Preload Everything Security & Risk Analysis

wordpress.org/plugins/preload-everything

Fasten Your Website Loading Speed By Preloading Internal Pages Ahead Of The Time For Your Visitors.

10 active installs v2.0.2 PHP 8.0+ WP 5.6+ Updated Dec 14, 2025
performancepreloadpreloadingspeedspeed-optimization
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Preload Everything Safe to Use in 2026?

Generally Safe

Score 100/100

Preload Everything has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "preload-everything" v2.0.2 plugin exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, the absence of file operations and external HTTP requests reduces the attack surface. The plugin also has no recorded vulnerability history, indicating a consistent track record of security. However, the complete absence of nonce and capability checks across all identified entry points (though none are explicitly listed as unprotected) is a notable area of concern. While the static analysis reports zero unprotected entry points, the lack of these fundamental WordPress security mechanisms means that if any entry points were to be introduced or exposed in the future, they would be inherently vulnerable to certain types of attacks.

While the current state of the plugin appears secure due to its limited attack surface and diligent coding practices in other areas, the lack of robust authentication and authorization checks on any potential entry points represents a potential weakness. This is particularly concerning if the plugin's functionality might evolve to include user-facing interactions or data manipulation. The clean vulnerability history is a significant positive, but it doesn't entirely mitigate the inherent risk associated with the absence of these critical security checks.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Preload Everything Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Preload Everything Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
53 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped53 total outputs
Attack Surface

Preload Everything Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuincludes\class-preload-everything.php:123
actionadmin_initincludes\class-preload-everything.php:124
actionwp_enqueue_scriptsincludes\class-preload-everything.php:137
actionadmin_enqueue_scriptsincludes\class-sajjad-dev-settings-api.php:324
Maintenance & Trust

Preload Everything Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 14, 2025
PHP min version8.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Preload Everything Developer Profile

Sajjad Hossain Sagor

32 plugins · 10K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
139 days
View full developer profile
Detection Fingerprints

How We Detect Preload Everything

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/preload-everything/public/assets/css/preload-everything.css/wp-content/plugins/preload-everything/public/assets/js/preload-everything.js
Script Paths
/wp-content/plugins/preload-everything/public/assets/js/preload-everything.js
Version Parameters
preload-everything/public/assets/css/preload-everything.css?ver=preload-everything/public/assets/js/preload-everything.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Preload Everything