
Pars Host Addons Security & Risk Analysis
wordpress.org/plugins/pars-host-addonsThis plugin is programmed to significantly enhance your website's load speed, ensuring a seamless and faster user experience.
Is Pars Host Addons Safe to Use in 2026?
Generally Safe
Score 92/100Pars Host Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pars-host-addons" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals no known CVEs in its history, indicating a generally secure development past. The code also shows a commitment to secure coding practices with 100% of SQL queries using prepared statements and a high percentage (80%) of output being properly escaped. However, there are significant concerns arising from the taint analysis and the absence of certain security checks. The presence of 3 flows with unsanitized paths, despite no critical or high severity flags, suggests potential for subtle vulnerabilities if these paths are reachable. Furthermore, the complete lack of nonce checks and capability checks, coupled with the absence of any authentication checks on its entry points (AJAX, REST API, shortcodes, cron), represents a considerable risk. This means that any code that interacts with the plugin could potentially be exploited without proper authorization, leaving the door open for unauthorized actions.
While the plugin has no recorded vulnerabilities, this may be due to its limited exposure or because the current analysis hasn't uncovered exploitable issues. The critical missing authentication and authorization mechanisms on all entry points are a significant weakness. The taint analysis revealing unsanitized paths, even without critical severity, warrants careful investigation as it points to potential weaknesses in input validation. In conclusion, while the plugin avoids common pitfalls like raw SQL and lacks historical vulnerabilities, the absence of fundamental security checks and the presence of unsanitized paths create a concerning attack surface that needs immediate attention to mitigate potential risks.
Key Concerns
- Unsanitized paths found in taint analysis
- No nonce checks found
- No capability checks found
- No authentication checks on AJAX handlers
- No authentication checks on REST API routes
- Output escaping is not 100%
Pars Host Addons Security Vulnerabilities
Pars Host Addons Release Timeline
Pars Host Addons Code Analysis
Output Escaping
Data Flow Analysis
Pars Host Addons Attack Surface
WordPress Hooks 24
Maintenance & Trust
Pars Host Addons Maintenance & Trust
Maintenance Signals
Community Trust
Pars Host Addons Alternatives
Seraphinite Accelerator
seraphinite-accelerator
Turns on site high speed to be attractive for people and search engines.
ezCache
ezcache
Lightning-fast WordPress optimization — page caching, Redis Object Cache, Critical CSS, WebP images, CSS/JS optimization, and 15+ performance tools.
WP Compress – Instant Performance & Speed Optimization
wp-compress-image-optimizer
Everything you need for a faster website – smart optimization, advanced caching, adaptive images, WebP creation, script improvements, optional CDN del …
Core Web Vitals & PageSpeed Booster
core-web-vitals-pagespeed-booster
Core Web Vitals (CWV) is the new ranking factor
Servebolt Optimizer
servebolt-optimizer
This plugin implements Servebolt's WordPress best practices, and connects your site to the Servebolt Admin Panel.
Pars Host Addons Developer Profile
2 plugins · 0 total installs
How We Detect Pars Host Addons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pars-host-addons/css/pars-host-wp-admin.css/wp-content/plugins/pars-host-addons/partials/assets/fonts/yekan-bakh/font.css/wp-content/plugins/pars-host-addons/css/bootstrap.rtl.min.css/wp-content/plugins/pars-host-addons/js/pars-host-wp-admin.jsjs/pars-host-wp-admin.jspars-host-wp-admin.css?ver=font.css?ver=bootstrap.rtl.min.css?ver=pars-host-wp-admin.js?ver=HTML / DOM Fingerprints
parshost-dashboard-pagedata-pars-host-pageParsHostAdminParsHostAjax