Tiny CDN Security & Risk Analysis

wordpress.org/plugins/tiny-cdn

Use an origin pull CDN with very few lines of code.

10 active installs v0.1.6 PHP + WP 4.0+ Updated Oct 6, 2018
cdncontent-delivery-networkoptimizationperformance
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Tiny CDN Safe to Use in 2026?

Generally Safe

Score 85/100

Tiny CDN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'tiny-cdn' plugin v0.1.6 exhibits a strong security posture. The absence of any identified dangerous functions, raw SQL queries, unsanitized taint flows, and file operations suggests diligent coding practices and a focus on security. The code also demonstrates good output escaping and utilizes prepared statements exclusively for any SQL interactions, further mitigating common attack vectors. The presence of a capability check, though singular, indicates at least some awareness of authorization. The plugin's vulnerability history is also entirely clear, with no recorded CVEs, which is a significant positive indicator.

However, the static analysis reveals a complete lack of any identified attack surface entry points, which is unusual for a plugin that likely performs some function. This could mean the plugin is extremely minimal or that the analysis might have missed certain entry points. Crucially, there are zero nonce checks and zero AJAX handlers without authentication checks explicitly identified. While the capability check is present, the lack of direct nonce checks for potentially interactive elements like AJAX handlers presents a potential blind spot. The absence of identified REST API routes without permission callbacks is also a positive, but the overall lack of discovered entry points, coupled with a single capability check and no nonce checks, suggests that while the core code is clean, the plugin's integration and interaction points might require further scrutiny to ensure comprehensive security. The current data suggests a strong foundation, but a complete absence of interaction points is worth noting.

Key Concerns

  • No identified nonce checks
  • No identified AJAX handlers without auth checks
  • No identified REST API routes without permission callbacks
Vulnerabilities
None known

Tiny CDN Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Tiny CDN Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Tiny CDN Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actiontemplate_redirecttiny-cdn.php:25
filterplugins_urltiny-cdn.php:47
filtertheme_root_uritiny-cdn.php:48
filterupload_dirtiny-cdn.php:49
filterscript_loader_srctiny-cdn.php:52
filterstyle_loader_srctiny-cdn.php:53
filterthe_contenttiny-cdn.php:56
filterwidget_texttiny-cdn.php:57
filterwp_get_attachment_image_srctiny-cdn.php:60
filterwpseo_opengraph_imagetiny-cdn.php:63
filterwpseo_xml_sitemap_img_srctiny-cdn.php:64
filtertiny_cdntiny-cdn.php:66
Maintenance & Trust

Tiny CDN Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 6, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tiny CDN Developer Profile

Viktor Szépe

8 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tiny CDN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tiny-cdn/assets/css/main.css/wp-content/plugins/tiny-cdn/assets/js/main.js
Script Paths
/wp-content/plugins/tiny-cdn/assets/js/main.js
Version Parameters
tiny-cdn/assets/css/main.css?ver=tiny-cdn/assets/js/main.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Tiny CDN