
Statixly Security & Risk Analysis
wordpress.org/plugins/statixlyGenerate a static HTML version of your WordPress website and download it as a ZIP archive.
Is Statixly Safe to Use in 2026?
Generally Safe
Score 100/100Statixly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Statixly v1.0.2 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and all output is properly escaped, mitigating risks of SQL injection and Cross-Site Scripting (XSS) originating from direct output manipulation. The absence of known CVEs and a clean vulnerability history also suggests a generally well-maintained codebase.
However, a significant concern lies in the plugin's attack surface. With 10 AJAX handlers, an overwhelming 9 lack proper authentication checks. This exposes a substantial portion of the plugin's functionality to unauthorized users, potentially leading to various exploits if these handlers perform sensitive actions or expose information. The limited use of nonce checks (4) further exacerbates this issue, as they are a crucial mechanism for verifying the legitimacy of requests. While taint analysis shows no critical or high-severity flows, the sheer number of unprotected entry points makes it a prime target for brute-force attacks or exploitation of any potential logic flaws within those handlers.
In conclusion, while the plugin excels in core security principles like prepared statements and output escaping, the extensive unprotected AJAX handlers represent a critical weakness. This significantly increases the risk of unauthorized access and potential misuse of plugin features. Until these AJAX handlers are secured with appropriate nonce and capability checks, Statixly v1.0.2 should be considered to have a moderate to high security risk.
Key Concerns
- 9 unprotected AJAX handlers
- Limited nonce checks (4)
Statixly Security Vulnerabilities
Statixly Release Timeline
Statixly Code Analysis
SQL Query Safety
Output Escaping
Statixly Attack Surface
AJAX Handlers 10
WordPress Hooks 8
Maintenance & Trust
Statixly Maintenance & Trust
Maintenance Signals
Community Trust
Statixly Alternatives
Simply Static – The Static Site Generator
simply-static
Convert WordPress to static HTML. Boost performance 3-5x. Eliminate security vulnerabilities. Deploy anywhere.
Blizhost CloudCache Purge – Speed, Security, and Optimization
blizhost-cache-purge
Automatic Cache Clearing and CloudCache Integration to Boost Speed and Protect Your Site with Enhanced Security.
Make Me Static, Static Site Generator, Git, Pages and Live Stats
make-me-static
Static site generator using Git for storage. Comes with free integrated Git + Pages solution including Live WebStats.
Static Snap
static-snap
Static Snap converts your WordPress site into a static website, boosting performance, security, scalability, and SEO.
FBS Secure Optimize
fbs-secure-optimize
A comprehensive WordPress plugin for performance optimization and security enhancement. Features asset optimization, database cleanup, and security.
Statixly Developer Profile
2 plugins · 9K total installs
How We Detect Statixly
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statixly/assets/css/admin.css/wp-content/plugins/statixly/assets/css/export.css/wp-content/plugins/statixly/assets/js/export.js/wp-content/plugins/statixly/assets/js/export.jsstatixly-adminstatixly-exportHTML / DOM Fingerprints
Copyright (C) 2026 Anindya Sundar MandalThis file is part of Statixly. For full license text, see license.txt.statixlyExportData