Native Performance Security & Risk Analysis

wordpress.org/plugins/native-performance

Improve the performance of your WordPress: Reduce load times, solve common errors and more using the Native Performance plugin.

10 active installs v1.2.10 PHP 5.0+ WP 4.0+ Updated Apr 28, 2025
cacheheartbeat-apioptimizationperformancespeed
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Native Performance Safe to Use in 2026?

Generally Safe

Score 92/100

Native Performance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "native-performance" plugin v1.2.10 appears to have a strong security posture. The absence of identified vulnerabilities in its history, coupled with a clean code analysis, suggests a well-maintained and security-conscious development process. Specifically, the analysis indicates no dangerous functions, no raw SQL queries, and all output being properly escaped. The plugin also exhibits no obvious entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected by authentication or permission checks.

Concerns are minimal, as there are no detected taint flows or exploitable code signals. The plugin does not perform file operations or external HTTP requests, further reducing potential attack vectors. The presence of capability checks is a positive sign for access control. The lack of any recorded vulnerabilities, especially critical or high severity ones, over its history is a significant strength, implying robust testing and proactive security measures by the developers.

Overall, the plugin presents a very low risk profile. Its strengths lie in its minimal attack surface and adherence to secure coding practices. The absence of any known or identified vulnerabilities in the provided data points to a highly secure plugin. However, the analysis is based on static data, and a deeper dynamic analysis or code review might uncover more nuanced issues, though none are immediately apparent from this report.

Vulnerabilities
None known

Native Performance Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Native Performance Release Timeline

v1.2.10Current
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Native Performance Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Native Performance Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionadmin_initcore\class-admin.php:20
actionwp_print_stylescore\class-functions.php:28
filterheartbeat_settingscore\class-functions.php:34
actioninitcore\class-functions.php:41
filterscript_loader_srccore\class-functions.php:48
filterstyle_loader_srccore\class-functions.php:49
filterget_avatar_urlcore\class-functions.php:55
actionwp_default_scriptscore\class-functions.php:61
actionwp_enqueue_scriptscore\class-functions.php:75
actionwp_enqueue_scriptscore\class-functions.php:76
actionafter_setup_themecore\class-functions.php:82
filterfallback_intermediate_image_sizescore\class-functions.php:88
filterclean_urlcore\class-functions.php:94
filterrest_enabledincludes\tweaks\head.php:27
filterrest_jsonp_enabledincludes\tweaks\head.php:28
filterthe_generatorincludes\tweaks\header.php:30
actionwp_print_stylesincludes\tweaks\plugins.php:56
actionwp_print_scriptsincludes\tweaks\plugins.php:61
filteradmin_footer_textnative-performance-main.php:28
actionplugins_loadednative-performance-main.php:38
filterplugin_action_linksnative-performance.php:71
filterplugin_row_metanative-performance.php:93
Maintenance & Trust

Native Performance Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 28, 2025
PHP min version5.0
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Native Performance Developer Profile

quecodigo

2 plugins · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Native Performance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/native-performance/assets/css/style.css/wp-content/plugins/native-performance/assets/js/native-performance.js
Generator Patterns
Native Performance
Script Paths
/wp-content/plugins/native-performance/assets/js/native-performance.js
Version Parameters
native-performance/assets/css/style.css?ver=native-performance/assets/js/native-performance.js?ver=

HTML / DOM Fingerprints

CSS Classes
native-performance-page
HTML Comments
<!-- NATIVE PERFORMANCE --><!-- NATIVE PERFORMANCE START --><!-- NATIVE PERFORMANCE END -->
Data Attributes
data-np-module
JS Globals
np_data
FAQ

Frequently Asked Questions about Native Performance