Static Cache Wrangler – Headless Assistant Security & Risk Analysis

wordpress.org/plugins/stcw-headless-assistant

Convert Static Cache Wrangler HTML output to headless CMS import formats with pluggable architecture.

0 active installs v2.1.0 PHP 7.4+ WP 6.0+ Updated Jan 22, 2026
cmsconverterexporterheadlesssanity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Static Cache Wrangler – Headless Assistant Safe to Use in 2026?

Generally Safe

Score 100/100

Static Cache Wrangler – Headless Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "stcw-headless-assistant" plugin v2.1.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, the use of prepared statements for all SQL queries, and a high percentage of properly escaped output are excellent indicators of secure coding practices. Furthermore, the lack of known vulnerabilities and CVEs in its history suggests a well-maintained and secure plugin. The plugin also demonstrates a very limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the opportunities for attackers to interact with the plugin's code.

However, a critical concern arises from the absence of any nonce checks across all entry points, which were identified as having 0 total entry points and 0 unprotected entry points. While the static analysis reports 0 unprotected entry points, the lack of any nonce checks, even if capability checks are present, represents a significant oversight. This could potentially leave the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks if any of its functionalities were to be triggered by external requests without proper verification. The plugin does have one capability check, which is a positive sign, but this alone does not fully mitigate CSRF risks. Therefore, while the plugin excels in many areas of secure coding, the missing nonce checks present a notable weakness.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

Static Cache Wrangler – Headless Assistant Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Static Cache Wrangler – Headless Assistant Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
103 prepared
Unescaped Output
1
58 escaped
Nonce Checks
0
Capability Checks
1
File Operations
13
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared103 total queries

Output Escaping

98% escaped59 total outputs
Attack Surface

Static Cache Wrangler – Headless Assistant Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuadmin\class-stcw-headless-admin.php:21
actionadmin_enqueue_scriptsadmin\class-stcw-headless-admin.php:22
actionadmin_noticesstcw-headless-assistant.php:83
filterplugin_row_metastcw-headless-assistant.php:105
actioninitstcw-headless-assistant.php:120
actionplugins_loadedstcw-headless-assistant.php:122
Maintenance & Trust

Static Cache Wrangler – Headless Assistant Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 22, 2026
PHP min version7.4
Downloads100

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Static Cache Wrangler – Headless Assistant Developer Profile

derickschaefer

5 plugins · 30 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Static Cache Wrangler – Headless Assistant

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stcw-headless-assistant/admin/css/admin-style.css/wp-content/plugins/stcw-headless-assistant/admin/js/admin-script.js
Script Paths
admin/js/admin-script.js
Version Parameters
stcw-headless-assistant/admin/css/admin-style.css?ver=stcw-headless-assistant/admin/js/admin-script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Static Cache Wrangler – Headless Assistant