
BoltAudit – Plugin & Performance Analyzer Security & Risk Analysis
wordpress.org/plugins/boltauditBoltAudit helps you identify bloated, unused, abandoned, and performance-heavy plugins—plus database bloat, autoloaded options, and runtime impact.
Is BoltAudit – Plugin & Performance Analyzer Safe to Use in 2026?
Generally Safe
Score 100/100BoltAudit – Plugin & Performance Analyzer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The boltaudit v0.0.8 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of identified attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, especially without authorization checks, indicates a design that minimizes potential entry vectors for attackers. Furthermore, the presence of capability checks and a relatively high percentage of SQL queries using prepared statements are positive indicators of good coding practices.
However, there are a few areas that warrant attention. The absence of nonce checks on any potential entry points (though none were identified) is a potential weakness if new entry points are added in the future. The plugin also makes an external HTTP request, which, without further context, could be a vector for certain types of attacks if not handled securely. The SQL query usage, while leaning towards prepared statements, still has a significant portion not utilizing them, which could be a source of SQL injection vulnerabilities if these specific queries handle user-supplied data.
The plugin's vulnerability history is remarkably clean, with zero known CVEs. This suggests either a very robust development and testing process, or that the plugin has not been a target of extensive security research. While this is excellent, it should not lead to complacency. The strengths lie in its minimal attack surface and the use of prepared statements. The weaknesses, though minor at this stage, are the lack of nonce checks and the remaining raw SQL queries, along with the external HTTP request.
Key Concerns
- Raw SQL queries present
- Missing nonce checks on entry points
- External HTTP request made
BoltAudit – Plugin & Performance Analyzer Security Vulnerabilities
BoltAudit – Plugin & Performance Analyzer Release Timeline
BoltAudit – Plugin & Performance Analyzer Code Analysis
SQL Query Safety
Output Escaping
BoltAudit – Plugin & Performance Analyzer Attack Surface
WordPress Hooks 2
Maintenance & Trust
BoltAudit – Plugin & Performance Analyzer Maintenance & Trust
Maintenance Signals
Community Trust
BoltAudit – Plugin & Performance Analyzer Alternatives
Performance Lab
performance-lab
Performance plugin from the WordPress Performance Team, which is a collection of standalone performance features.
DiveWP – Boost Site Performance with Clear, Actionable Steps
divewp-boost-site-performance
Learn WP Best Practices Through Your Own Site! Get clear insights about Performance, Security, and Best Practices – explained in plain English.
AI Database Optimizer
ai-database-optimizer
AI-powered database optimization with automatic backup protection for peak WordPress performance.
Fand Transient and Action Cleaner
fand-transient-action-cleaner
Clean up your database by removing expired transients and cumbersome Action Scheduler logs. Optimize your performance with one click.
Optimal State – Complete Optimization & Performance Suite
optistate
All-in-one WordPress performance suite: database optimization, automated backups, page caching, and cleanup. Replace 4+ plugins and save money.
BoltAudit – Plugin & Performance Analyzer Developer Profile
2 plugins · 130 total installs
How We Detect BoltAudit – Plugin & Performance Analyzer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boltaudit/app/Views/assets/css/vendor/material-icons.css/wp-content/plugins/boltaudit/app/Views/assets/css/app.css/wp-content/plugins/boltaudit/app/Views/assets/js/vendor/apexcharts.js/wp-content/plugins/boltaudit/app/Views/assets/js/vendor/vue.min.js/wp-content/plugins/boltaudit/app/Views/assets/js/vendor/axios.min.js/wp-content/plugins/boltaudit/app/Views/assets/js/app.js/wp-content/plugins/boltaudit/app/Views/assets/js/vendor/apexcharts.js/wp-content/plugins/boltaudit/app/Views/assets/js/vendor/vue.min.js/wp-content/plugins/boltaudit/app/Views/assets/js/vendor/axios.min.js/wp-content/plugins/boltaudit/app/Views/assets/js/app.jsboltaudit/app/Views/assets/css/vendor/material-icons.css?ver=boltaudit/app/Views/assets/css/app.css?ver=boltaudit/app/Views/assets/js/vendor/apexcharts.js?ver=boltaudit/app/Views/assets/js/vendor/vue.min.js?ver=boltaudit/app/Views/assets/js/vendor/axios.min.js?ver=boltaudit/app/Views/assets/js/app.js?ver=HTML / DOM Fingerprints
boltaudit-appboltaudit-dashboardboltaudit-cardboltaudit-card-headerboltaudit-card-bodyboltaudit-chart-wrapperboltaudit-table-wrapperboltaudit-table+5 moredata-controllerdata-actiondata-targetwindow.BoltAuditAppwindow.BoltAuditData