
Core Web Vitals – Real User Monitoring (RUM) Security & Risk Analysis
wordpress.org/plugins/core-web-vitals-real-user-monitoring-rumTrack Core Web Vitals (LCP, INP, CLS, FCP, TTFB) from real users with comprehensive analytics, GA4 integration, and performance insights.
Is Core Web Vitals – Real User Monitoring (RUM) Safe to Use in 2026?
Generally Safe
Score 100/100Core Web Vitals – Real User Monitoring (RUM) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin, "core-web-vitals-real-user-monitoring-rum" v1.0.2, exhibits a generally good security posture with strong adherence to best practices in several key areas. The extensive use of prepared statements for SQL queries and a high percentage of properly escaped output demonstrate a solid foundation for preventing common web vulnerabilities. The absence of dangerous functions and critical or high severity taint flows further contributes to its positive security profile. However, there are notable areas of concern that elevate its risk. The presence of multiple unprotected AJAX handlers and a REST API route without permission callbacks represent significant attack vectors that could be exploited by unauthenticated users. While the plugin has no recorded vulnerability history, this lack of historical issues should not be mistaken for guaranteed future security, especially given the identified weaknesses in access control for its entry points. Overall, the plugin has strengths in code hygiene but requires immediate attention to its access control mechanisms to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- REST API route without permission callbacks
- Cron events (potential for unintended execution)
Core Web Vitals – Real User Monitoring (RUM) Security Vulnerabilities
Core Web Vitals – Real User Monitoring (RUM) Release Timeline
Core Web Vitals – Real User Monitoring (RUM) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Core Web Vitals – Real User Monitoring (RUM) Attack Surface
AJAX Handlers 3
REST API Routes 2
WordPress Hooks 10
Scheduled Events 3
Maintenance & Trust
Core Web Vitals – Real User Monitoring (RUM) Maintenance & Trust
Maintenance Signals
Community Trust
Core Web Vitals – Real User Monitoring (RUM) Alternatives
MUDRAVA RUM
mudrava-rum
Real User Monitoring (RUM) plugin for WordPress that tracks TTFB, LCP, server generation time, and other performance metrics from real visitors.
Vibes
vibes
Truthful user experience and browsing performances monitoring.
Site24x7 Real User Monitoring
site24x7-rum
Real User Monitoring (RUM) by Site24x7 provides deep and accurate insight into real users’experience on your WordPress setup.
SpeedVitals RUM
speedvitals-rum
Integrates SpeedVitals RUM Script in your WordPress Website
Lumeo Vitals
lumeo-vitals
Optimize your Core Web Vitals (LCP, INP, CLS) with a single click. Lumeo Vitals is a lightweight performance engine designed for modern WordPress site …
Core Web Vitals – Real User Monitoring (RUM) Developer Profile
7 plugins · 210 total installs
How We Detect Core Web Vitals – Real User Monitoring (RUM)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/chart.umd.min.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/admin-dashboard.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/css/admin-styles.css/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/web-vitals.min.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/chart.umd.min.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/admin-dashboard.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/web-vitals.min.jscore-web-vitals-real-user-monitoring-rum/assets/js/admin-dashboard.js?ver=core-web-vitals-real-user-monitoring-rum/assets/css/admin-styles.css?ver=core-web-vitals-real-user-monitoring-rum/assets/js/web-vitals.min.js?ver=HTML / DOM Fingerprints
nandcwvrum-orange-icontoplevel_page_core-web-vitalsnandcwvrum_admin/wp-json/nandcwvrum/v1/