
Last-Modified and If-Modified-Since Headers Security & Risk Analysis
wordpress.org/plugins/last-modified-and-if-modified-since-headersAdd Last-Modified anв support If-Modified-Since Headers
Is Last-Modified and If-Modified-Since Headers Safe to Use in 2026?
Generally Safe
Score 85/100Last-Modified and If-Modified-Since Headers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'last-modified-and-if-modified-since-headers' plugin v1.0 exhibits an excellent security posture based on the provided static analysis. The complete absence of any identified attack surface points, including AJAX handlers, REST API routes, shortcodes, and cron events, indicates a highly contained and well-defined functionality. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The plugin also avoids file operations, external HTTP requests, and correctly uses nonces and capability checks where applicable.
Despite the strong static analysis, the taint analysis reveals two flows with unsanitized paths. While these are not classified as critical or high severity, they warrant attention as they represent potential vectors for unexpected behavior or data manipulation if the plugin's inputs are not strictly controlled. The lack of any historical vulnerabilities is a significant strength, suggesting consistent security focus from the developers. However, the absence of historical data also means there's no track record to review for past issues and their resolutions, which is a minor point to consider.
In conclusion, this plugin appears to be very secure due to its minimal attack surface and robust coding practices. The primary area for improvement lies in addressing the identified taint flows, even if they are currently low severity, to ensure complete sanitization of all data paths.
Key Concerns
- Flows with unsanitized paths found
Last-Modified and If-Modified-Since Headers Security Vulnerabilities
Last-Modified and If-Modified-Since Headers Release Timeline
Last-Modified and If-Modified-Since Headers Code Analysis
Data Flow Analysis
Last-Modified and If-Modified-Since Headers Attack Surface
WordPress Hooks 1
Maintenance & Trust
Last-Modified and If-Modified-Since Headers Maintenance & Trust
Maintenance Signals
Community Trust
Last-Modified and If-Modified-Since Headers Alternatives
LH Add Headers
lh-add-headers
Adds the ETag, Last-Modified, and if appropriate 304 headers to HTTP responses generated by WordPress for more efficient caching.
Headers Security Advanced & HSTS WP
headers-security-advanced-hsts-wp
Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.
HTTP Headers
http-headers
HTTP Headers adds CORS & security HTTP headers to your website.
WP Hide & Security Enhancer
wp-hide-security-enhancer
Protect your website by concealing vulnerable WordPress traces, plugins, themes, login/admin url. 2FA, Captcha, Firewall, Security Headers etc.
WP Last Modified Info
wp-last-modified-info
Ultimate Last Modified Plugin for WordPress with Gutenberg support. Use shortcodes to show last modified info on WP 4.7+ sites.
Last-Modified and If-Modified-Since Headers Developer Profile
1 plugin · 200 total installs
How We Detect Last-Modified and If-Modified-Since Headers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.