
Super Page Cache Security & Risk Analysis
wordpress.org/plugins/wp-cloudflare-page-cacheBoost PageSpeed, SEO, and Core Web Vitals with full page caching, JS/CSS optimization, media optimization, and Cloudflare CDN.
Is Super Page Cache Safe to Use in 2026?
Generally Safe
Score 96/100Super Page Cache has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-cloudflare-page-cache plugin, version 5.2.3, presents a mixed security posture. On the positive side, the static analysis shows no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication, indicating a generally secure entry point strategy. The plugin also demonstrates good practices in output escaping and utilizes capability checks extensively.
However, there are notable areas of concern. The presence of two dangerous functions, specifically `unserialize`, without any taint analysis results is a significant red flag. This function is notoriously prone to object injection vulnerabilities if not handled with extreme care and proper sanitization. Furthermore, a substantial percentage of SQL queries (69%) are not using prepared statements, increasing the risk of SQL injection. The absence of any nonce checks on any entry points is a critical oversight, leaving the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks.
The vulnerability history reveals a pattern of Cross-Site Scripting (XSS) and CSRF, with a recent high-severity vulnerability found. While there are no currently unpatched CVEs, the recurring nature of these vulnerability types suggests a potential for similar issues to re-emerge if not proactively addressed. The plugin's strengths lie in its controlled attack surface and output escaping, but the identified risks from `unserialize`, raw SQL queries, and the complete lack of nonce checks warrant significant attention.
Key Concerns
- Dangerous function 'unserialize' present
- SQL queries not using prepared statements (69%)
- No nonce checks implemented
- High severity vulnerability in history
- Medium severity vulnerability in history
Super Page Cache Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Super Page Cache <= 5.2.2 - Unauthenticated Stored Cross-Site Scripting via Activity Log
Super Page Cache for Cloudflare <= 4.7.5 - Cross-Site Request Forgery
Super Page Cache Release Timeline
Super Page Cache Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Super Page Cache Attack Surface
WordPress Hooks 46
Maintenance & Trust
Super Page Cache Maintenance & Trust
Maintenance Signals
Community Trust
Super Page Cache Alternatives
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
WP Meteor Website Speed Optimization Addon
wp-meteor
2x-5x improvement in your Page Speed score. A completely new way of optimizing your page speed.
RabbitLoader – AI Speed Optimization, Caching & CDN for WordPress & WooCommerce
rabbit-loader
All-in-one AI speed optimization plugin for WordPress & WooCommerce websites. Get faster loading pages and near-perfect PageSpeed scores — in just …
App for Cloudflare®
app-for-cf
All things Cloudflare (caching, flexible SSL, Turnstile, settings, rules, analytics, media in R2, image transforms [AVIF, WebP], secure admin area).
Super Page Cache Developer Profile
2 plugins · 260K total installs
How We Detect Super Page Cache
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-cloudflare-page-cache/assets/css/assets-manager.css/wp-content/plugins/wp-cloudflare-page-cache/assets/js/assets-manager.js/wp-content/plugins/wp-cloudflare-page-cache/assets/js/assets-manager.jsHTML / DOM Fingerprints
spc-assets-managerdata-spc-asset-managerSPCAssetManager/wp-json/spc/v1