Amigo Performance Security & Risk Analysis

wordpress.org/plugins/amigo-performance

Amigo Performance delivers professional-grade optimization controls for WordPress sites that need consistent Core Web Vitals improvements without addi …

10 active installs v3.3 PHP 8.0+ WP 6.0+ Updated Mar 1, 2026
cachinglazy-loadingoptimizationpage-speedperformance
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amigo Performance Safe to Use in 2026?

Generally Safe

Score 100/100

Amigo Performance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The amigo-performance plugin v3.3 exhibits a generally strong security posture, adhering to several best practices. The plugin has a minimal attack surface with only three AJAX handlers, and notably, none of them appear to lack authentication checks based on the provided data. Furthermore, the plugin demonstrates a high degree of diligence in output escaping (98%) and a significant majority of its SQL queries use prepared statements (78%), which are crucial for preventing common web vulnerabilities. The absence of known CVEs and a clean vulnerability history further contribute to its positive security assessment. However, the taint analysis reveals some areas of concern. While no critical or high severity issues were flagged in the taint flows, the presence of 3 flows with unsanitized paths and 2 critical severity taint flows are noteworthy. These unsanitized paths could potentially lead to path traversal vulnerabilities if not handled with extreme care, especially when combined with file operations. The plugin's strength lies in its proactive security measures like capability checks and nonce checks, and its low number of entry points. The primary weakness lies in the identified taint flows, which require careful review and potential remediation to eliminate any residual risks.

Key Concerns

  • Flows with unsanitized paths detected
  • Critical severity taint flows detected
  • SQL queries without prepared statements detected
Vulnerabilities
None known

Amigo Performance Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Amigo Performance Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
21 prepared
Unescaped Output
2
104 escaped
Nonce Checks
6
Capability Checks
9
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

78% prepared27 total queries

Output Escaping

98% escaped106 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
process_setting (includes\class-amigo-performance-settings.php:107)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Amigo Performance Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_amigoperf_toggle_assetincludes\class-amigo-performance-asset-manager.php:36
authwp_ajax_amigoperf_asset_admin_toggleincludes\class-amigo-performance-asset-manager.php:37
authwp_ajax_amigoperf_asset_admin_deleteincludes\class-amigo-performance-asset-manager.php:38
WordPress Hooks 31
actioninitamigo-performance.php:141
actioninitamigo-performance.php:145
actioninitamigo-performance.php:148
actioninitamigo-performance.php:151
actionadmin_menuincludes\class-amigo-performance-admin.php:25
actionadmin_enqueue_scriptsincludes\class-amigo-performance-admin.php:26
actionwp_enqueue_scriptsincludes\class-amigo-performance-admin.php:27
actionwp_headincludes\class-amigo-performance-admin.php:28
actionadmin_headincludes\class-amigo-performance-admin.php:29
actionadmin_bar_menuincludes\class-amigo-performance-admin.php:32
actionwp_print_stylesincludes\class-amigo-performance-asset-manager.php:41
actionwp_print_scriptsincludes\class-amigo-performance-asset-manager.php:42
actionadmin_print_stylesincludes\class-amigo-performance-asset-manager.php:43
actionadmin_print_scriptsincludes\class-amigo-performance-asset-manager.php:44
actionwp_enqueue_scriptsincludes\class-amigo-performance-asset-manager.php:46
actionadmin_enqueue_scriptsincludes\class-amigo-performance-asset-manager.php:47
filterstyle_loader_srcincludes\class-amigo-performance-core.php:37
filterscript_loader_srcincludes\class-amigo-performance-core.php:38
filterscript_loader_tagincludes\class-amigo-performance-core.php:61
filterthe_contentincludes\class-amigo-performance-lazyload.php:27
actionwp_enqueue_scriptsincludes\class-amigo-performance-lazyload.php:35
actiontemplate_redirectincludes\class-amigo-performance-lazyload.php:97
actionget_headerincludes\class-amigo-performance-lazyload.php:98
actionwp_footerincludes\class-amigo-performance-lazyload.php:99
actionwp_enqueue_scriptsincludes\class-amigo-performance-lazyload.php:108
actionwp_enqueue_scriptsincludes\class-amigo-performance-minify.php:30
actionwp_print_stylesincludes\class-amigo-performance-minify.php:31
actionwp_print_scriptsincludes\class-amigo-performance-minify.php:32
filterstyle_loader_srcincludes\class-amigo-performance-minify.php:40
filterscript_loader_srcincludes\class-amigo-performance-minify.php:44
actionadmin_initincludes\class-amigo-performance-settings.php:25
Maintenance & Trust

Amigo Performance Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 1, 2026
PHP min version8.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Amigo Performance Developer Profile

Amigo Dheena

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amigo Performance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amigo-performance/assets/css/amigo-performance-admin.css/wp-content/plugins/amigo-performance/assets/js/amigo-performance-admin.js
Script Paths
/wp-content/plugins/amigo-performance/assets/js/amigo-performance-admin.js
Version Parameters
amigo-performance/assets/css/amigo-performance-admin.css?ver=amigo-performance/assets/js/amigo-performance-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
amigo-performance-settings-wrapamigo-performance-settings-section
HTML Comments
<!-- Amigo Performance: Initiating Query Strings Removal --><!-- Amigo Performance: Initiating Emoji Removal --><!-- Amigo Performance: Initiating Defer JavaScript --><!-- Amigo Performance: Initiating Lazy Load for Images -->+3 more
Data Attributes
data-amigoperf-lazyload-imagedata-amigoperf-lazyload-iframe
JS Globals
window.amigoperf_asset_manager
FAQ

Frequently Asked Questions about Amigo Performance