Open Lazy Security & Risk Analysis

wordpress.org/plugins/open-lazy

A handy toolkit can easily tweak up and speed up your wordpress, more simple, more natural. Including pack the resources, unload the unnecessary, main …

10 active installs v2.6 PHP + WP + Updated Aug 15, 2019
linkpackspeedtoolkittweak
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Open Lazy Safe to Use in 2026?

Generally Safe

Score 85/100

Open Lazy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "open-lazy" plugin v2.6 exhibits a generally strong security posture based on the static analysis provided. The complete absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals show no dangerous functions, no raw SQL queries (all prepared statements), and no critical or high severity taint flows. The plugin also demonstrates some good practices with file operations and external HTTP requests, and importantly, the presence of at least one capability check.

However, several areas warrant attention. The output escaping is a significant concern, with only 39% of outputs being properly escaped, leaving a considerable number of opportunities for cross-site scripting (XSS) vulnerabilities. The lack of any nonce checks on its entry points, coupled with a capability check that is not guaranteed to cover all potential attack vectors for its file operations or external requests, suggests a potential for privilege escalation or unauthorized actions if these entry points are indeed exposed. The vulnerability history being clear is a positive sign, indicating a lack of publicly disclosed security flaws in the past, but it does not negate the risks identified in the static analysis. The plugin's strengths lie in its minimal attack surface and secure database interactions, but the poor output escaping and absence of robust authentication/authorization on its limited entry points are notable weaknesses.

Key Concerns

  • Low output escaping percentage
  • No nonce checks on entry points
  • Limited capability checks
Vulnerabilities
None known

Open Lazy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Open Lazy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
15 escaped
Nonce Checks
0
Capability Checks
1
File Operations
4
External Requests
2
Bundled Libraries
0

Output Escaping

39% escaped38 total outputs
Attack Surface

Open Lazy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 33
actioninitopen-lazy.php:18
actionget_headeropen-lazy.php:20
actionwp_enqueue_scriptsopen-lazy.php:42
actionwp_enqueue_scriptsopen-lazy.php:45
actionwp_enqueue_scriptsopen-lazy.php:48
actionlogin_enqueue_scriptsopen-lazy.php:49
filterlogin_headertextopen-lazy.php:53
filterlogin_headerurlopen-lazy.php:54
filtergettext_with_contextopen-lazy.php:57
filterthe_contentopen-lazy.php:60
actionwp_headopen-lazy.php:61
actionwp_footeropen-lazy.php:62
actionlogin_headopen-lazy.php:63
actionwp_footeropen-lazy.php:66
filterscript_loader_srcopen-lazy.php:69
filterstyle_loader_srcopen-lazy.php:70
filterwp_revisions_to_keepopen-lazy.php:74
filterwidget_textopen-lazy.php:78
filterwp_resource_hintsopen-lazy.php:81
actiontemplate_redirectopen-lazy.php:84
actionadmin_initopen-lazy.php:91
filterpre_update_option_olopopen-lazy.php:95
filterpre_set_site_transient_update_pluginsopen-lazy.php:96
actionadmin_bar_menuopen-lazy.php:97
actionwp_dashboard_setupopen-lazy.php:99
actionadmin_headopen-lazy.php:102
actionadmin_menuopen-lazy.php:118
actioncurrent_screenopen-lazy.php:136
actionwp_enqueue_scriptsopen-lazy.php:193
actionlogin_enqueue_scriptsopen-lazy.php:194
actionadmin_enqueue_scriptsopen-lazy.php:195
actionhttp_api_curlopen-lazy.php:390
filterlocaleopen-lazy.php:398
Maintenance & Trust

Open Lazy Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 15, 2019
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Open Lazy Developer Profile

Link

4 plugins · 90 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Open Lazy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/open-lazy/open-lazy.css/wp-content/plugins/open-lazy/open-lazy.js
Script Paths
/wp-content/plugins/open-lazy/open-lazy.js
Version Parameters
open-lazy/open-lazy.css?ver=open-lazy/open-lazy.js?ver=

HTML / DOM Fingerprints

CSS Classes
olop-indicator
Data Attributes
data-olop-img-iddata-olop-placeholder
JS Globals
open_lazy
FAQ

Frequently Asked Questions about Open Lazy