
LH HTTP/2 Server Push Security & Risk Analysis
wordpress.org/plugins/lh-http2-server-pushDoes HTTP/2 Server Push for JavaScript and CSS resources properly.
Is LH HTTP/2 Server Push Safe to Use in 2026?
Generally Safe
Score 85/100LH HTTP/2 Server Push has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-http2-server-push" plugin version 1.02 exhibits a very strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Crucially, the lack of any taint analysis findings, especially those with unsanitized paths or critical/high severity, indicates a well-sanitized codebase concerning data flow vulnerabilities. The plugin also scores highly due to the complete absence of known CVEs, suggesting a history of responsible development and maintenance.
However, the analysis does reveal a potential area for improvement: the complete lack of capability checks and nonce checks on its zero entry points. While there are no entry points currently, this indicates that if any were to be introduced in the future, they would lack fundamental security protections. This is a design pattern rather than a current vulnerability, but it represents a future risk if the plugin evolves. The plugin's strengths lie in its clean code and lack of known historical vulnerabilities, but the absence of built-in authorization checks for potential future interactions is a notable weakness.
Key Concerns
- No capability checks for potential entry points
- No nonce checks for potential entry points
LH HTTP/2 Server Push Security Vulnerabilities
LH HTTP/2 Server Push Code Analysis
Output Escaping
LH HTTP/2 Server Push Attack Surface
WordPress Hooks 1
Maintenance & Trust
LH HTTP/2 Server Push Maintenance & Trust
Maintenance Signals
Community Trust
LH HTTP/2 Server Push Alternatives
Better Resource Hints
better-resource-hints
Better Resource Hints will make your WordPress site or application faster and generally more performant by intelligently leveraging resource hints lik …
HTTP/2 Server Push
http2-server-push
Enables HTTP/2 server push for local JavaScript and CSS resources.
Image Preloading
image-preloading
Modern image preloading/prefetching plugin for WordPress to improve page loading performance.
Speculative Loading
speculation-rules
Enables browsers to speculatively prerender or prefetch pages to achieve near-instant loads based on user interaction.
Flying Pages: Preload Pages for Faster Navigation & Improved User Experience
flying-pages
Preload pages intelligently to boost site speed and enhance user experience by loading pages before users click, ensuring instant page transitions.
LH HTTP/2 Server Push Developer Profile
77 plugins · 15K total installs
How We Detect LH HTTP/2 Server Push
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-http2-server-push/