
Enesozer Guard for Core Web Vitals Security & Risk Analysis
wordpress.org/plugins/enesozer-guard-for-core-web-vitalsMonitor and remediate Core Web Vitals regressions.
Is Enesozer Guard for Core Web Vitals Safe to Use in 2026?
Generally Safe
Score 100/100Enesozer Guard for Core Web Vitals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The enesozer-guard-for-core-web-vitals plugin, version 0.1.2, exhibits a mixed security posture. On the positive side, the plugin demonstrates good coding practices by using prepared statements for all SQL queries and ensuring proper output escaping. There are no identified dangerous functions, file operations, external HTTP requests, or bundled libraries that could introduce vulnerabilities. The absence of any recorded vulnerabilities or CVEs in its history is also a strong indicator of a secure development process thus far.
However, a significant concern arises from the plugin's attack surface. It exposes one REST API route that lacks any permission callbacks, rendering it accessible to any user, including unauthenticated ones. This is a critical oversight as it presents a direct entry point for potential exploitation without any authorization checks. The lack of nonce checks on AJAX handlers, while currently at zero, is also a potential area of concern if AJAX functionality is added in the future without proper security measures.
In conclusion, while the plugin excels in areas like data sanitization and query security, the unprotected REST API route is a glaring weakness that elevates the overall risk. The vulnerability history is reassuring, but the current static analysis reveals a specific, exploitable flaw. Addressing the unprotected REST API route should be the immediate priority to improve the plugin's security.
Key Concerns
- Unprotected REST API route without permission callback
- No nonce checks on AJAX handlers (potential future risk)
Enesozer Guard for Core Web Vitals Security Vulnerabilities
Enesozer Guard for Core Web Vitals Release Timeline
Enesozer Guard for Core Web Vitals Code Analysis
Enesozer Guard for Core Web Vitals Attack Surface
REST API Routes 1
WordPress Hooks 1
Maintenance & Trust
Enesozer Guard for Core Web Vitals Maintenance & Trust
Maintenance Signals
Community Trust
Enesozer Guard for Core Web Vitals Alternatives
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
Autoptimize
autoptimize
Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.
RabbitLoader – AI Speed Optimization, Caching & CDN for WordPress & WooCommerce
rabbit-loader
All-in-one AI speed optimization plugin for WordPress & WooCommerce websites. Get faster loading pages and near-perfect PageSpeed scores — in just …
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization
add-expires-headers
AEH Speed Optimization boosts site speed with caching, minification, lazy loading, and image optimization to improve performance and SEO.
Zero Config Performance Optimization
wpo-tweaks
Advanced performance optimizations for WordPress. Improves speed, reduces server resources and optimizes PageSpeed.
Enesozer Guard for Core Web Vitals Developer Profile
1 plugin · 0 total installs
How We Detect Enesozer Guard for Core Web Vitals
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
enesozer-guard-for-core-web-vitals/enesozer-guard-for-core-web-vitals.php?ver=HTML / DOM Fingerprints
/wp-json/para/v1/health