
Subresource Integrity (SRI) Manager Security & Risk Analysis
wordpress.org/plugins/wp-sriAdds Subresource Integrity (SRI) attributes to your page's elements for better protection against JavaScript DDoS attacks.
Is Subresource Integrity (SRI) Manager Safe to Use in 2026?
Use With Caution
Score 63/100Subresource Integrity (SRI) Manager has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-sri plugin version 0.4.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing proper output escaping on the majority of its outputs. It also incorporates nonce and capability checks, which are fundamental security measures. However, a significant concern is the presence of an unprotected AJAX handler, which represents a direct entry point into the plugin's functionality that can be accessed without authentication. While the taint analysis shows no identified vulnerabilities, the single external HTTP request warrants careful consideration, as it could potentially be exploited if not handled securely.
The plugin's vulnerability history is a major red flag. With one known CVE, which is currently unpatched and categorized as medium severity, this indicates a recurring issue of missing authorization. The fact that the last vulnerability was dated in the near future (2025-09-22) and is related to missing authorization suggests a potential for ongoing security weaknesses in how the plugin handles user access to its features. This, combined with the unprotected AJAX handler, points to a pattern where authorization checks are being overlooked.
In conclusion, while wp-sri version 0.4.0 has some strengths in its secure coding practices regarding SQL and output handling, the presence of an unprotected AJAX endpoint and a documented history of missing authorization vulnerabilities, including a currently unpatched medium severity issue, present significant risks. The unprotected AJAX handler and the unpatched CVE are the most critical areas requiring immediate attention.
Key Concerns
- Unprotected AJAX handler
- Currently unpatched CVE (medium severity)
- Vulnerability history: Missing Authorization pattern
Subresource Integrity (SRI) Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Subresource Integrity (SRI) Manager <= 0.4.0 - Missing Authorization
Subresource Integrity (SRI) Manager Code Analysis
Output Escaping
Subresource Integrity (SRI) Manager Attack Surface
AJAX Handlers 1
WordPress Hooks 14
Maintenance & Trust
Subresource Integrity (SRI) Manager Maintenance & Trust
Maintenance Signals
Community Trust
Subresource Integrity (SRI) Manager Alternatives
Auto SRI
auto-sri
Automatically adds Subresource Integrity (SRI) to external scripts/styles and safely excludes Google reCAPTCHA and Google Fonts.
VerifiedVisitors
verifiedvisitors
VerifiedVisitors is a powerful AI/ML bot mitigation plugin to support the Wordpress community. It’s an easy to configure platform to defeat bad bots.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
Subresource Integrity (SRI) Manager Developer Profile
13 plugins · 2K total installs
How We Detect Subresource Integrity (SRI) Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-sri/js/wp-sri.js/wp-content/plugins/wp-sri/css/wp-sri.css/wp-content/plugins/wp-sri/js/wp-sri.jswp-sri/js/wp-sri.js?ver=wp-sri/css/wp-sri.css?ver=HTML / DOM Fingerprints
integritycrossoriginoptions