Core Web Vitals – Real User Monitoring (RUM) Security & Risk Analysis

wordpress.org/plugins/core-web-vitals-real-user-monitoring-rum

Track Core Web Vitals (LCP, INP, CLS, FCP, TTFB) from real users with comprehensive analytics, GA4 integration, and performance insights.

0 active installs v1.0.2 PHP 7.2+ WP 6.2+ Updated Nov 14, 2025
core-web-vitalslcpmonitoringperformancerum
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Core Web Vitals – Real User Monitoring (RUM) Safe to Use in 2026?

Generally Safe

Score 100/100

Core Web Vitals – Real User Monitoring (RUM) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

This plugin, "core-web-vitals-real-user-monitoring-rum" v1.0.2, exhibits a generally good security posture with strong adherence to best practices in several key areas. The extensive use of prepared statements for SQL queries and a high percentage of properly escaped output demonstrate a solid foundation for preventing common web vulnerabilities. The absence of dangerous functions and critical or high severity taint flows further contributes to its positive security profile. However, there are notable areas of concern that elevate its risk. The presence of multiple unprotected AJAX handlers and a REST API route without permission callbacks represent significant attack vectors that could be exploited by unauthenticated users. While the plugin has no recorded vulnerability history, this lack of historical issues should not be mistaken for guaranteed future security, especially given the identified weaknesses in access control for its entry points. Overall, the plugin has strengths in code hygiene but requires immediate attention to its access control mechanisms to mitigate potential security risks.

Key Concerns

  • Unprotected AJAX handlers
  • REST API route without permission callbacks
  • Cron events (potential for unintended execution)
Vulnerabilities
None known

Core Web Vitals – Real User Monitoring (RUM) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Core Web Vitals – Real User Monitoring (RUM) Release Timeline

v1.0.2Current
Code Analysis
Analyzed Mar 17, 2026

Core Web Vitals – Real User Monitoring (RUM) Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
36 prepared
Unescaped Output
6
102 escaped
Nonce Checks
6
Capability Checks
6
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

97% prepared37 total queries

Output Escaping

94% escaped108 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
nandcwvrum_save_settings (includes\admin-page.php:504)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Core Web Vitals – Real User Monitoring (RUM) Attack Surface

Entry Points5
Unprotected3

AJAX Handlers 3

authwp_ajax_nandcwvrum_export_csvcore-web-vitals-real-user-monitoring-rum.php:111
authwp_ajax_nandcwvrum_refresh_dashboardcore-web-vitals-real-user-monitoring-rum.php:112
authwp_ajax_nandcwvrum_test_ga4includes\ga4-integration.php:315

REST API Routes 2

POST/wp-json/nandcwvrum/v1/collectcore-web-vitals-real-user-monitoring-rum.php:362
GET/wp-json/nandcwvrum/v1/statscore-web-vitals-real-user-monitoring-rum.php:391
WordPress Hooks 10
actioninitcore-web-vitals-real-user-monitoring-rum.php:83
actionadmin_menucore-web-vitals-real-user-monitoring-rum.php:90
actionwp_dashboard_setupcore-web-vitals-real-user-monitoring-rum.php:93
actionadmin_enqueue_scriptscore-web-vitals-real-user-monitoring-rum.php:96
actionwp_enqueue_scriptscore-web-vitals-real-user-monitoring-rum.php:104
actionrest_api_initcore-web-vitals-real-user-monitoring-rum.php:107
actionadmin_noticesincludes\admin-page.php:540
actionnandcwvrum_daily_aggregationincludes\analytics.php:401
actionnandcwvrum_cleanup_old_dataincludes\analytics.php:402
actionnandcwvrum_send_email_reportincludes\analytics.php:403

Scheduled Events 3

nandcwvrum_daily_aggregation
nandcwvrum_cleanup_old_data
nandcwvrum_send_email_report
Maintenance & Trust

Core Web Vitals – Real User Monitoring (RUM) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 14, 2025
PHP min version7.2
Downloads213

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Core Web Vitals – Real User Monitoring (RUM) Developer Profile

Prakhar Bhatia

7 plugins · 210 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Core Web Vitals – Real User Monitoring (RUM)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/chart.umd.min.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/admin-dashboard.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/css/admin-styles.css/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/web-vitals.min.js
Script Paths
/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/chart.umd.min.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/admin-dashboard.js/wp-content/plugins/core-web-vitals-real-user-monitoring-rum/assets/js/web-vitals.min.js
Version Parameters
core-web-vitals-real-user-monitoring-rum/assets/js/admin-dashboard.js?ver=core-web-vitals-real-user-monitoring-rum/assets/css/admin-styles.css?ver=core-web-vitals-real-user-monitoring-rum/assets/js/web-vitals.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
nandcwvrum-orange-icon
Data Attributes
toplevel_page_core-web-vitals
JS Globals
nandcwvrum_admin
REST Endpoints
/wp-json/nandcwvrum/v1/
FAQ

Frequently Asked Questions about Core Web Vitals – Real User Monitoring (RUM)