
StaticDelivr: Free CDN, Image Optimization & Speed Security & Risk Analysis
wordpress.org/plugins/staticdelivrSpeed up WordPress with free CDN delivery, image optimization, smart asset detection, failure recovery, and privacy-first Google Fonts proxy.
Is StaticDelivr: Free CDN, Image Optimization & Speed Safe to Use in 2026?
Generally Safe
Score 100/100StaticDelivr: Free CDN, Image Optimization & Speed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The staticdelivr v2.5.2 plugin exhibits a generally strong security posture based on the provided static analysis. It has a small attack surface, with all identified entry points (AJAX handlers) appearing to have proper authentication checks, which is a significant positive. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and a high percentage of properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. Furthermore, the plugin has no known vulnerability history, indicating a commitment to security or a lack of past issues.
However, the lack of explicit capability checks on its AJAX handlers, despite the presence of nonce checks, could represent a potential weakness. While nonce checks prevent CSRF attacks, they don't restrict functionality based on user roles, meaning any authenticated user could potentially trigger these AJAX actions. The absence of taint analysis results is also noteworthy, as it implies either no such analysis was performed or no flows were identified; the former could mean potential issues were missed.
In conclusion, staticdelivr v2.5.2 appears to be a secure plugin with strong foundations. The primary area for improvement lies in implementing capability checks for its AJAX endpoints to ensure that only authorized users can perform specific actions. The lack of reported vulnerabilities is encouraging, but continuous vigilance and comprehensive taint analysis are always recommended for robust security.
Key Concerns
- Missing capability checks on AJAX handlers
StaticDelivr: Free CDN, Image Optimization & Speed Security Vulnerabilities
StaticDelivr: Free CDN, Image Optimization & Speed Release Timeline
StaticDelivr: Free CDN, Image Optimization & Speed Code Analysis
Output Escaping
StaticDelivr: Free CDN, Image Optimization & Speed Attack Surface
AJAX Handlers 2
WordPress Hooks 32
Maintenance & Trust
StaticDelivr: Free CDN, Image Optimization & Speed Maintenance & Trust
Maintenance Signals
Community Trust
StaticDelivr: Free CDN, Image Optimization & Speed Alternatives
SpeedyCache – Cache, Optimization, Performance
speedycache
SpeedyCache is a WordPress cache plugin that helps you improve performance of your WordPress site by caching, minifying, and compressing your website.
WP Compress – Instant Performance & Speed Optimization
wp-compress-image-optimizer
Everything you need for a faster website – smart optimization, advanced caching, adaptive images, WebP creation, script improvements, optional CDN del …
Swift Performance Lite
swift-performance-lite
Swift Performance is a cache and performance booster plugin. It can speed up your site, improve SEO scores and user experience.
BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript
searchpro
Automatically boost your PageSpeed score to 90+ for both mobile & desktop and pass Core Web Vitals for WordPress website without any technical skills.
GoCache
gocache-cdn
Acelere seu site e reduza seus custos com cloud.
StaticDelivr: Free CDN, Image Optimization & Speed Developer Profile
1 plugin · 10 total installs
How We Detect StaticDelivr: Free CDN, Image Optimization & Speed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/staticdelivr/assets/css/staticdelivr-admin.css/wp-content/plugins/staticdelivr/assets/css/staticdelivr-frontend.css/wp-content/plugins/staticdelivr/assets/js/staticdelivr-admin.js/wp-content/plugins/staticdelivr/assets/js/staticdelivr-frontend.js/wp-content/plugins/staticdelivr/assets/js/staticdelivr-fallback.jsstaticdelivr-admin.css?ver=staticdelivr-frontend.css?ver=staticdelivr-admin.js?ver=staticdelivr-frontend.js?ver=staticdelivr-fallback.js?ver=HTML / DOM Fingerprints
staticdelivr-cdn-settings<!-- StaticDelivr CDN Fallback Script --><!-- StaticDelivr CDN Script -->data-staticdelivr-configStaticDelivr/wp-json/staticdelivr/v1/config