
GTmetrix for WordPress Security & Risk Analysis
wordpress.org/plugins/gtmetrix-for-wordpressGTmetrix can help you develop a faster, more efficient, and all-around improved website experience for your users. Your users will love you for it.
Is GTmetrix for WordPress Safe to Use in 2026?
Mostly Safe
Score 84/100GTmetrix for WordPress is generally safe to use though it hasn't been updated recently. 3 past CVEs were resolved. Keep it updated.
The gtmetrix-for-wordpress plugin version 0.4.8 presents a mixed security posture. On the positive side, it demonstrates good practices such as using prepared statements for all SQL queries and a reasonable percentage of properly escaped outputs. The absence of critical or high severity vulnerabilities in its history, and no currently unpatched CVEs, are also encouraging signs. However, several areas raise significant concerns. The presence of 3 AJAX handlers without authentication checks creates a direct attack vector, allowing unauthorized users to potentially trigger plugin functionalities. Furthermore, the use of dangerous functions like `unserialize` and `create_function` indicates potential vulnerabilities if inputs are not meticulously sanitized, as hinted by the taint analysis showing flows with unsanitized paths. While the historical medium severity vulnerabilities (CSRF and XSS) are patched, their recurrence pattern suggests that the plugin might have underlying architectural weaknesses that need constant vigilance and patching.
Key Concerns
- 3 AJAX handlers without auth checks
- 2 flows with unsanitized paths
- Dangerous functions: unserialize, create_function
- 72% output properly escaped (below 90%)
- 2 external HTTP requests
GTmetrix for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
GTmetrix for WordPress <= 0.4.7 - Cross-Site Request Forgery
GTmetrix for WordPress <= 0.4.6 - Reflected Cross-Site Scripting via 'report_id' and 'event_id'
GTmetrix for WordPress <= 0.4.5 - Reflected Cross-Site Scripting via 'url'
GTmetrix for WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
GTmetrix for WordPress Attack Surface
AJAX Handlers 8
WordPress Hooks 16
Scheduled Events 4
Maintenance & Trust
GTmetrix for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
GTmetrix for WordPress Alternatives
Fast Velocity Minify
fast-velocity-minify
Maximize GTmetrix, PageSpeed and enhance Web Vitals by minifying CSS/JS, lazy loading scripts, optimizing images, and improving load speed overall.
PhastPress
phastpress
PhastPress automatically optimizes your site for the best possible performance.
Machete
machete
Machete is a lean and simple suite of tools that solve common WordPress annoyances: cookie bar, tracking codes, header cleanup, social sharing
Lucky Orange
lucky-orange
Less time crunching numbers, more time growing your business.
SEO Engine
seo-engine
Made it through the SEO plugin wasteland? You've earned a coffee ☺️ Quietly powerful AI SEO that actually works. No bloat, just results. Enjoy! 💕
GTmetrix for WordPress Developer Profile
1 plugin · 9K total installs
How We Detect GTmetrix for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gtmetrix-for-wordpress/css/admin.css/wp-content/plugins/gtmetrix-for-wordpress/css/dashboard.css/wp-content/plugins/gtmetrix-for-wordpress/js/admin.js/wp-content/plugins/gtmetrix-for-wordpress/js/dashboard.js/wp-content/plugins/gtmetrix-for-wordpress/js/gtmetrix.js/wp-content/plugins/gtmetrix-for-wordpress/js/admin.js/wp-content/plugins/gtmetrix-for-wordpress/js/dashboard.js/wp-content/plugins/gtmetrix-for-wordpress/js/gtmetrix.jsgtmetrix-for-wordpress/css/admin.css?ver=gtmetrix-for-wordpress/css/dashboard.css?ver=gtmetrix-for-wordpress/js/admin.js?ver=gtmetrix-for-wordpress/js/dashboard.js?ver=gtmetrix-for-wordpress/js/gtmetrix.js?ver=HTML / DOM Fingerprints
gfw-widget-titlegtmetrix-report-linkgtmetrix-report-detailsGTmetrix for WordPressPlugin Name: GTmetrix for WordPressdata-gfw-urldata-gfw-api-keygfw_ajax_objectGFW_WP_VERSIONGFW_VERSIONGFW_USER_AGENTGFW_TIMEZONEGFW_AUTHORIZED+7 more/wp-json/gtmetrix/v1/test/wp-json/gtmetrix/v1/reports[gtmetrix_report][gtmetrix_score]