wao.io Cache Control Security & Risk Analysis

wordpress.org/plugins/wao-io-cache-control

wao.io Cache Control is a free plugin to clear your WordPress site's cache at wao.io.

10 active installs v1.0.0 PHP 5.6+ WP 4.8+ Updated Aug 9, 2020
cachecachingclearcontrolpagespeed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is wao.io Cache Control Safe to Use in 2026?

Generally Safe

Score 85/100

wao.io Cache Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "wao-io-cache-control" v1.0.0 plugin exhibits a generally good security posture due to a lack of identified critical vulnerabilities and a complete absence of known CVEs. The code also demonstrates responsible practices by utilizing prepared statements for all SQL queries and not performing any file operations or external HTTP requests without apparent safeguards. The presence of only one external HTTP request is noted, and while not explicitly flagged as insecure, it warrants careful monitoring. The primary concern arises from the taint analysis, which revealed one flow with an unsanitized path. Although this did not reach a critical or high severity, it indicates a potential weakness that could be exploited under specific conditions. Furthermore, the lack of output escaping for a significant portion (67%) of identified outputs is a notable risk, potentially exposing the application to Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is not properly handled before display.

While the plugin has no recorded vulnerability history, suggesting a stable and well-maintained codebase thus far, the identified taint flow and insufficient output escaping are areas that require immediate attention. The absence of any reported vulnerabilities is a positive indicator, but it does not negate the risks identified through static and taint analysis. Future development should prioritize addressing the unsanitized path and ensuring all output is properly escaped to maintain a robust security profile. The plugin's strengths lie in its SQL handling and lack of known exploits, but its weaknesses in output sanitization and the presence of an unsanitized path need to be rectified.

Key Concerns

  • Unsanitized path in taint flow
  • Insufficient output escaping
Vulnerabilities
None known

wao.io Cache Control Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

wao.io Cache Control Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

33% escaped15 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<cache-control> (cache-control.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

wao.io Cache Control Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_initwao-io-cache-control.php:66
actionadmin_menuwao-io-cache-control.php:199
actionadmin_post_clear_cachewao-io-cache-control.php:200
actionadmin_noticeswao-io-cache-control.php:204
actionpublish_postwao-io-cache-control.php:219
actionpublish_pagewao-io-cache-control.php:220
actionafter_switch_themewao-io-cache-control.php:221
actioncustomize_save_afterwao-io-cache-control.php:222
actionupdate_theme_complete_actionswao-io-cache-control.php:223
actionupgrader_process_completewao-io-cache-control.php:224
actionplugins_loadedwao-io-cache-control.php:256
Maintenance & Trust

wao.io Cache Control Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 9, 2020
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

wao.io Cache Control Developer Profile

wao.io

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect wao.io Cache Control

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wao-io-cache-control/admin/css/main.css/wp-content/plugins/wao-io-cache-control/admin/js/main.js
Script Paths
/wp-content/plugins/wao-io-cache-control/admin/js/main.js
Version Parameters
wao-io-cache-control/admin/css/main.css?ver=wao-io-cache-control/admin/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
wao-io-cache-control-wrapper
HTML Comments
<!-- wao.io Cache Control by Avenga Germany GmbH --><!-- If you do not have an API key yet, please contact wao.io support! -->
Data Attributes
data-wao-io-cache-control-nonce
JS Globals
wao_io_cc_ajax_object
FAQ

Frequently Asked Questions about wao.io Cache Control