Advanced Speed Increaser Security & Risk Analysis

wordpress.org/plugins/advanced-speed-increaser

Advanced Speed Increaser is a light weighted plugin to speed up wordpress website by using GZIP compression and setting header expiration for images.

300 active installs v2.2.1 PHP + WP 3.5+ Updated Apr 3, 2020
expires-headerexpiry-headerfar-future-expirationgzipjavascript
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 1, 2025
Safety Verdict

Is Advanced Speed Increaser Safe to Use in 2026?

Use With Caution

Score 64/100

Advanced Speed Increaser has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 1, 2025Updated 6yr ago
Risk Assessment

The "advanced-speed-increaser" v2.2.1 plugin exhibits a mixed security posture. While it demonstrates strong practices in avoiding direct SQL injection by using prepared statements for all queries and has no external HTTP requests or file operations, several critical areas raise significant concern. The complete lack of output escaping across all identified output points is a severe weakness, potentially leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis revealed a high-severity flow with an unsanitized path, which, even without a critical rating, indicates a potential vulnerability.

The plugin's vulnerability history is particularly worrying, with one known, unpatched medium-severity CVE. The fact that this vulnerability is recent and remains unpatched suggests a lack of timely security maintenance and a potential pattern of introducing or not fully remediating security flaws. While the plugin has a small attack surface with no direct entry points, the identified code weaknesses and the unpatched vulnerability create a significant risk profile. The lack of nonce and capability checks on any potential implicit entry points, combined with the unescaped output, creates a dangerous environment where an attacker could leverage these weaknesses to compromise user sessions or inject malicious code.

In conclusion, while the plugin adheres to good practices in SQL query handling and external communication, the critical deficiency in output escaping, the high-severity taint flow, and the presence of an unpatched vulnerability collectively point to a plugin that is not secure and poses a considerable risk to WordPress sites. Immediate attention is required to address these vulnerabilities.

Key Concerns

  • Unpatched CVE
  • High severity taint flow
  • All outputs unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
1 published

Advanced Speed Increaser Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31753medium · 4.3Cross-Site Request Forgery (CSRF)

Advanced Speed Increaser <= 2.2.1 - Cross-Site Request Forgery

Apr 1, 2025Unpatched
Version History

Advanced Speed Increaser Release Timeline

v2.1.01 CVE
v2.0.01 CVE
v1.1.01 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Advanced Speed Increaser Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared9 total queries

Output Escaping

0% escaped8 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<admin-setting> (admin-setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Advanced Speed Increaser Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuadvanced-speed-increaser.php:22
actionget_headeradvanced-speed-increaser.php:208
actionadmin_headadvanced-speed-increaser.php:215
actionadmin_noticesadvanced-speed-increaser.php:227
Maintenance & Trust

Advanced Speed Increaser Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 3, 2020
PHP min version
Downloads19K

Community Trust

Rating76/100
Number of ratings10
Active installs300
Developer Profile

Advanced Speed Increaser Developer Profile

Animesh Kumar

2 plugins · 600 total installs

77
trust score
Avg Security Score
75/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Speed Increaser

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-speed-increaser/assets/css/admin.css
Version Parameters
advanced-speed-increaser/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
tw_asi_admin_message
HTML Comments
Minify HTML By, Advanced Speed Increaser 2.2.1 - https://wordpress.org/plugins/advanced-speed-increaser/ Total size saved: % | Size before compression: bytes | Size after compression: bytes. ***
FAQ

Frequently Asked Questions about Advanced Speed Increaser