HTTP/2 Server Push Security & Risk Analysis

wordpress.org/plugins/http2-server-push

Enables HTTP/2 server push for local JavaScript and CSS resources.

1K active installs v1.4 PHP + WP 3.0+ Updated Mar 25, 2018
http2performanceprefetch
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HTTP/2 Server Push Safe to Use in 2026?

Generally Safe

Score 85/100

HTTP/2 Server Push has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "http2-server-push" plugin v1.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, all identified outputs are properly escaped, and there's no indication of taint analysis issues, suggesting a lack of opportunities for common injection vulnerabilities. The plugin's vulnerability history is also clean, with no recorded CVEs. This data points to excellent secure coding practices and a well-maintained codebase. However, it is important to note the complete lack of capability checks and nonce checks. While the current analysis shows no exploitable entry points, this could become a concern if the plugin's functionality or attack surface were to expand in future versions without corresponding security measures. Overall, the plugin appears very secure, but a slight caution is warranted regarding the absence of authentication checks on potentially sensitive future additions.

Vulnerabilities
None known

HTTP/2 Server Push Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

HTTP/2 Server Push Release Timeline

v1.4Current
v1.3
v1.2
v1.1
Code Analysis
Analyzed Mar 16, 2026

HTTP/2 Server Push Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

HTTP/2 Server Push Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninithttp2-server-push.php:42
filterscript_loader_srchttp2-server-push.php:82
filterstyle_loader_srchttp2-server-push.php:83
actionwp_headhttp2-server-push.php:102
Maintenance & Trust

HTTP/2 Server Push Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 25, 2018
PHP min version
Downloads28K

Community Trust

Rating84/100
Number of ratings11
Active installs1K
Developer Profile

HTTP/2 Server Push Developer Profile

Dana Ross

5 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HTTP/2 Server Push

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/http2-server-push/

HTML / DOM Fingerprints

JS Globals
http2_script_srcshttp2_stylesheet_srcs
FAQ

Frequently Asked Questions about HTTP/2 Server Push