kombat-optimizer Security & Risk Analysis

wordpress.org/plugins/kombatoptimizer

WebP optimizer for WordPress/WooCommerce with scan, cron, and TTFB tools in a fast tabbed interface.

10 active installs v1.2.3 PHP + WP 5.0+ Updated Oct 20, 2025
cronimage-optimizationperformancewebpwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is kombat-optimizer Safe to Use in 2026?

Generally Safe

Score 100/100

kombat-optimizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The kombatoptimizer v1.2.3 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and output escaping is consistently applied. The absence of known vulnerabilities in its history is also a positive indicator. However, the plugin does utilize file operations and makes external HTTP requests, which are potential points of concern that, while not exhibiting direct vulnerabilities in this analysis, warrant careful monitoring. A significant weakness identified is the complete lack of capability checks on any of its entry points. While the attack surface is currently small (0 unprotected entry points), relying solely on other WordPress mechanisms for authorization instead of implementing explicit capability checks within the plugin itself is a risky practice. This can lead to privilege escalation if other security layers are compromised or misconfigured. Therefore, while the plugin demonstrates good coding practices in other areas, the absence of capability checks represents a notable security risk that needs to be addressed.

Key Concerns

  • No capability checks implemented
Vulnerabilities
None known

kombat-optimizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

kombat-optimizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
32 escaped
Nonce Checks
7
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped32 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
kombatoptimizer_panel (kombat-optimizer.php:44)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

kombat-optimizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterthe_contentinc\replace-webp.php:8
filterpost_thumbnail_htmlinc\replace-webp.php:9
filterwoocommerce_product_get_imageinc\replace-webp.php:10
filterwoocommerce_single_product_image_thumbnail_htmlinc\replace-webp.php:11
filterwp_get_attachment_image_attributesinc\replace-webp.php:12
filterwp_calculate_image_srcsetinc\replace-webp.php:13
filterwp_get_attachment_image_srcinc\replace-webp.php:14
filterpost_thumbnail_htmlinc\replace-webp.php:15
actioninitinc\webp-cron.php:5
actionkombatoptimizer_weekly_webp_croninc\webp-cron.php:19
actionadmin_menukombat-optimizer.php:30
actionadmin_enqueue_scriptskombat-optimizer.php:316

Scheduled Events 2

kombatoptimizer_weekly_webp_cron
kombatoptimizer_weekly_webp_cron
Maintenance & Trust

kombat-optimizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 20, 2025
PHP min version
Downloads237

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

kombat-optimizer Developer Profile

d_alinus2004

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect kombat-optimizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kombatoptimizer/assets/css/admin-style.css/wp-content/plugins/kombatoptimizer/assets/js/admin-script.js/wp-content/plugins/kombatoptimizer/assets/css/kombat-style.css/wp-content/plugins/kombatoptimizer/assets/js/kombat-script.js/wp-content/plugins/kombatoptimizer/assets/css/webp-style.css/wp-content/plugins/kombatoptimizer/assets/js/webp-script.js/wp-content/plugins/kombatoptimizer/assets/css/ttfb-style.css/wp-content/plugins/kombatoptimizer/assets/js/ttfb-script.js
Script Paths
/wp-content/plugins/kombatoptimizer/assets/js/admin-script.js/wp-content/plugins/kombatoptimizer/assets/js/kombat-script.js/wp-content/plugins/kombatoptimizer/assets/js/webp-script.js/wp-content/plugins/kombatoptimizer/assets/js/ttfb-script.js
Version Parameters
kombatoptimizer/assets/css/admin-style.css?ver=kombatoptimizer/assets/js/admin-script.js?ver=kombatoptimizer/assets/css/kombat-style.css?ver=kombatoptimizer/assets/js/kombat-script.js?ver=kombatoptimizer/assets/css/webp-style.css?ver=kombatoptimizer/assets/js/webp-script.js?ver=kombatoptimizer/assets/css/ttfb-style.css?ver=kombatoptimizer/assets/js/ttfb-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
kombat-tabskombat-tab-buttonskombat-tab-contentkombat-loaderkombat-info-boxkombat-info-restorekombat-btn
HTML Comments
🔧 Include module externe🖼️ Include înlocuire imagini doar dacă opțiunea e activă🔧 Adaugă meniu în admin🔧 Panou administrare+30 more
Data Attributes
data-targetname="webp_folder"id="webp_folder"name="generate_webp"name="optimize_webp"id="kombat-loader"+12 more
JS Globals
kombatoptimizer_adminkombatoptimizer_webpkombatoptimizer_ttfb
FAQ

Frequently Asked Questions about kombat-optimizer