Asset Queue Manager Security & Risk Analysis

wordpress.org/plugins/asset-queue-manager

A tool for experienced frontend performance engineers to take control over the scripts and styles enqueued on their site.

200 active installs v1.0.3 PHP + WP 4.0+ Updated Mar 10, 2016
debugdeveloperdevelopmenttool
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Asset Queue Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Asset Queue Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The asset-queue-manager plugin v1.0.3 exhibits a generally good security posture with several positive indicators. The absence of known vulnerabilities in its history is a significant strength, suggesting a commitment to security or a lack of prior exploitation. Furthermore, all SQL queries are prepared, and there are no file operations or external HTTP requests, all of which reduce common attack vectors. The presence of nonce checks on one of its entry points is also a positive sign.

However, the plugin has a notable weakness: one of its two AJAX handlers is not protected by any authentication or authorization checks. This creates a direct entry point for unauthenticated users to interact with plugin functionality, which could be exploited if that handler performs sensitive operations or manipulates data without proper validation. The static analysis also identified that two out of three output locations are not properly escaped, posing a risk of Cross-Site Scripting (XSS) if the data being output originates from user input or untrusted sources.

While the plugin has no recorded vulnerabilities, the lack of capability checks on AJAX handlers and the unescaped output are areas that warrant attention. The presence of an unprotected AJAX handler is the most significant immediate risk. Overall, the plugin is not critically insecure, but these identified weaknesses present opportunities for attackers to potentially exploit the application.

Key Concerns

  • Unprotected AJAX handler
  • Unescaped output detected
Vulnerabilities
None known

Asset Queue Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Asset Queue Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface
1 unprotected

Asset Queue Manager Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

noprivwp_ajax_aqm-modify-assetasset-queue-manager.php:80
authwp_ajax_aqm-modify-assetasset-queue-manager.php:81
WordPress Hooks 12
actioninitasset-queue-manager.php:77
actioninitasset-queue-manager.php:84
actionadmin_bar_initasset-queue-manager.php:88
actionwp_headasset-queue-manager.php:91
actionwp_footerasset-queue-manager.php:92
filterplugin_action_linksasset-queue-manager.php:107
actionwp_enqueue_scriptsasset-queue-manager.php:115
actionwp_headasset-queue-manager.php:118
actionwp_footerasset-queue-manager.php:121
actionadmin_bar_menuasset-queue-manager.php:124
actionwp_footerasset-queue-manager.php:127
actionplugins_loadedasset-queue-manager.php:534
Maintenance & Trust

Asset Queue Manager Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedMar 10, 2016
PHP min version
Downloads16K

Community Trust

Rating94/100
Number of ratings14
Active installs200
Developer Profile

Asset Queue Manager Developer Profile

NateWr

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Asset Queue Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/asset-queue-manager/assets/css/aqm.css/wp-content/plugins/asset-queue-manager/assets/js/aqm.js/wp-content/plugins/asset-queue-manager/assets/js/aqm.min.js
Script Paths
/wp-content/plugins/asset-queue-manager/assets/js/aqm.js/wp-content/plugins/asset-queue-manager/assets/js/aqm.min.js
Version Parameters
asset-queue-manager/assets/css/aqm.css?ver=asset-queue-manager/assets/js/aqm.js?ver=asset-queue-manager/assets/js/aqm.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
aqm-admin-bar-menuaqm-controls
Data Attributes
data-aqm-noncedata-aqm-siteurldata-aqm-ajaxurl
JS Globals
aqm
FAQ

Frequently Asked Questions about Asset Queue Manager