Pars Host Addons Security & Risk Analysis

wordpress.org/plugins/pars-host-addons

This plugin is programmed to significantly enhance your website's load speed, ensuring a seamless and faster user experience.

0 active installs v1.0.0 PHP 7.4+ WP + Updated Apr 29, 2025
cachelazy-loadingoptimizationperformancespeed-up
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pars Host Addons Safe to Use in 2026?

Generally Safe

Score 100/100

Pars Host Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "pars-host-addons" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals no known CVEs in its history, indicating a generally secure development past. The code also shows a commitment to secure coding practices with 100% of SQL queries using prepared statements and a high percentage (80%) of output being properly escaped. However, there are significant concerns arising from the taint analysis and the absence of certain security checks. The presence of 3 flows with unsanitized paths, despite no critical or high severity flags, suggests potential for subtle vulnerabilities if these paths are reachable. Furthermore, the complete lack of nonce checks and capability checks, coupled with the absence of any authentication checks on its entry points (AJAX, REST API, shortcodes, cron), represents a considerable risk. This means that any code that interacts with the plugin could potentially be exploited without proper authorization, leaving the door open for unauthorized actions.

While the plugin has no recorded vulnerabilities, this may be due to its limited exposure or because the current analysis hasn't uncovered exploitable issues. The critical missing authentication and authorization mechanisms on all entry points are a significant weakness. The taint analysis revealing unsanitized paths, even without critical severity, warrants careful investigation as it points to potential weaknesses in input validation. In conclusion, while the plugin avoids common pitfalls like raw SQL and lacks historical vulnerabilities, the absence of fundamental security checks and the presence of unsanitized paths create a concerning attack surface that needs immediate attention to mitigate potential risks.

Key Concerns

  • Unsanitized paths found in taint analysis
  • No nonce checks found
  • No capability checks found
  • No authentication checks on AJAX handlers
  • No authentication checks on REST API routes
  • Output escaping is not 100%
Vulnerabilities
None known

Pars Host Addons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pars Host Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
46
182 escaped
Nonce Checks
0
Capability Checks
0
File Operations
11
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped228 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
force_ssl_redirection (admin\inc\class-pars-host-setting.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pars Host Addons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actionadmin_initadmin\class-pars-host-wp-admin-options.php:81
actionwpadmin\inc\class-pars-host-setting-optimization.php:5
actionwp_enqueue_scriptsadmin\inc\class-pars-host-setting.php:228
actionwp_enqueue_scriptsadmin\inc\class-pars-host-setting.php:233
actionwp_enqueue_scriptsadmin\inc\class-pars-host-setting.php:238
actionwp_enqueue_scriptsadmin\inc\class-pars-host-setting.php:245
actionwp_enqueue_scriptsadmin\inc\class-pars-host-setting.php:269
actionadmin_initadmin\inc\class-pars-host-setting.php:288
actiontemplate_redirectadmin\inc\class-pars-host-setting.php:289
actionwp_headadmin\inc\class-pars-host-setting.php:296
filterthe_contentadmin\inc\class-pars-host-setting.php:304
filterpost_thumbnail_htmladmin\inc\class-pars-host-setting.php:305
filterwp_get_attachment_image_attributesadmin\inc\class-pars-host-setting.php:306
filterthe_contentadmin\inc\class-pars-host-setting.php:313
actionwp_enqueue_scriptsadmin\inc\class-pars-host-setting.php:331
actionwp_enqueue_scriptsadmin\inc\class-pars-host-setting.php:333
actionadmin_enqueue_scriptsincludes\class-pars-host-wp.php:153
actionadmin_enqueue_scriptsincludes\class-pars-host-wp.php:154
actionadmin_menuincludes\class-pars-host-wp.php:155
actionadmin_initincludes\class-pars-host-wp.php:156
actionupdated_optionincludes\class-pars-host-wp.php:157
filterplugin_action_linksincludes\class-pars-host-wp.php:158
actionwp_enqueue_scriptsincludes\class-pars-host-wp.php:173
actionwp_enqueue_scriptsincludes\class-pars-host-wp.php:174
Maintenance & Trust

Pars Host Addons Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 29, 2025
PHP min version7.4
Downloads413

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pars Host Addons Developer Profile

Pars Host Developer Team

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pars Host Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pars-host-addons/css/pars-host-wp-admin.css/wp-content/plugins/pars-host-addons/partials/assets/fonts/yekan-bakh/font.css/wp-content/plugins/pars-host-addons/css/bootstrap.rtl.min.css/wp-content/plugins/pars-host-addons/js/pars-host-wp-admin.js
Script Paths
js/pars-host-wp-admin.js
Version Parameters
pars-host-wp-admin.css?ver=font.css?ver=bootstrap.rtl.min.css?ver=pars-host-wp-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
parshost-dashboard-page
Data Attributes
data-pars-host-page
JS Globals
ParsHostAdminParsHostAjax
FAQ

Frequently Asked Questions about Pars Host Addons