GoCache Security & Risk Analysis

wordpress.org/plugins/gocache-cdn

Acelere seu site e reduza seus custos com cloud.

1K active installs v1.3.6 PHP + WP 5.3+ Updated Jan 15, 2025
cachecdnoptimizationperformancespeed
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEOct 17, 2025
Download
Safety Verdict

Is GoCache Safe to Use in 2026?

Mostly Safe

Score 70/100

GoCache is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Oct 17, 2025Updated 1yr ago
Risk Assessment

The "gocache-cdn" v1.3.6 plugin presents a significant security risk primarily due to its unprotected AJAX handlers. The static analysis revealed a substantial attack surface with 6 AJAX handlers, all of which lack proper authorization checks. This is a critical vulnerability that could allow unauthenticated users to trigger arbitrary actions within the plugin.

While the plugin shows some good practices, such as using prepared statements for SQL queries and generally good output escaping, these strengths are overshadowed by the fundamental security flaws. The absence of capability checks further exacerbates the risk associated with the unprotected AJAX endpoints. The vulnerability history, showing a known medium severity CVE from 2025-10-17 related to "Missing Authorization," reinforces this concern and indicates a recurring pattern of authorization issues. The fact that this CVE is currently unpatched is a serious red flag.

In conclusion, despite some positive coding practices, the "gocache-cdn" plugin is highly vulnerable. The unprotected AJAX handlers, combined with a history of authorization-related vulnerabilities that remain unpatched, make this plugin a prime target for attackers. Remediation of the authorization checks on AJAX endpoints is paramount.

Key Concerns

  • 6 unprotected AJAX handlers
  • 0 capability checks
  • 1 unpatched medium severity CVE
  • Missing Authorization vulnerability pattern
Vulnerabilities
1 published

GoCache Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62966medium · 4.3Missing Authorization

GoCache <= 1.3.6 - Missing Authorization

Oct 17, 2025Unpatched
Version History

GoCache Release Timeline

v1.3.6Current1 CVE
v1.3.51 CVE
v1.3.41 CVE
v1.3.31 CVE
v1.3.21 CVE
v1.3.01 CVE
v1.2.9.11 CVE
v1.2.91 CVE
v1.2.81 CVE
v1.2.71 CVE
v1.2.61 CVE
v1.2.51 CVE
v1.2.4.21 CVE
v1.2.41 CVE
v1.2.31 CVE
v1.2.21 CVE
v1.2.11 CVE
v1.2.01 CVE
v1.1.91 CVE
v1.1.81 CVE
Code Analysis
Analyzed Mar 16, 2026

GoCache Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
23 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

88% escaped26 total outputs
Attack Surface
6 unprotected

GoCache Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_jt3WHdVr42nM9HfTController\cache.php:21
authwp_ajax_Tk5FhDBt68mW8GlPController\cache.php:22
authwp_ajax_VwtDUTW92c2B8YjfController\cache.php:23
authwp_ajax_mbuceP3nRNUqXzR5Controller\cache.php:24
authwp_ajax_CBS93bVqAwWnVFHwController\requests.php:14
authwp_ajax_settings_gocache_saveController\settings.php:24
WordPress Hooks 11
actionplugins_loadedConfig\core.php:54
actionadmin_enqueue_scriptsConfig\core.php:55
actionadmin_enqueue_scriptsConfig\core.php:56
actioninitController\cache.php:18
actionwp_insert_commentController\cache.php:104
actiontransition_comment_statusController\cache.php:105
actionafter_delete_postController\cache.php:108
actiondelete_attachmentController\cache.php:109
actionadmin_menuController\settings.php:23
actionadmin_initController\settings.php:25
filtergocache_before_save_optionController\settings.php:26
Maintenance & Trust

GoCache Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 15, 2025
PHP min version
Downloads52K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

GoCache Developer Profile

Apiki

6 plugins · 1K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GoCache

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gocache-cdn/assets/javascripts/built.js/wp-content/plugins/gocache-cdn/assets/stylesheets/style.css
Script Paths
/wp-content/plugins/gocache-cdn/assets/javascripts/built.js
Version Parameters
gocache-cdn/assets/javascripts/built.js?ver=gocache-cdn/assets/stylesheets/style.css?ver=

HTML / DOM Fingerprints

JS Globals
AdminGlobalVars
FAQ

Frequently Asked Questions about GoCache