
Extras for WP Rocket Security & Risk Analysis
wordpress.org/plugins/extra-wp-rocketAdded extra options to your WP Rocket configuration
Is Extras for WP Rocket Safe to Use in 2026?
Generally Safe
Score 85/100Extras for WP Rocket has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'extra-wp-rocket' v1.2 plugin exhibits a generally good security posture based on the static analysis. It has a minimal attack surface with no discovered AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points. The absence of dangerous functions and the exclusive use of prepared statements for SQL queries are strong indicators of secure coding practices. Furthermore, the plugin demonstrates a commitment to security by incorporating capability checks. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a history of stability and security diligence.
However, the analysis does reveal some areas for concern. The low percentage of properly escaped output (10%) is a significant weakness. This means that user-supplied data or dynamically generated content that is outputted by the plugin is likely not being adequately sanitized, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. While there are no critical taint flows or issues with unsanitized paths reported, the lack of nonce checks on the identified file operations (even if they don't have an attack surface reported) is a missed opportunity for robust security. The plugin also has some file operations without clear security checks mentioned, which could be a vector if not handled carefully.
In conclusion, 'extra-wp-rocket' v1.2 has a strong foundation in terms of limiting its attack surface and secure database interactions. The absence of historical vulnerabilities is commendable. The primary weakness lies in its output escaping, which requires immediate attention to prevent XSS attacks. The lack of nonce checks on file operations is another area that should be addressed to further harden the plugin's security.
Key Concerns
- Low output escaping percentage
- File operations without explicit nonce checks mentioned
Extras for WP Rocket Security Vulnerabilities
Extras for WP Rocket Code Analysis
Output Escaping
Extras for WP Rocket Attack Surface
WordPress Hooks 10
Maintenance & Trust
Extras for WP Rocket Maintenance & Trust
Maintenance Signals
Community Trust
Extras for WP Rocket Alternatives
Stratum Widgets for Elementor
stratum
20+ Premium widgets for Elementor, including Advanced Slider, Instagram, Google Maps, Advanced Accordion, Post Grid.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Extras for WP Rocket Developer Profile
3 plugins · 690 total installs
How We Detect Extras for WP Rocket
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extra-wp-rocket/extra-wp-rocket.phpHTML / DOM Fingerprints
notice-errornotice-infonotice-success