
Super Preloader for Cloudflare Security & Risk Analysis
wordpress.org/plugins/super-preloader-for-cloudflarePreload your sitemap URLs into multiple Cloudflare edge locations using proxies and a custom Cloudflare Worker.
Is Super Preloader for Cloudflare Safe to Use in 2026?
Generally Safe
Score 100/100Super Preloader for Cloudflare has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "super-preloader-for-cloudflare" plugin version 1.0.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and properly escaping the vast majority of its output. The absence of any known vulnerabilities in its history is also a strong indicator of developer diligence. However, a significant concern lies in its attack surface. With a total of 3 entry points identified, all 3 are unprotected AJAX handlers. This means that any unauthenticated user could potentially interact with these AJAX endpoints, posing a considerable risk if these handlers are not robustly secured through other means or if they expose sensitive functionality.
The static analysis reveals no dangerous functions, no critical or high-severity taint flows, and no raw SQL queries, which are all positive signs. The plugin also includes nonce checks and capability checks, though the lack of authentication checks on AJAX handlers overshadows this to some extent. The presence of file operations and external HTTP requests, while not inherently insecure, warrants further investigation in conjunction with the unprotected AJAX handlers.
Overall, the plugin is built on a foundation of generally secure coding practices, particularly regarding database interactions and output sanitization. The lack of a vulnerability history is reassuring. Nevertheless, the exposure of all AJAX entry points to unauthenticated users is a critical weakness that significantly elevates the risk profile. This plugin would be considered moderately secure if the AJAX endpoints were properly protected, but as is, it presents a tangible security risk.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
Super Preloader for Cloudflare Security Vulnerabilities
Super Preloader for Cloudflare Release Timeline
Super Preloader for Cloudflare Code Analysis
Output Escaping
Data Flow Analysis
Super Preloader for Cloudflare Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Scheduled Events 3
Maintenance & Trust
Super Preloader for Cloudflare Maintenance & Trust
Maintenance Signals
Community Trust
Super Preloader for Cloudflare Alternatives
Proxy Cache Purge
varnish-http-purge
Automatically empty proxy cached content when your site is modified.
Cache Warmer
cache-warmer
Visits website pages to warm (create) the cache if you have any caching solutions configured.
Nginx Cache Controller
nginx-champuru
Provides some functions of controlling Nginx proxy server cache.
Servebolt Optimizer
servebolt-optimizer
This plugin implements Servebolt's WordPress best practices, and connects your site to the Servebolt Admin Panel.
Cloudflare Page Cache
cloudflare-page-cache
Adds support for caching pages on Cloudflare and automatic purging when content changes.
Super Preloader for Cloudflare Developer Profile
2 plugins · 50 total installs
How We Detect Super Preloader for Cloudflare
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/super-preloader-for-cloudflare/css/admin-ui.css/wp-content/plugins/super-preloader-for-cloudflare/js/admin-ui.js/wp-content/plugins/super-preloader-for-cloudflare/js/admin-ui.jssuper-preloader-for-cloudflare/css/admin-ui.css?ver=super-preloader-for-cloudflare/js/admin-ui.js?ver=HTML / DOM Fingerprints
wpff-sp-settings-layoutwpff-sp-settings-mainwpff-sp-settings-sidebarwpff