YD *FAST* Page update Security & Risk Analysis

wordpress.org/plugins/yd-fast-page-update

Speed-up page updating, when using custom permalinks and a lot of pages.

10 active installs v0.2.0 PHP + WP 2.9.1+ Updated May 20, 2010
adminadministrationblogscmswordpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YD *FAST* Page update Safe to Use in 2026?

Generally Safe

Score 85/100

YD *FAST* Page update has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "yd-fast-page-update" plugin, version 0.2.0, exhibits a strong security posture in its static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. Furthermore, the code adheres to excellent practices by not utilizing dangerous functions, all SQL queries are prepared, and all identified outputs are properly escaped. The absence of file operations and external HTTP requests further contributes to its secure design. Taint analysis, while limited to two flows, found no critical or high severity issues, and the plugin has a clean vulnerability history with zero recorded CVEs.

Despite these positive indicators, the taint analysis did reveal two flows with unsanitized paths. While these did not reach critical or high severity in this analysis, they represent a potential area for concern and warrant closer inspection to ensure no vulnerabilities can be exploited. The absence of nonce checks and capability checks on all entry points (though there are none identified) could be a concern if new entry points are added without these security measures. Overall, the plugin demonstrates a commitment to secure coding practices, but the presence of unsanitized paths suggests vigilance is still necessary.

Key Concerns

  • Flows with unsanitized paths found
Vulnerabilities
None known

YD *FAST* Page update Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

YD *FAST* Page update Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
yd_save_fpu_data (yd-fast-page-update.php:115)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YD *FAST* Page update Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuyd-fast-page-update.php:43
actionsave_postyd-fast-page-update.php:47
actionpre_post_updateyd-fast-page-update.php:48
actionadmin_menuyd-fast-page-update.php:100
actionsave_postyd-fast-page-update.php:120
Maintenance & Trust

YD *FAST* Page update Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedMay 20, 2010
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

YD *FAST* Page update Developer Profile

Yann at WP&Co

14 plugins · 180 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YD *FAST* Page update

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
yd-fast-page-update/style.css?ver=yd-fast-page-update/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- YD: Avoid flushing rules if previous post name and parent are the same --><!-- TODO: Also avoid flushing as long as we're draft/unpublished --><!-- TODO: maybe invent some selective flush method -->
Data Attributes
id="yd_fpu_status" name="yd_fpu_status"id="yd_fpu_box"
FAQ

Frequently Asked Questions about YD *FAST* Page update