
Gcore CDN Security & Risk Analysis
wordpress.org/plugins/g-core-labs-cdnGcore Plugin
Is Gcore CDN Safe to Use in 2026?
Generally Safe
Score 85/100Gcore CDN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "g-core-labs-cdn" plugin version 1.1.10 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection risks (all queries use prepared statements), and output escaping vulnerabilities, along with a lack of file operations and external HTTP requests, are significant strengths. The plugin also demonstrates good practices by implementing nonce checks on its entry points, which are all protected by authentication. The taint analysis revealing no unsanitized paths further reinforces this positive assessment.
However, the most notable concern arises from the complete absence of capability checks on the identified AJAX handlers. While nonce checks are present, this missing layer of authorization means that any authenticated user, regardless of their role or permissions, could potentially interact with these AJAX endpoints. This could lead to unintended actions or information disclosure if these handlers perform sensitive operations or expose data that should be restricted to specific user roles.
The plugin's vulnerability history is entirely clear, with no recorded CVEs. This lack of past issues, coupled with the current static analysis findings, suggests a proactive approach to security or, at the very least, no publicly known vulnerabilities. Nevertheless, the missing capability checks represent a tangible risk that should be addressed to ensure comprehensive access control and to prevent potential privilege escalation or unauthorized data manipulation.
Key Concerns
- AJAX handlers lack capability checks
Gcore CDN Security Vulnerabilities
Gcore CDN Release Timeline
Gcore CDN Code Analysis
Output Escaping
Data Flow Analysis
Gcore CDN Attack Surface
AJAX Handlers 4
WordPress Hooks 5
Maintenance & Trust
Gcore CDN Maintenance & Trust
Maintenance Signals
Community Trust
Gcore CDN Alternatives
bunny.net – WordPress CDN Plugin
bunnycdn
Enable Bunny CDN to speed up your WordPress website and enjoy greatly improved loading times around the world.
RocketCDN – WordPress CDN Plugin
rocketcdn
RocketCDN plugin is the easiest WordPress CDN plugin. It automatically rewrites all URLs to be served by our content delivery network (CDN).
5centsCDN – WordPress CDN Plugin
5centscdn
Optimize WordPress speed and performance with 5centsCDN plugin. Get advanced caching, CDN, and seamless optimization today!
powerwaf.com – WordPress WAF & CDN Plugin
powerwaf-cdn
Accelerate and protect your website to the maximum with PowerWAF CDN. With this plugin you can keep dynamic content updated at the edge to increase de …
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
Gcore CDN Developer Profile
1 plugin · 90 total installs
How We Detect Gcore CDN
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/g-core-labs-cdn/css/amaran.min.css/wp-content/plugins/g-core-labs-cdn/css/animate.min.css/wp-content/plugins/g-core-labs-cdn/css/checkbox.min.css/wp-content/plugins/g-core-labs-cdn/css/custom.css/wp-content/plugins/g-core-labs-cdn/js/jquery.amaran.min.js/wp-content/plugins/g-core-labs-cdn/js/scripts.jsjs/jquery.amaran.min.jsjs/scripts.jsg-core-labs-cdn/css/amaran.min.css?ver=1.0g-core-labs-cdn/css/animate.min.css?ver=1.0g-core-labs-cdn/css/checkbox.min.css?ver=1.0g-core-labs-cdn/css/custom.css?ver=1.0g-core-labs-cdn/js/jquery.amaran.min.js?ver=1.0g-core-labs-cdn/js/scripts.js?ver=HTML / DOM Fingerprints
g-core-labs-cdn-logog_core_labs_settings