
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization Security & Risk Analysis
wordpress.org/plugins/add-expires-headersAEH Speed Optimization boosts site speed with caching, minification, lazy loading, and image optimization to improve performance and SEO.
Is AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization Safe to Use in 2026?
Mostly Safe
Score 76/100AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "add-expires-headers" v3.1.0 plugin presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and implementing a reasonable number of nonce and capability checks, significant concerns remain. The presence of two AJAX handlers without proper authentication checks creates a notable attack surface, as these endpoints could potentially be exploited by unauthenticated users. Taint analysis shows no critical or high severity flows, which is positive, and the plugin avoids dangerous functions and raw SQL.
Key Concerns
- Unpatched CVE found
- AJAX handlers without auth checks
- Moderate percentage of unescaped output
- Bundled outdated library (Freemius v1.0)
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Add Expires Headers & Optimized Minify <= 3.1.0 - Missing Authorization
Add Expires Headers & Optimized Minify <= 2.7 - Cross-Site Request Forgery via [placeholder]
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization Attack Surface
AJAX Handlers 4
WordPress Hooks 25
Maintenance & Trust
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization Maintenance & Trust
Maintenance Signals
Community Trust
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization Alternatives
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
Autoptimize
autoptimize
Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.
Aruba HiSpeed Cache
aruba-hispeed-cache
Aruba HiSpeed Cache interfaces directly with an Aruba hosting platform's HiSpeed Cache service and automates its management.
10Web Booster – Website speed optimization, Cache & Page Speed optimizer
tenweb-speed-optimizer
Speed up your site with 10Web Booster. Pass Core Web Vitals by optimizing HTML / CSS / JavaScript, Image Optimization, Lazy Loading, Cache, Google Fon …
Seraphinite Accelerator
seraphinite-accelerator
Turns on site high speed to be attractive for people and search engines.
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization Developer Profile
4 plugins · 8K total installs
How We Detect AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-expires-headers/assests/css/aeh-frontend.css/wp-content/plugins/add-expires-headers/assets/css/aeh-admin.css/wp-content/plugins/add-expires-headers/assets/css/materialize.min.css/wp-content/plugins/add-expires-headers/assets/js/materialize.min.js/wp-content/plugins/add-expires-headers/assets/js/admin.js/wp-content/plugins/add-expires-headers/assets/js/admin.jsadd-expires-headers/assets/css/aeh-admin.css?ver=add-expires-headers/assets/css/materialize.min.css?ver=add-expires-headers/assets/js/materialize.min.js?ver=add-expires-headers/assets/js/admin.js?ver=HTML / DOM Fingerprints
aeh-admin-containeraeh-settings-titleaeh-input-wrapperaeh-section-header<!-- AEH Admin Section -->data-aeh-tabAEH_Admin