
Instant Back/Forward Security & Risk Analysis
wordpress.org/plugins/nocache-bfcacheEnables back/forward cache (bfcache) for instant history navigations even when “nocache” headers are sent, such as when a user is logged in.
Is Instant Back/Forward Safe to Use in 2026?
Generally Safe
Score 100/100Instant Back/Forward has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'nocache-bfcache' v1.3.1 plugin exhibits a very strong security posture based on the provided static analysis. There are no identified entry points exposed through AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal attack surface. Furthermore, the code demonstrates excellent secure coding practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations, external HTTP requests, and the lack of nonce and capability checks (which are likely unnecessary given the absence of other entry points) are also positive indicators.
The vulnerability history is equally reassuring, with zero known CVEs and no recorded vulnerabilities of any severity. This suggests a well-maintained and secure codebase throughout its history. The absence of any critical or high-severity taint flows further reinforces the confidence in the plugin's security. Overall, this plugin appears to be exceptionally secure and well-developed from a security perspective. The primary strength lies in its extremely limited attack surface and adherence to secure coding principles.
While the analysis indicates a highly secure plugin, it's worth noting that the lack of explicit capability checks and nonce checks, while not a concern in this specific scenario due to the absence of entry points, could become a point of concern if the plugin were to introduce new entry points in the future without implementing these checks. However, based on the current data, the plugin is very robust.
Instant Back/Forward Security Vulnerabilities
Instant Back/Forward Code Analysis
Output Escaping
Instant Back/Forward Attack Surface
WordPress Hooks 12
Maintenance & Trust
Instant Back/Forward Maintenance & Trust
Maintenance Signals
Community Trust
Instant Back/Forward Alternatives
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Speed Optimizer – The All-In-One Performance-Boosting Plugin
sg-cachepress
Boost your website performance and page speed, and increase conversions with powerful caching, frontend, media, and environment optimizations.
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance
wp-optimize
Get caching and more with this powerful cache plugin. Cache, optimize images, clean your database and minify for maximum performance.
WP Super Cache
wp-super-cache
A very fast caching engine for WordPress that produces static html files.
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
Instant Back/Forward Developer Profile
22 plugins · 437K total installs
How We Detect Instant Back/Forward
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nocache-bfcache/assets/js/bfcache-invalidation.js/wp-content/plugins/nocache-bfcache/assets/js/bfcache-opt-in.js/wp-content/plugins/nocache-bfcache/assets/js/detect-scripting-enabled-at-login.js/wp-content/plugins/nocache-bfcache/assets/js/bfcache-invalidation.js/wp-content/plugins/nocache-bfcache/assets/js/bfcache-opt-in.js/wp-content/plugins/nocache-bfcache/assets/js/detect-scripting-enabled-at-login.jsnocache-bfcache/assets/js/bfcache-invalidation.js?ver=nocache-bfcache/assets/js/bfcache-opt-in.js?ver=nocache-bfcache/assets/js/detect-scripting-enabled-at-login.js?ver=HTML / DOM Fingerprints
data-nocache-bfcache-cookie-namedata-nocache-bfcache-initial-session-tokendata-nocache-bfcache-debugdata-nocache-bfcache-i18n-log-prefixdata-nocache-bfcache-i18n-page-restoreddata-nocache-bfcache-i18n-page-invalidating+8 morewindow.wp.element.render