
WEDOS | Protection & Cache Performance Security & Risk Analysis
wordpress.org/plugins/wgpwppActivate WEDOS Global protection — WAF, DDoS protection and CDN for your WordPress website.
Is WEDOS | Protection & Cache Performance Safe to Use in 2026?
Generally Safe
Score 99/100WEDOS | Protection & Cache Performance has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "wgpwpp" v1.2.2 exhibits a concerning security posture due to a significant number of unprotected entry points and a history of vulnerabilities, particularly related to missing authorization. While the use of prepared statements for SQL queries is a positive practice, it is overshadowed by the fact that all identified AJAX handlers and REST API routes lack proper authentication or permission checks. This creates a wide attack surface that could be easily exploited by unauthenticated users. The presence of the `unserialize` function is another critical red flag, especially in the absence of strict input validation, as it can lead to remote code execution vulnerabilities.
The vulnerability history, with a known unpatched medium severity CVE, further amplifies the risks. The pattern of "Missing Authorization" as a common vulnerability type strongly suggests a recurring oversight in how the plugin handles user permissions, making it a predictable target for attackers. While the plugin demonstrates some good practices like prepared statements, the overwhelming number of unprotected entry points and the historical vulnerability trend point towards a plugin that requires immediate attention and remediation to mitigate severe security risks.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function: unserialize
- Low percentage of properly escaped output
- Unpatched medium severity CVE
- Missing authorization vulnerability history
- Flows with unsanitized paths
WEDOS | Protection & Cache Performance Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WEDOS Global <= 1.2.2 - Missing Authorization
WEDOS | Protection & Cache Performance Release Timeline
WEDOS | Protection & Cache Performance Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WEDOS | Protection & Cache Performance Attack Surface
AJAX Handlers 12
REST API Routes 1
WordPress Hooks 39
Scheduled Events 1
Maintenance & Trust
WEDOS | Protection & Cache Performance Maintenance & Trust
Maintenance Signals
Community Trust
WEDOS | Protection & Cache Performance Alternatives
Security Ninja – WordPress Security & Firewall
security-ninja
WordPress security plugin with free 8G firewall/WAF, 50+ security tests, vulnerability and core scanning, events logging, and AI-powered security repo …
Advanced IP Blocker
advanced-ip-blocker
A complete WordPress security firewall: blocks IPs, bots, countries & ASN. Includes an intelligent WAF, Threat Scoring, Geo-Challenge, and 2FA.
BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection
bitfire
Stop hackers, bots, and malware before they touch your site. AI-powered security with real human support when you need it.
Anti-Hacker – Security Plugin
anti-hacker
Anti-Hacker protects your Wordpress against hackers attacks, hiding sensitive information that would be used to exploit your site, detecting and fixin …
Cloud Maestro – WAF Security Suite for Cloudflare
waf-security-suite-for-cloudflare
Bulk deploy powerful WAF security rules to multiple Cloudflare domains with one click. Protect your sites from bots, malicious traffic, and threats.
WEDOS | Protection & Cache Performance Developer Profile
2 plugins · 2K total installs
How We Detect WEDOS | Protection & Cache Performance
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wgpwpp/admin/css/fontawesome-free-6.5.2-web/css/fontawesome.min.css/wp-content/plugins/wgpwpp/admin/css/font-awesome-4.7.0/css/font-awesome.min.css/wp-content/plugins/wgpwpp/admin/css/fontawesome-free-6.5.2-web/css/solid.min.css/wp-content/plugins/wgpwpp/admin/css/wgpwpp-admin.css/wp-content/plugins/wgpwpp/admin/partials/wp-wgp/dist/mini.css/wp-content/plugins/wgpwpp/admin/css/wgpwpp-service.css/wp-content/plugins/wgpwpp/admin/js/wgpwpp-admin.js/wp-content/plugins/wgpwpp/admin/js/wgpwpp-admin.jswgpwpp/admin/css/fontawesome-free-6.5.2-web/css/fontawesome.min.css?ver=wgpwpp/admin/css/font-awesome-4.7.0/css/font-awesome.min.css?ver=wgpwpp/admin/css/fontawesome-free-6.5.2-web/css/solid.min.css?ver=wgpwpp/admin/css/wgpwpp-admin.css?ver=wgpwpp/admin/partials/wp-wgp/dist/mini.css?ver=wgpwpp/admin/css/wgpwpp-service.css?ver=wgpwpp/admin/js/wgpwpp-admin.js?ver=HTML / DOM Fingerprints
wgpwpp-admin-menuwgpwpp-layout-flexwgpwpp-contentwgpwpp-footerwgpwpp-footer-contentwgpwpp-content-centerwgpwpp-headerwgpwpp-header-content+16 moredata-wgpwpp-iddata-wgpwpp-actionwgpwpp_ajax_object/wp-json/wgpwpp/v1/report/wp-json/wgpwpp/v1/cache