wuk.ch DNS-Prefetch / Prerender Security & Risk Analysis

wordpress.org/plugins/wukch-dns-prefetch-prerender

Adds dns-prefetch and prerender functionalities on WordPress for better PageSpeed.

10 active installs v1.1.4 PHP + WP 4.0+ Updated Sep 9, 2017
dns-prefetchprerenderspeed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is wuk.ch DNS-Prefetch / Prerender Safe to Use in 2026?

Generally Safe

Score 85/100

wuk.ch DNS-Prefetch / Prerender has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "wukch-dns-prefetch-prerender" plugin v1.1.4 exhibits a concerning security posture primarily due to its lack of proper output escaping and the presence of unsanitized flows, despite a seemingly small attack surface. While the static analysis reveals no directly dangerous functions, SQL injection risks are present given that 27% of its SQL queries are not using prepared statements. The absence of capability checks and nonce checks on entry points, although currently zero in number, indicates a potential for privilege escalation or cross-site request forgery if any entry points were to be introduced in future versions without proper security measures. The plugin's vulnerability history is clean, which is a positive sign, suggesting it has not been a target or has been developed with some degree of security awareness. However, the fundamental issues with output escaping and taint analysis cannot be overlooked. The fact that 100% of outputs are unescaped and there are unsanitized flows with the potential for issues, even if not classified as critical or high in this analysis, represents a significant risk of cross-site scripting (XSS) vulnerabilities. This could allow attackers to inject malicious scripts into a user's browser, leading to session hijacking or other malicious activities. The plugin's strengths lie in its limited attack surface and lack of known vulnerabilities. However, the unescaped output and unsanitized data flows are significant weaknesses that require immediate attention to prevent potential security breaches.

Key Concerns

  • Unescaped output (100%)
  • Unsanitized paths in taint analysis (2 flows)
  • SQL queries without prepared statements (27%)
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

wuk.ch DNS-Prefetch / Prerender Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

wuk.ch DNS-Prefetch / Prerender Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
8 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

73% prepared11 total queries

Output Escaping

0% escaped1 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
fetchrender (wuk-prerender.php:42)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

wuk.ch DNS-Prefetch / Prerender Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_print_scriptswuk-prerender.php:30
actioninitwuk-prerender.php:145
Maintenance & Trust

wuk.ch DNS-Prefetch / Prerender Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedSep 9, 2017
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

wuk.ch DNS-Prefetch / Prerender Developer Profile

Stefan M.

2 plugins · 110 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect wuk.ch DNS-Prefetch / Prerender

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- wuk.ch DNS-Prefetch / Prerender START --><!-- wuk.ch DNS-Prefetch / Prerender END -->
FAQ

Frequently Asked Questions about wuk.ch DNS-Prefetch / Prerender