Static Snap Security & Risk Analysis

wordpress.org/plugins/static-snap

Static Snap converts your WordPress site into a static website, boosting performance, security, scalability, and SEO.

30 active installs v0.3.6 PHP 7.4+ WP 6.5.0+ Updated Aug 11, 2025
headlessperformancesecurityseostatic-site-generator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Static Snap Safe to Use in 2026?

Generally Safe

Score 100/100

Static Snap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The static analysis of "static-snap" v0.3.6 reveals a generally strong security posture. The plugin demonstrates excellent practices regarding SQL query sanitization, with 99% of queries utilizing prepared statements, and all output is properly escaped, indicating a low risk of common injection and cross-site scripting vulnerabilities. The absence of any recorded CVEs, particularly critical or high severity ones, further reinforces this positive assessment. The plugin also incorporates nonce and capability checks, which are essential for securing entry points. However, the presence of 6 file operations and 11 external HTTP requests, while not inherently problematic, represent potential areas that warrant closer scrutiny in a dynamic analysis phase, as their implementation could introduce vulnerabilities if not handled with extreme care. The attack surface is minimal, with only one REST API route, and importantly, this route has permission callbacks, meaning it is protected. The lack of any taint analysis findings is also a positive sign, suggesting no easily identifiable data flow vulnerabilities in the analyzed code.

Key Concerns

  • External HTTP requests present
  • File operations present
Vulnerabilities
None known

Static Snap Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Static Snap Release Timeline

v0.3.6Current
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.9
v0.2.8
v0.2.7
v0.2.6
v0.2.5
v0.2.4
v0.2.3
Code Analysis
Analyzed Mar 16, 2026

Static Snap Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
77 prepared
Unescaped Output
0
35 escaped
Nonce Checks
2
Capability Checks
13
File Operations
6
External Requests
11
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

99% prepared78 total queries

Output Escaping

100% escaped35 total outputs
Attack Surface

Static Snap Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

GET/wp-json/static-snap/v1/statussrc\rest\class-rest.php:49
WordPress Hooks 36
actionadmin_bar_menusrc\dashboard\class-admin-bar.php:33
actionadmin_menusrc\dashboard\class-settings.php:35
actionadmin_enqueue_scriptssrc\dashboard\class-settings.php:37
actionwp_enqueue_scriptssrc\dashboard\class-settings.php:39
actionadmin_enqueue_scriptssrc\dashboard\class-settings.php:111
filterquerysrc\database\class-table.php:238
actioninitsrc\deployment\class-head.php:28
filterget_shortlinksrc\deployment\class-head.php:40
actionelementor/frontend/before_enqueue_scriptssrc\extensions\elementor\class-elementor-extension.php:23
actionelementor/elements/categories_registeredsrc\extensions\elementor\class-elementor-extension.php:24
actionelementor/widgets/widgets_registeredsrc\extensions\elementor\class-elementor-extension.php:25
filterwpcf7_load_jssrc\extensions\forms\contact-form-7\class-contact-form-7-extension.php:34
filterwpcf7_form_action_urlsrc\extensions\forms\contact-form-7\class-contact-form-7-extension.php:35
filterwpcf7_form_additional_attssrc\extensions\forms\contact-form-7\class-contact-form-7-extension.php:36
filterwpcf7_form_hidden_fieldssrc\extensions\forms\contact-form-7\class-contact-form-7-extension.php:37
actionwp_enqueue_scriptssrc\extensions\forms\contact-form-7\class-contact-form-7-extension.php:38
actionwp_enqueue_scriptssrc\extensions\forms\elementor\class-elementor-form-extension.php:41
actionelementor-pro/forms/pre_rendersrc\extensions\forms\elementor\class-elementor-form-extension.php:43
actionelementor/frontend/before_rendersrc\extensions\forms\elementor\class-elementor-form-extension.php:45
filterelementor_pro/forms/render/itemsrc\extensions\forms\elementor\class-elementor-form-extension.php:46
filtergform_form_tagsrc\extensions\forms\gravity-forms\class-gravity-forms-extension.php:33
filtergform_form_argssrc\extensions\forms\gravity-forms\class-gravity-forms-extension.php:34
filtergform_field_contentsrc\extensions\forms\gravity-forms\class-gravity-forms-extension.php:35
actionwp_enqueue_scriptssrc\extensions\forms\gravity-forms\class-gravity-forms-extension.php:36
filterwpforms_frontend_form_actionsrc\extensions\forms\wp-forms\class-wp-forms-extension.php:32
filterwpforms_frontend_form_attssrc\extensions\forms\wp-forms\class-wp-forms-extension.php:33
actionwpforms_display_submit_beforesrc\extensions\forms\wp-forms\class-wp-forms-extension.php:34
actionwp_enqueue_scriptssrc\extensions\forms\wp-forms\class-wp-forms-extension.php:35
actionrest_api_initsrc\extensions\fuse-js\class-fuse-js-search-extension.php:29
actionwp_footersrc\extensions\search\algolia\class-algolia-extension.php:49
filterdo_rocket_generate_caching_filessrc\extensions\wp-rocket\class-wp-rocket-extension.php:20
actionwp_enqueue_scriptssrc\frontend\class-frontend.php:25
actionwp_footersrc\frontend\class-frontend.php:27
actionrest_api_initsrc\rest\class-rest.php:29
actionplugins_loadedstatic-snap.php:68
filtercron_schedulesvendor_prefixed\deliciousbrains\wp-background-processing\classes\wp-background-process.php:90
Maintenance & Trust

Static Snap Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 11, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Static Snap Developer Profile

staticsnap

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Static Snap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/static-snap/assets/js/frontend.js/wp-content/plugins/static-snap/assets/js/dashboard.js
Script Paths
/wp-content/plugins/static-snap/vendor/autoload.php
Version Parameters
static-snap-frontendstatic-snap-dashboard

HTML / DOM Fingerprints

JS Globals
StaticSnapDashboardConfig
FAQ

Frequently Asked Questions about Static Snap