
wuk.ch DNS-Prefetch / Prerender Security & Risk Analysis
wordpress.org/plugins/wukch-dns-prefetch-prerenderAdds dns-prefetch and prerender functionalities on WordPress for better PageSpeed.
Is wuk.ch DNS-Prefetch / Prerender Safe to Use in 2026?
Generally Safe
Score 85/100wuk.ch DNS-Prefetch / Prerender has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wukch-dns-prefetch-prerender" plugin v1.1.4 exhibits a concerning security posture primarily due to its lack of proper output escaping and the presence of unsanitized flows, despite a seemingly small attack surface. While the static analysis reveals no directly dangerous functions, SQL injection risks are present given that 27% of its SQL queries are not using prepared statements. The absence of capability checks and nonce checks on entry points, although currently zero in number, indicates a potential for privilege escalation or cross-site request forgery if any entry points were to be introduced in future versions without proper security measures. The plugin's vulnerability history is clean, which is a positive sign, suggesting it has not been a target or has been developed with some degree of security awareness. However, the fundamental issues with output escaping and taint analysis cannot be overlooked. The fact that 100% of outputs are unescaped and there are unsanitized flows with the potential for issues, even if not classified as critical or high in this analysis, represents a significant risk of cross-site scripting (XSS) vulnerabilities. This could allow attackers to inject malicious scripts into a user's browser, leading to session hijacking or other malicious activities. The plugin's strengths lie in its limited attack surface and lack of known vulnerabilities. However, the unescaped output and unsanitized data flows are significant weaknesses that require immediate attention to prevent potential security breaches.
Key Concerns
- Unescaped output (100%)
- Unsanitized paths in taint analysis (2 flows)
- SQL queries without prepared statements (27%)
- No capability checks
- No nonce checks
wuk.ch DNS-Prefetch / Prerender Security Vulnerabilities
wuk.ch DNS-Prefetch / Prerender Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
wuk.ch DNS-Prefetch / Prerender Attack Surface
WordPress Hooks 2
Maintenance & Trust
wuk.ch DNS-Prefetch / Prerender Maintenance & Trust
Maintenance Signals
Community Trust
wuk.ch DNS-Prefetch / Prerender Alternatives
Pre* Party Resource Hints
pre-party-browser-hints
Take advantage of browser resource hints and plug-and-play features to improve page load time.
Simple DNS Prefetch
simple-dns-prefetch
Adds (or removes) DNS prefetching meta tags to your site and speeds up your page load speed.
Prerender and Prefetch
prerender-and-prefetch
Puts Prerender and Prefetch tag in the page. Allowing compatible navigators to do a pre-load of the page you figure the visitor is going to go.
Behavior Flow
behavior-flow
Better site performance and increased conversion rates using visitors' behavior flow
EVE Dynamic Prerender
eve-dynamic-prerender
An easy and powerful plugin to implement a real dynamic Prerender Meta Tag inside the head section of the HTML document. This version use AJAX so it w …
wuk.ch DNS-Prefetch / Prerender Developer Profile
2 plugins · 110 total installs
How We Detect wuk.ch DNS-Prefetch / Prerender
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- wuk.ch DNS-Prefetch / Prerender START --><!-- wuk.ch DNS-Prefetch / Prerender END -->