StaticDelivr: Free CDN, Image Optimization & Speed Security & Risk Analysis

wordpress.org/plugins/staticdelivr

Speed up WordPress with free CDN delivery, image optimization, smart asset detection, failure recovery, and privacy-first Google Fonts proxy.

10 active installs v2.5.2 PHP 7.4+ WP 5.8+ Updated Jan 27, 2026
cachecdngdprimage-optimizationspeed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is StaticDelivr: Free CDN, Image Optimization & Speed Safe to Use in 2026?

Generally Safe

Score 100/100

StaticDelivr: Free CDN, Image Optimization & Speed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The staticdelivr v2.5.2 plugin exhibits a generally strong security posture based on the provided static analysis. It has a small attack surface, with all identified entry points (AJAX handlers) appearing to have proper authentication checks, which is a significant positive. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and a high percentage of properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. Furthermore, the plugin has no known vulnerability history, indicating a commitment to security or a lack of past issues.

However, the lack of explicit capability checks on its AJAX handlers, despite the presence of nonce checks, could represent a potential weakness. While nonce checks prevent CSRF attacks, they don't restrict functionality based on user roles, meaning any authenticated user could potentially trigger these AJAX actions. The absence of taint analysis results is also noteworthy, as it implies either no such analysis was performed or no flows were identified; the former could mean potential issues were missed.

In conclusion, staticdelivr v2.5.2 appears to be a secure plugin with strong foundations. The primary area for improvement lies in implementing capability checks for its AJAX endpoints to ensure that only authorized users can perform specific actions. The lack of reported vulnerabilities is encouraging, but continuous vigilance and comprehensive taint analysis are always recommended for robust security.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

StaticDelivr: Free CDN, Image Optimization & Speed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

StaticDelivr: Free CDN, Image Optimization & Speed Release Timeline

v2.5.2Current
v2.5.1
v2.5.0
v2.4.1
v2.4.0
v2.3.0
v2.2.2
v2.2.1
v2.2.0
v2.1.0
v2.0.0
v1.7.1
v1.7.0
v1.6.0
v1.5.0
v1.4.0
v1.3.1
v1.3.0
v1.2.1
v1.2.0
Code Analysis
Analyzed Mar 17, 2026

StaticDelivr: Free CDN, Image Optimization & Speed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
74 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped80 total outputs
Attack Surface

StaticDelivr: Free CDN, Image Optimization & Speed Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_staticdelivr_report_failureincludes\class-staticdelivr-failure-tracker.php:69
noprivwp_ajax_staticdelivr_report_failureincludes\class-staticdelivr-failure-tracker.php:70
WordPress Hooks 32
actionadmin_menuincludes\class-staticdelivr-admin.php:76
actionadmin_initincludes\class-staticdelivr-admin.php:77
actionadmin_noticesincludes\class-staticdelivr-admin.php:78
actionadmin_enqueue_scriptsincludes\class-staticdelivr-admin.php:79
filterstyle_loader_srcincludes\class-staticdelivr-assets.php:81
filterscript_loader_srcincludes\class-staticdelivr-assets.php:82
filterscript_loader_tagincludes\class-staticdelivr-assets.php:83
filterstyle_loader_tagincludes\class-staticdelivr-assets.php:84
actionwp_footerincludes\class-staticdelivr-devtools.php:49
actionadmin_footerincludes\class-staticdelivr-devtools.php:50
actionshutdownincludes\class-staticdelivr-failure-tracker.php:66
actionwp_headincludes\class-staticdelivr-fallback.php:75
actionadmin_headincludes\class-staticdelivr-fallback.php:76
filterstyle_loader_srcincludes\class-staticdelivr-google-fonts.php:58
filterwp_resource_hintsincludes\class-staticdelivr-google-fonts.php:59
actiontemplate_redirectincludes\class-staticdelivr-google-fonts.php:62
actionshutdownincludes\class-staticdelivr-google-fonts.php:63
filterwp_get_attachment_image_srcincludes\class-staticdelivr-images.php:77
filterwp_calculate_image_srcsetincludes\class-staticdelivr-images.php:78
filterthe_contentincludes\class-staticdelivr-images.php:79
filterpost_thumbnail_htmlincludes\class-staticdelivr-images.php:80
filterwp_get_attachment_urlincludes\class-staticdelivr-images.php:81
actionshutdownincludes\class-staticdelivr-verification.php:68
actionswitch_themeincludes\class-staticdelivr-verification.php:71
actionactivated_pluginincludes\class-staticdelivr-verification.php:72
actiondeactivated_pluginincludes\class-staticdelivr-verification.php:73
actiondeleted_pluginincludes\class-staticdelivr-verification.php:74
filterhttp_request_timeoutincludes\class-staticdelivr-verification.php:351
filterhttp_request_timeoutincludes\class-staticdelivr-verification.php:399
actioninitstaticdelivr.php:92
actionplugins_loadedstaticdelivr.php:107
filterplugin_row_metastaticdelivr.php:176
Maintenance & Trust

StaticDelivr: Free CDN, Image Optimization & Speed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 27, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

StaticDelivr: Free CDN, Image Optimization & Speed Developer Profile

coozywana

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect StaticDelivr: Free CDN, Image Optimization & Speed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/staticdelivr/assets/css/staticdelivr-admin.css/wp-content/plugins/staticdelivr/assets/css/staticdelivr-frontend.css/wp-content/plugins/staticdelivr/assets/js/staticdelivr-admin.js/wp-content/plugins/staticdelivr/assets/js/staticdelivr-frontend.js/wp-content/plugins/staticdelivr/assets/js/staticdelivr-fallback.js
Version Parameters
staticdelivr-admin.css?ver=staticdelivr-frontend.css?ver=staticdelivr-admin.js?ver=staticdelivr-frontend.js?ver=staticdelivr-fallback.js?ver=

HTML / DOM Fingerprints

CSS Classes
staticdelivr-cdn-settings
HTML Comments
<!-- StaticDelivr CDN Fallback Script --><!-- StaticDelivr CDN Script -->
Data Attributes
data-staticdelivr-config
JS Globals
StaticDelivr
REST Endpoints
/wp-json/staticdelivr/v1/config
FAQ

Frequently Asked Questions about StaticDelivr: Free CDN, Image Optimization & Speed