LC Scripts Optimizer Security & Risk Analysis

wordpress.org/plugins/lc-scripts-optimizer

Tool built with a unique focus: optimize as much as possible WordPress website scripts usage to make pages load much faster!

20 active installs v2.1.0 PHP 7.0+ WP 5.0+ Updated Mar 9, 2026
cachecompressminificationseospeed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LC Scripts Optimizer Safe to Use in 2026?

Generally Safe

Score 100/100

LC Scripts Optimizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The lc-scripts-optimizer plugin v2.1.0 demonstrates a generally good security posture with no recorded vulnerabilities or critical taint flows. The plugin effectively utilizes prepared statements for SQL queries and implements nonce and capability checks for its entry points, which is a strong indicator of secure coding practices in these areas. The absence of bundled libraries and external HTTP requests further reduces the attack surface.

However, a significant concern arises from the output escaping, where only 38% of outputs are properly escaped. This presents a notable risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could potentially be injected and executed within the browser. Additionally, the presence of two taint flows with unsanitized paths, while not classified as critical or high, warrants investigation to ensure no sensitive data is exposed or manipulated unintentionally.

Given the plugin's clean vulnerability history, it's likely that these identified issues have not yet led to exploitation. Nevertheless, the unescaped output and unsanitized taint flows represent real potential weaknesses that should be addressed to maintain a robust security profile. The plugin's strengths lie in its authentication and data handling, but its output sanitization needs immediate attention.

Key Concerns

  • Insufficient output escaping
  • Taint flows with unsanitized paths
Vulnerabilities
None known

LC Scripts Optimizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

LC Scripts Optimizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
65
40 escaped
Nonce Checks
4
Capability Checks
4
File Operations
4
External Requests
3
Bundled Libraries
0

Output Escaping

38% escaped105 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
get_code (settings\settings_engine.php:99)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LC Scripts Optimizer Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_lcso_empty_scripts_cacheajax.php:37
authwp_ajax_lcso_store_queued_scriptsajax.php:67
authwp_ajax_lcso_del_stored_scriptajax.php:110
WordPress Hooks 15
actiontemplate_redirectclasses\frontend.php:53
actioninitclasses\frontend.php:56
actionshutdownclasses\frontend.php:105
actionshutdownclasses\frontend.php:106
actionwp_print_scriptsclasses\frontend.php:142
actionwp_print_stylesclasses\frontend.php:145
actionwp_print_scriptsclasses\frontend.php:153
actionwp_print_stylesclasses\frontend.php:156
actionwp_headclasses\frontend.php:159
actionwp_footerclasses\frontend.php:160
actioninitlc_scripts_optimizer.php:71
actionadmin_enqueue_scriptslc_scripts_optimizer.php:97
actionadmin_menulc_scripts_optimizer.php:110
filterplugin_row_metalc_scripts_optimizer.php:137
actionactivated_pluginlc_scripts_optimizer.php:156
Maintenance & Trust

LC Scripts Optimizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

LC Scripts Optimizer Developer Profile

LCweb

4 plugins · 90 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LC Scripts Optimizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lc-scripts-optimizer/settings/settings_style.css/wp-content/plugins/lc-scripts-optimizer/css/admin.css/wp-content/plugins/lc-scripts-optimizer/js/lc-switch/lc_switch.min.js/wp-content/plugins/lc-scripts-optimizer/js/lc-wp-popup-message/lc_wp_popup_message.min.js/wp-content/plugins/lc-scripts-optimizer/js/lc-select/themes/lcwp_prefixed.css/wp-content/plugins/lc-scripts-optimizer/js/lc-select/lc_select.min.js
Script Paths
/wp-content/plugins/lc-scripts-optimizer/settings/settings_style.css/wp-content/plugins/lc-scripts-optimizer/css/admin.css/wp-content/plugins/lc-scripts-optimizer/js/lc-switch/lc_switch.min.js/wp-content/plugins/lc-scripts-optimizer/js/lc-wp-popup-message/lc_wp_popup_message.min.js/wp-content/plugins/lc-scripts-optimizer/js/lc-select/themes/lcwp_prefixed.css/wp-content/plugins/lc-scripts-optimizer/js/lc-select/lc_select.min.js
Version Parameters
lc-scripts-optimizer/settings/settings_style.css?ver=lc-scripts-optimizer/css/admin.css?ver=lc-scripts-optimizer/js/lc-switch/lc_switch.min.js?ver=lc-scripts-optimizer/js/lc-wp-popup-message/lc_wp_popup_message.min.js?ver=lc-scripts-optimizer/js/lc-select/themes/lcwp_prefixed.css?ver=lc-scripts-optimizer/js/lc-select/lc_select.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
lcso_check_lcweb_pjcts_link
Data Attributes
lcso_php_debuglcso_ml
JS Globals
lcso_ml
FAQ

Frequently Asked Questions about LC Scripts Optimizer