Smart Prefetch: Unlock Lightning-Fast Navigation Security & Risk Analysis

wordpress.org/plugins/smart-prefetch

Eliminate mobile latency with AI predictive prefetching. Load pages before the click to protect ad spend, boost UX, and maximize conversions.

0 active installs v1.6.1 PHP 7.2+ WP 5.2+ Updated Apr 6, 2026
core-web-vitalsoptimizationperformanceprefetchspeed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smart Prefetch: Unlock Lightning-Fast Navigation Safe to Use in 2026?

Generally Safe

Score 100/100

Smart Prefetch: Unlock Lightning-Fast Navigation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The smart-prefetch plugin version 1.4.1 exhibits a generally good security posture based on the provided static analysis. It demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped. There are no indications of dangerous functions being used, file operations, or the bundling of external libraries, which are all positive signs. The absence of known vulnerabilities in its history further suggests a mature and well-maintained codebase.

However, a significant concern arises from the identified REST API route that lacks permission callbacks. This creates an unprotected entry point into the plugin's functionality. While no taint flows were detected, indicating no immediate susceptibility to common injection attacks from this specific REST API route in the static analysis, this unprotected endpoint represents a potential attack vector. An attacker could potentially trigger this route without proper authorization, leading to unintended consequences, depending on what the route actually does. The presence of only one identified entry point, while small, is entirely unprotected, which is a notable weakness.

In conclusion, the plugin's core coding practices are strong, particularly concerning data handling and output sanitization. The primary weakness lies in the single unprotected REST API route. While the current lack of detected vulnerabilities and taint flows is reassuring, this unprotected endpoint warrants attention as a potential avenue for future exploits or misuse. Addressing this single unprotected REST API route would significantly enhance the plugin's overall security.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

Smart Prefetch: Unlock Lightning-Fast Navigation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Smart Prefetch: Unlock Lightning-Fast Navigation Release Timeline

v1.6.1Current
v1.6.0
v1.5.1
v1.5.0
v1.4.1
v1.3.0
v1.2.0
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Smart Prefetch: Unlock Lightning-Fast Navigation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
11 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped11 total outputs
Attack Surface
1 unprotected

Smart Prefetch: Unlock Lightning-Fast Navigation Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/smartprefetch/v1/validate-emailinc\public.php:111
WordPress Hooks 7
actionadmin_menuinc\admin.php:9
actioninitinc\public.php:12
actionwp_enqueue_scriptsinc\public.php:17
actiontemplate_redirectinc\public.php:18
filterwp_headersinc\public.php:19
actionrest_api_initinc\public.php:20
filterplugin_action_links_smart-prefetch/smart-prefetch.phpsmart-prefetch.php:25
Maintenance & Trust

Smart Prefetch: Unlock Lightning-Fast Navigation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 6, 2026
PHP min version7.2
Downloads703

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Smart Prefetch: Unlock Lightning-Fast Navigation Developer Profile

Buggu Labs

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smart Prefetch: Unlock Lightning-Fast Navigation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smart-prefetch/admin/css/style.css
Script Paths
https://pub-cdn.smartprefetch.link/prefetch/index.min.js
Version Parameters
smart-prefetch/admin/css/style.css?v=/prefetch/index.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-smart-prefetch-link
JS Globals
SmartPrefetch
REST Endpoints
/smartprefetch/v1/validate-email
FAQ

Frequently Asked Questions about Smart Prefetch: Unlock Lightning-Fast Navigation