WP Google Core Web Vitals Fix Security & Risk Analysis

wordpress.org/plugins/cls-lcp-issues-fix

A helpful plugin to identify and guide fixes for LCP, CLS, and FID issues to boost your Core Web Vitals and pass Google's performance benchmarks.

400 active installs v1.0.8 PHP + WP 5.0+ Updated Jul 15, 2025
cls-issuecore-web-vitalsgoogle-optimizationlcp-issueweb-vitals-fix
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP Google Core Web Vitals Fix Safe to Use in 2026?

Generally Safe

Score 100/100

WP Google Core Web Vitals Fix has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "cls-lcp-issues-fix" plugin, version 1.0.8, exhibits a generally good security posture with a very limited attack surface and no publicly known vulnerabilities. The analysis reveals a single AJAX handler, but importantly, it lacks authentication checks, posing a potential risk. While the plugin has a small number of SQL queries and file operations, the low percentage of prepared statements for SQL and the significantly low rate of proper output escaping are concerning.

The taint analysis, although limited in scope, did identify one flow with unsanitized paths. This, combined with the lack of robust input validation suggested by the low output escaping rate, could lead to cross-site scripting (XSS) or other injection vulnerabilities. The plugin also performs external HTTP requests, which could be leveraged in certain attack scenarios if not handled securely.

Given the absence of historical vulnerabilities, the plugin appears to have been developed with some security considerations. However, the presence of an unprotected AJAX endpoint, raw SQL queries, and poor output sanitization are significant weaknesses that require attention. Addressing these specific concerns would greatly improve the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of prepared SQL statements
  • Poor output escaping rate
  • Flow with unsanitized paths
Vulnerabilities
None known

WP Google Core Web Vitals Fix Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Google Core Web Vitals Fix Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
2 prepared
Unescaped Output
29
2 escaped
Nonce Checks
2
Capability Checks
2
File Operations
9
External Requests
2
Bundled Libraries
0

SQL Query Safety

29% prepared7 total queries

Output Escaping

6% escaped31 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
plggcwvf_Page_Install_IonCube (wp-core-web-vitals-optimization.php:930)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Google Core Web Vitals Fix Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_plggcwvf_install_image_optimizerwp-core-web-vitals-optimization.php:462
WordPress Hooks 6
actionadmin_bar_menuwp-core-web-vitals-optimization.php:33
actionadmin_menuwp-core-web-vitals-optimization.php:43
actionadmin_menuwp-core-web-vitals-optimization.php:51
actionupgrader_process_completewp-core-web-vitals-optimization.php:67
actionadmin_initwp-core-web-vitals-optimization.php:455
actionadmin_initwp-core-web-vitals-optimization.php:546
Maintenance & Trust

WP Google Core Web Vitals Fix Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 15, 2025
PHP min version
Downloads12K

Community Trust

Rating86/100
Number of ratings6
Active installs400
Developer Profile

WP Google Core Web Vitals Fix Developer Profile

SEOBoost

1 plugin · 400 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Google Core Web Vitals Fix

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
cls-lcp-issues-fix/wp-core-web-vitals-optimization.php

HTML / DOM Fingerprints

CSS Classes
greenreduilabel
JS Globals
window.location.href
FAQ

Frequently Asked Questions about WP Google Core Web Vitals Fix