Page Speed Insights Security & Risk Analysis

wordpress.org/plugins/itman-page-speed-insights

Displays and measures page performance according to the Google PageSpeed Insights.

200 active installs v1.0.6 PHP 5.2.4+ WP 3.5+ Updated Jun 26, 2023
google-page-speeditman-page-speedpage-speed-widgetspeedspeed-insights
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Page Speed Insights Safe to Use in 2026?

Generally Safe

Score 85/100

Page Speed Insights has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'itman-page-speed-insights' v1.0.6 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin has a minimal attack surface, with no AJAX handlers, REST API routes, or shortcodes exposed, and the single cron event is not explicitly detailed regarding authentication. Crucially, there are no recorded vulnerabilities (CVEs), indicating a history of stability and likely good security practices in past development. However, there are significant concerns regarding output escaping, with only 13% of outputs being properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sanitized before being displayed. Additionally, the SQL query implementation is concerning, with only 33% using prepared statements, potentially opening the door to SQL injection flaws if data is not properly validated. The absence of nonce checks and capability checks on its entry points, although limited, also warrants attention. While the lack of taint analysis results and the absence of dangerous functions are positive, the unescaped outputs and raw SQL queries represent the most immediate risks.

Key Concerns

  • Low percentage of properly escaped output
  • Low percentage of SQL queries using prepared statements
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Page Speed Insights Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Page Speed Insights Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
2 prepared
Unescaped Output
14
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

33% prepared6 total queries

Output Escaping

13% escaped16 total outputs
Attack Surface

Page Speed Insights Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitadmin\admin.php:12
actionadmin_enqueue_scriptsadmin\admin.php:13
actionadmin_enqueue_scriptsadmin\admin.php:14
actionadmin_print_scripts-tools_page_itman-page-speed-insightsadmin\admin.php:15
actionadmin_menuadmin\admin.php:26
actionwp_dashboard_setupincludes\dashboardWidget.php:44
actionadmin_enqueue_scriptsincludes\dashboardWidget.php:216
actionitps_fetchPageSpeedDataitman-page-speed-insights.php:53
actionplugins_loadeditman-page-speed-insights.php:54
actioninititman-page-speed-insights.php:75

Scheduled Events 1

itps_fetchPageSpeedData
Maintenance & Trust

Page Speed Insights Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 26, 2023
PHP min version5.2.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Page Speed Insights Developer Profile

Matej Podstrelenec

5 plugins · 530 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Page Speed Insights

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/itman-page-speed-insights/css/itman-page-speed-admin.css/wp-content/plugins/itman-page-speed-insights/js/itman-page-speed-admin.js
Script Paths
https://www.gstatic.com/charts/loader.js
Version Parameters
itman-page-speed-insights/css/itman-page-speed-admin.css?ver=itman-page-speed-insights/js/itman-page-speed-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
itemprop="logo"
JS Globals
googlechart_data
FAQ

Frequently Asked Questions about Page Speed Insights