
Simply Static – The Static Site Generator Security & Risk Analysis
wordpress.org/plugins/simply-staticConvert WordPress to static HTML. Boost performance 3-5x. Eliminate security vulnerabilities. Deploy anywhere.
Is Simply Static – The Static Site Generator Safe to Use in 2026?
Generally Safe
Score 99/100Simply Static – The Static Site Generator has a strong security track record. Known vulnerabilities have been patched promptly.
The Simply Static plugin v3.6.3 demonstrates a generally strong security posture with excellent adoption of security best practices. The attack surface is well-managed, with all identified AJAX handlers and REST API routes protected by appropriate permission callbacks, which is a significant positive. The code signals indicate a robust approach to security, with a high percentage of SQL queries using prepared statements and a vast majority of outputs being properly escaped. The presence of nonce checks and capability checks further reinforces this good practice.
However, a critical area of concern is the use of the `unserialize` function. This function is inherently risky as it can lead to Remote Code Execution (RCE) vulnerabilities if an attacker can control the data being unserialized. While no direct taint flows were identified from this function in the provided analysis, it remains a potential entry point for sophisticated attacks. The vulnerability history, while showing no currently unpatched CVEs, reveals past issues related to sensitive information logging and Cross-Site Scripting (XSS). The recency of the last vulnerability (April 2024) suggests ongoing security considerations and the need for continued vigilance.
In conclusion, Simply Static v3.6.3 is commendably built with security in mind, especially regarding its attack surface and general coding practices. The primary weakness lies in the `unserialize` function, which requires careful monitoring and potential mitigation. The past vulnerability history, though resolved, serves as a reminder that even well-secured plugins can have exploitable flaws, necessitating prompt updates for future versions.
Key Concerns
- Use of the 'unserialize' function
Simply Static – The Static Site Generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Simply Static <= 3.1.3 - Unauthenticated Information Exposure
Simply Static <= 3.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Simply Static – The Static Site Generator Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Simply Static – The Static Site Generator Attack Surface
AJAX Handlers 1
REST API Routes 65
WordPress Hooks 82
Maintenance & Trust
Simply Static – The Static Site Generator Maintenance & Trust
Maintenance Signals
Community Trust
Simply Static – The Static Site Generator Alternatives
Make Me Static, Static Site Generator, Git, Pages and Live Stats
make-me-static
Static site generator using Git for storage. Comes with free integrated Git + Pages solution including Live WebStats.
Static Snap
static-snap
Static Snap converts your WordPress site into a static website, boosting performance, security, scalability, and SEO.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
Plugin Check (PCP)
plugin-check
Plugin Check is a WordPress.org tool which provides checks to help plugins meet the directory requirements and follow various best practices.
Simply Static – The Static Site Generator Developer Profile
1 plugin · 30K total installs
How We Detect Simply Static – The Static Site Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simply-static/assets/css/admin.css/wp-content/plugins/simply-static/assets/js/admin.js/wp-content/plugins/simply-static/assets/js/admin.jssimply-static/assets/css/admin.css?ver=simply-static/assets/js/admin.js?ver=HTML / DOM Fingerprints
simply-static-settings-formsimply-static-export-logsimply-static-settings-navigationdata-simply-static-idsimplyStaticAdmin/wp-json/simply-static/v1/settings/export_404