Admin Speedo Security & Risk Analysis

wordpress.org/plugins/admin-speedo

AdminSpeedo is a simple method of boosting your WordPress admin dashboard and freeing your site code from unnecessary and not needed items.

10 active installs v2.4.1 PHP 5.6+ WP 3.9+ Updated Dec 11, 2022
cachingcore-web-vitalsoptimizepagespeedperformance
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Admin Speedo Safe to Use in 2026?

Generally Safe

Score 85/100

Admin Speedo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'admin-speedo' v2.4.1 demonstrates a generally strong security posture based on the static analysis. The absence of direct attack surface points like AJAX handlers, REST API routes, and shortcodes is a positive indicator. Furthermore, the adherence to prepared statements for all SQL queries and a high percentage of properly escaped output suggests good coding practices regarding common web vulnerabilities. The lack of file operations and external HTTP requests also reduces potential attack vectors.

Despite these strengths, two flows with unsanitized paths were identified during the taint analysis. While classified as not critical or high severity, these represent a potential concern as they indicate areas where user-supplied data might not be sufficiently cleaned before being used, potentially leading to unexpected behavior or information disclosure if exploited. The plugin also bundles the Freemius library v1.0, which could be an outdated component carrying its own unpatched vulnerabilities, although no specific issues were reported for this version.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the static analysis findings, suggests a low risk of known, exploitable vulnerabilities. However, the presence of unsanitized path flows and the bundled library warrant a degree of caution, as these are internal code weaknesses rather than documented external threats.

Key Concerns

  • Flows with unsanitized paths
  • Bundled outdated Freemius library
Vulnerabilities
None known

Admin Speedo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Admin Speedo Release Timeline

v2.4.1Current
v2.4.0
v2.3.0
v2.2.2
v2.2.1
v2.2.0
v2.1.1
v2.1.0
v2.0.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Admin Speedo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
1
86 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared4 total queries

Output Escaping

99% escaped87 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
admin_speedo_settings (admin/settings.php:7)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Admin Speedo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 30
actionadmin_menuadmin/admin-menu.php:9
actionactivated_pluginadminspeedo.php:20
actionwp_enqueue_scriptsinc/functions.php:15
filterposts_fieldsinc/functions.php:22
actionwp_dashboard_setupinc/functions.php:63
filterheartbeat_settingsinc/functions.php:82
actioninitinc/functions.php:89
filterjetpack_just_in_time_msgsinc/functions.php:95
filterjetpack_show_promotionsinc/functions.php:96
filterhttp_request_host_is_externalinc/functions.php:103
actionin_admin_headerinc/functions.php:120
filterwoocommerce_marketing_menu_itemsinc/functions.php:132
actionwp_dashboard_setupinc/functions.php:138
actionwp_dashboard_setupinc/functions.php:149
filterwoocommerce_allow_marketplace_suggestionsinc/functions.php:161
actionwidgets_initinc/functions.php:167
actionwp_print_scriptsinc/functions.php:191
actionwp_dashboard_setupinc/functions.php:220
filtercron_schedulesinc/functions.php:238
actionadminsp_cron_hookinc/functions.php:252
filterscript_loader_taginc/functions.php:293
filtertiny_mce_pluginsinc/functions.php:306
filterscript_loader_srcinc/functions.php:316
filterstyle_loader_srcinc/functions.php:317
filterxmlrpc_enabledinc/functions.php:322
filteradmin_footer_textinc/functions.php:327
actioninitinc/functions.php:332
actionwpinc/functions.php:358
actionadminsp_wp_optimize_databaseinc/functions.php:361
filterwp_loadedinc/functions.php:384

Scheduled Events 2

adminsp_cron_hook
adminsp_wp_optimize_database
Maintenance & Trust

Admin Speedo Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 11, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Admin Speedo Developer Profile

Rajin Sharwar

9 plugins · 350 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Admin Speedo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-speedo/css/admin-speedo.css/wp-content/plugins/admin-speedo/js/admin-speedo.js
Script Paths
/wp-content/plugins/admin-speedo/js/admin-speedo.js
Version Parameters
admin-speedo/css/admin-speedo.css?ver=admin-speedo/js/admin-speedo.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Admin Speedo