
Perform – Performance Optimization for WordPress Security & Risk Analysis
wordpress.org/plugins/performSpeed up your WordPress site by removing unused assets, optimize loading order, and much more; ideal for WooCommerce, page builders and busy sites.
Is Perform – Performance Optimization for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Perform – Performance Optimization for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "perform" v1.5.1 exhibits a generally strong security posture based on the provided static analysis. The absence of direct SQL injection vulnerabilities through prepared statements, lack of exploitable taint flows, and presence of nonce and capability checks are significant strengths. The plugin also demonstrates good practice by avoiding file operations and external HTTP requests, further reducing its attack surface.
However, a notable concern is the moderate rate of improper output escaping, with 30% of outputs not being properly escaped. While taint analysis didn't reveal specific vulnerabilities, unescaped output can still lead to Cross-Site Scripting (XSS) attacks if user-supplied data is ever incorporated into these outputs without sanitization. The bundled Freemius library at v1.0 is also a potential point of concern if it contains known vulnerabilities that haven't been addressed in this specific version.
The plugin's vulnerability history being completely clear is a positive indicator, suggesting a history of secure development. This, combined with the static analysis findings, indicates a developer who prioritizes security. Nevertheless, the potential for XSS due to imperfect output escaping and the possibility of vulnerabilities in bundled libraries warrant attention for a comprehensive risk assessment.
Key Concerns
- 30% of outputs not properly escaped
- Bundled Freemius v1.0 library may be outdated
Perform – Performance Optimization for WordPress Security Vulnerabilities
Perform – Performance Optimization for WordPress Code Analysis
Bundled Libraries
Output Escaping
Perform – Performance Optimization for WordPress Attack Surface
AJAX Handlers 1
WordPress Hooks 51
Maintenance & Trust
Perform – Performance Optimization for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Perform – Performance Optimization for WordPress Alternatives
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Breeze Cache
breeze
Breeze is a caching plugin developed by Cloudways. Breeze uses advance caching systems to improve site loading times exponentially.
Cachify
cachify
Smart, efficient cache solution for WordPress. Use DB, HDD, Redis or Memcached for storing your blog pages. Make WordPress faster!
Swift Performance Lite
swift-performance-lite
Swift Performance is a cache and performance booster plugin. It can speed up your site, improve SEO scores and user experience.
Perform – Performance Optimization for WordPress Developer Profile
5 plugins · 220 total installs
How We Detect Perform – Performance Optimization for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/perform/assets/dist/css/admin.css/wp-content/plugins/perform/assets/dist/js/admin.min.js/wp-content/plugins/perform/assets/dist/js/admin-settings.js/wp-content/plugins/perform/assets/dist/js/admin.min.js/wp-content/plugins/perform/assets/dist/js/admin-settings.jsperform/assets/dist/css/admin.css?ver=perform/assets/dist/js/admin.min.js?ver=perform/assets/dist/js/admin-settings.js?ver=HTML / DOM Fingerprints
perform-settings-pagedata-perform-nonceperformwpSettings