WPIntell

Source evidence

Accessible directories – Can become a security risk?

SpeedyCache – Cache, Optimization, Performance · review · 2025-04-07T22:54:00+00:00

praisesentiment
highseverity
0.73relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 34 rows with source links

14.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

review · 5 stars
Dascent unresolved
Is it possible to protect somehow the direct access of the directories from which the cache is served? I was checking the logs and it seams like a tap was open and a lot of IPs targeting source files wp-content/cache/speedycache/webite.com/assets/---all files--- My .htaccess prevents direct browsing but not there.. if I am to add a rule in htaccess to prevent direct access to javascript/css and other files the plugin stores the site will not function well even if I do the expectation IP of my website still all in the open… and I feel naked leaving all those files in easy access. A bit of security layer would be good. Yes, there’s the index.html file in the directory… prevents not displaying the index of files yet as I’ve said…. there’s a leak and IPs are targeting constantly . Also, maybe obfuscate the name of the files… I don’t know. Maybe it is nothing and it is not a security risk but better safe than sorry I say. Hello, Thank you for reaching out to us with your concerns. The issue you are stating here, the files are meant to be accessed directly as these are just static files which even when if caching is not enabled, are served directly. SpeedyCache just minifies these files and stores them in this folder. And then injects the URL of these files by replacing the URL of the original file. And I request you that you create a support thread at https://wordpress.org/support/plugin/speedycache/#new-topic-0 as that would be an appropriate place to discuss this further. Regards, Vardan

Comments

1 shown
Vardan 2025-04-08T09:52:00+00:00

Hello, Thank you for reaching out to us with your concerns. The issue you are stating here, the files are meant to be accessed directly as these are just static files which even when if caching is not enabled, are served directly. SpeedyCache just minifies these files and stores them in this folder. And then injects the URL of these files by replacing the URL of the original file. And I request you that you create a support thread at https://wordpress.org/support/plugin/speedycache/#new-topic-0 as that would be an appropriate place to discuss this further. Regards, Vardan