
DiveWP – Boost Site Performance with Clear, Actionable Steps Security & Risk Analysis
wordpress.org/plugins/divewp-boost-site-performanceLearn WP Best Practices Through Your Own Site! Get clear insights about Performance, Security, and Best Practices – explained in plain English.
Is DiveWP – Boost Site Performance with Clear, Actionable Steps Safe to Use in 2026?
Generally Safe
Score 100/100DiveWP – Boost Site Performance with Clear, Actionable Steps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The divewp-boost-site-performance plugin v2.3.3 exhibits a mixed security posture. On the positive side, it shows a strong adherence to good security practices with a high percentage of SQL queries using prepared statements and properly escaped output. The plugin also has a clean vulnerability history, with no known CVEs, which suggests a potentially stable codebase. Furthermore, it demonstrates a robust use of nonce and capability checks throughout its code.
However, there are significant concerns that temper this positive outlook. The plugin presents a substantial attack surface with 49 AJAX handlers, and a notable portion of these (16) lack authentication checks. This represents a direct avenue for potential unauthorized actions if malicious inputs can be crafted. The taint analysis revealing 3 high-severity flows with unsanitized paths is particularly alarming, as these could lead to serious security breaches if exploited, despite the absence of reported critical issues.
In conclusion, while the plugin has good underlying practices and no recorded historical vulnerabilities, the high number of unprotected AJAX endpoints and the presence of high-severity unsanitized taint flows are critical weaknesses. These areas require immediate attention and remediation to mitigate potential risks to WordPress sites utilizing this plugin.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Dangerous function: unserialize
DiveWP – Boost Site Performance with Clear, Actionable Steps Security Vulnerabilities
DiveWP – Boost Site Performance with Clear, Actionable Steps Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
DiveWP – Boost Site Performance with Clear, Actionable Steps Attack Surface
AJAX Handlers 49
WordPress Hooks 109
Scheduled Events 3
Maintenance & Trust
DiveWP – Boost Site Performance with Clear, Actionable Steps Maintenance & Trust
Maintenance Signals
Community Trust
DiveWP – Boost Site Performance with Clear, Actionable Steps Alternatives
WPVulnerability
wpvulnerability
Get WordPress vulnerability alerts from the WPVulnerability Database API.
SiteLock Security – WP Hardening, Login Security & Malware Scans
sitelock
Free, lightweight WordPress security. Harden your site with login protection & 2FA, see Site Health clearly and run on-demand checks—setup in minutes.
WP Disable Site Health
wp-disable-site-health
License: GPLv2 or later Disables new Site Health screen from WP Dashboard
WP safely disable directory browsing
wp-safely-disable-directory-browsing
This essential .htaccess rules plugin allow you to improve security of your wordpress blog.
Site Health Manager
site-health-manager
Control which status tests and what debug information appear in your Site Health screen.
DiveWP – Boost Site Performance with Clear, Actionable Steps Developer Profile
1 plugin · 200 total installs
How We Detect DiveWP – Boost Site Performance with Clear, Actionable Steps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/divewp-boost-site-performance/assets/css/divewp-styles.css/wp-content/plugins/divewp-boost-site-performance/assets/js/divewp-scripts.js/wp-content/plugins/divewp-boost-site-performance/assets/js/divewp-script-dashboard.js/wp-content/plugins/divewp-boost-site-performance/assets/js/divewp-script-admin.js/wp-content/plugins/divewp-boost-site-performance/assets/js/divewp-scripts.js/wp-content/plugins/divewp-boost-site-performance/assets/js/divewp-script-dashboard.js/wp-content/plugins/divewp-boost-site-performance/assets/js/divewp-script-admin.jsdivewp-boost-site-performance/assets/css/divewp-styles.css?ver=divewp-boost-site-performance/assets/js/divewp-scripts.js?ver=divewp-boost-site-performance/assets/js/divewp-script-dashboard.js?ver=divewp-boost-site-performance/assets/js/divewp-script-admin.js?ver=HTML / DOM Fingerprints
divewp-dashboard-wrapdivewp-overview-sectiondivewp-performance-insightsdivewp-security-insightsdivewp-best-practices-insightsdivewp-email-logging-table<!-- DiveWP Debug Log --><!-- DiveWP Performance Insights Section --><!-- DiveWP Security Insights Section --><!-- DiveWP Best Practices Insights Section -->data-divewp-chart-typedata-divewp-chart-datadata-divewp-insight-slugdata-divewp-user-iddivewp_paramsdivewp_dashboard_datadivewp_email_logsdivewp_debug_settings/wp-json/divewp/v1/insights/wp-json/divewp/v1/email-logs/wp-json/divewp/v1/debug-settings[divewp_performance_insight][divewp_security_insight][divewp_best_practice_insight][divewp_email_log_viewer]