
Pars Host Addons Security & Risk Analysis
wordpress.org/plugins/pars-host-addonsThis plugin is programmed to significantly enhance your website's load speed, ensuring a seamless and faster user experience.
Is Pars Host Addons Safe to Use in 2026?
Generally Safe
Score 100/100Pars Host Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pars-host-addons" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals no known CVEs in its history, indicating a generally secure development past. The code also shows a commitment to secure coding practices with 100% of SQL queries using prepared statements and a high percentage (80%) of output being properly escaped. However, there are significant concerns arising from the taint analysis and the absence of certain security checks. The presence of 3 flows with unsanitized paths, despite no critical or high severity flags, suggests potential for subtle vulnerabilities if these paths are reachable. Furthermore, the complete lack of nonce checks and capability checks, coupled with the absence of any authentication checks on its entry points (AJAX, REST API, shortcodes, cron), represents a considerable risk. This means that any code that interacts with the plugin could potentially be exploited without proper authorization, leaving the door open for unauthorized actions.
While the plugin has no recorded vulnerabilities, this may be due to its limited exposure or because the current analysis hasn't uncovered exploitable issues. The critical missing authentication and authorization mechanisms on all entry points are a significant weakness. The taint analysis revealing unsanitized paths, even without critical severity, warrants careful investigation as it points to potential weaknesses in input validation. In conclusion, while the plugin avoids common pitfalls like raw SQL and lacks historical vulnerabilities, the absence of fundamental security checks and the presence of unsanitized paths create a concerning attack surface that needs immediate attention to mitigate potential risks.
Key Concerns
- Unsanitized paths found in taint analysis
- No nonce checks found
- No capability checks found
- No authentication checks on AJAX handlers
- No authentication checks on REST API routes
- Output escaping is not 100%
Pars Host Addons Security Vulnerabilities
Pars Host Addons Code Analysis
Output Escaping
Data Flow Analysis
Pars Host Addons Attack Surface
WordPress Hooks 24
Maintenance & Trust
Pars Host Addons Maintenance & Trust
Maintenance Signals
Community Trust
Pars Host Addons Alternatives
LWS Optimize – All-in-One Speed Booster & Cache Tools
lws-optimize
All-in-one speed optimization: caching, WebP/AVIF, Critical CSS, lazy loading, CDN, and more. Instantly boost Core Web Vitals and site speed!
Zero Config Performance Optimization
wpo-tweaks
Advanced performance optimizations for WordPress. Improves speed, reduces server resources and optimizes PageSpeed.
Seraphinite Accelerator
seraphinite-accelerator
Turns on site high speed to be attractive for people and search engines.
WP Compress – Instant Performance & Speed Optimization
wp-compress-image-optimizer
Everything you need for a faster website – smart optimization, advanced caching, adaptive images, WebP creation, script improvements, optional CDN del …
Core Web Vitals & PageSpeed Booster
core-web-vitals-pagespeed-booster
Core Web Vitals (CWV) is the new ranking factor
Pars Host Addons Developer Profile
1 plugin · 0 total installs
How We Detect Pars Host Addons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pars-host-addons/css/pars-host-wp-admin.css/wp-content/plugins/pars-host-addons/partials/assets/fonts/yekan-bakh/font.css/wp-content/plugins/pars-host-addons/css/bootstrap.rtl.min.css/wp-content/plugins/pars-host-addons/js/pars-host-wp-admin.jsjs/pars-host-wp-admin.jspars-host-wp-admin.css?ver=font.css?ver=bootstrap.rtl.min.css?ver=pars-host-wp-admin.js?ver=HTML / DOM Fingerprints
parshost-dashboard-pagedata-pars-host-pageParsHostAdminParsHostAjax