known CVEs, indicating a good track record of security. All SQL queries are properly prepared, and there are a reasonable number of capability and nonce checks, suggesting some attention to secure coding practices. However, several areas raise concerns. The plugin has a significant attack surface with 6 AJAX handlers, of which 3 lack proper authentication checks, creating a clear pathway for unauthenticated attackers. Additionally, the presence of the `unserialize` function, especially without explicit taint analysis indicating it's handled safely, is a notable risk. While taint analysis didn't reveal critical or high severity issues, the presence of unsanitized paths in all analyzed flows warrants caution. The lack of a vulnerability history is generally good, but it doesn't absolve the plugin from potential undiscovered issues, particularly given the aforementioned code signals.

Key Concerns

  • Unprotected AJAX handlers
  • Use of unserialize function
  • Flows with unsanitized paths
  • Low percentage of properly escaped output
Vulnerabilities
None known

Fastcache by Host.it Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Fastcache by Host.it Release Timeline

v1.6.7Current
v1.6.6
v1.6.5
v1.6.4
v1.6.3
v1.6.2
v1.6.1
v1.6
v1.5.20
v1.5.19
v1.5.18
v1.5.17
v1.5.16
v1.5.15
v1.5.14
v1.5.13
v1.5.12
v1.5.11
v1.5.10
v1.5.9
Code Analysis
Analyzed Mar 16, 2026

Fastcache by Host.it Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
2 prepared
Unescaped Output
274
87 escaped
Nonce Checks
14
Capability Checks
8
File Operations
35
External Requests
14
Bundled Libraries
1

Dangerous Functions Found

unserializereturn unserialize ( $content );src\Core\Platform\Cache.php:505

Bundled Libraries

Select2

SQL Query Safety

100% prepared2 total queries

Output Escaping

24% escaped361 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
processImageNodes (src\Core\LightImages.php:50)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Fastcache by Host.it Attack Surface

Entry Points6
Unprotected3

AJAX Handlers 6

authwp_ajax_multiselectsrc\Dispatcher.php:144
authwp_ajax_fastcache_hook_pagespeedsrc\Dispatcher.php:149
authwp_ajax_hstPurgeCachesrc\Host\public\class-fastcache-public.php:57
noprivwp_ajax_hstPurgeCachesrc\Host\public\class-fastcache-public.php:61
authwp_ajax_testCachesrc\Host\public\class-fastcache-public.php:65
authwp_ajax_attivazionefastcachesrc\Host\public\class-fastcache-public.php:69
WordPress Hooks 42
actionupgrader_process_completefastcache.php:83
actionautomatic_updates_completefastcache.php:105
actionadmin_enqueue_scriptssrc\Admin.php:36
actionadmin_bar_menusrc\Admin.php:40
actionadmin_initsrc\Admin.php:41
actionadmin_initsrc\Admin.php:42
actionadmin_action_updatesrc\Admin.php:44
actionadmin_noticessrc\Admin.php:327
actionwp_dashboard_setupsrc\Core\Admin\DashboardWidget.php:25
actionadmin_initsrc\Core\Admin\DashboardWidget.php:26
actionadmin_menusrc\Dispatcher.php:66
actionadmin_initsrc\Dispatcher.php:70
filterplugin_action_linkssrc\Dispatcher.php:74
filterwp_lazy_loading_enabledsrc\Dispatcher.php:81
actioninitsrc\Dispatcher.php:90
actionplugins_loadedsrc\Dispatcher.php:102
actionactivated_pluginsrc\Dispatcher.php:112
actiondeactivated_pluginsrc\Dispatcher.php:116
actionwp_headsrc\Dispatcher.php:123
actionwp_headsrc\Dispatcher.php:130
filterfastcache_get_page_cache_idsrc\Dispatcher.php:137
actionfastcache_cron_prunesrc\Dispatcher.php:236
actioninitsrc\Host\admin\class-fastcache-admin.php:57
actionadmin_menusrc\Host\admin\class-fastcache-admin.php:64
actionsave_postsrc\Host\admin\class-fastcache-admin.php:68
actionadmin_noticessrc\Host\admin\class-fastcache-admin.php:341
actionadmin_bar_menusrc\Host\includes\class-fastcache.php:132
actionadmin_bar_menusrc\Host\includes\class-fastcache.php:134
actionadmin_enqueue_scriptssrc\Host\includes\class-fastcache.php:138
actionadmin_enqueue_scriptssrc\Host\includes\class-fastcache.php:140
actionwp_enqueue_scriptssrc\Host\includes\class-fastcache.php:155
actionsend_headerssrc\Host\includes\class-fastcache.php:156
actiontemplate_redirectsrc\Host\includes\class-fastcache.php:157
actioninitsrc\Host\includes\class-fastcache.php:159
filterfastcache_host_v_purge_urlssrc\Host\Main.php:7
filtersafe_style_csssrc\Host\Main.php:53
actiontransition_post_statussrc\Host\public\class-fastcache-public.php:73
filteryith_wcwl_add_to_wishlisth_button_htmlsrc\Host\public\workarounds.class.php:17
actioninitsrc\Host\public\workarounds.class.php:80
filterwp_nonce_fieldsrc\Host\public\workarounds.class.php:91
filterwoocommerce_locate_templatesrc\Host\workarounds\EsiMiniCart.class.php:13
actionstorefront_headersrc\Host\workarounds\Storefront.class.php:11

Scheduled Events 1

fastcache_cron_prune
Maintenance & Trust

Fastcache by Host.it Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 14, 2026
PHP min version8.0
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

Fastcache by Host.it Developer Profile

Host.it

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fastcache by Host.it

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fastcache-by-host-it/build/css/admin-style.css/wp-content/plugins/fastcache-by-host-it/build/css/style.css/wp-content/plugins/fastcache-by-host-it/build/js/admin.js/wp-content/plugins/fastcache-by-host-it/build/js/fastcache.js
Script Paths
/wp-content/plugins/fastcache-by-host-it/build/js/admin.js/wp-content/plugins/fastcache-by-host-it/build/js/fastcache.js
Version Parameters
fastcache-by-host-it/build/css/admin-style.css?ver=fastcache-by-host-it/build/css/style.css?ver=fastcache-by-host-it/build/js/admin.js?ver=fastcache-by-host-it/build/js/fastcache.js?ver=

HTML / DOM Fingerprints

CSS Classes
fastcache_settings_inputfastcache_settings_input_fieldfastcache_settings_labelfastcache_settings_wrapperfastcache_settings_notice
Data Attributes
data-fastcache-settings-radiodata-fastcache-settings-text
JS Globals
window.fastcache
FAQ

Frequently Asked Questions about Fastcache by Host.it