
Performance Checker by DMUK Security & Risk Analysis
wordpress.org/plugins/performance-checker-by-dmukAutomatically generate bulk test posts in WordPress to simulate load for performance testing. Text Domain: performance-checker-by-dmuk.
Is Performance Checker by DMUK Safe to Use in 2026?
Generally Safe
Score 92/100Performance Checker by DMUK has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "performance-checker-by-dmuk" v3.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent code hygiene by utilizing prepared statements for all SQL queries and properly escaping all output, eliminating common web vulnerabilities like SQL injection and XSS. The absence of file operations and external HTTP requests further reduces its attack surface. The presence of 5 nonce checks is also a good indicator of security awareness. However, a significant concern is the presence of two AJAX handlers that lack authentication checks. This directly exposes these entry points, potentially allowing unauthenticated users to interact with plugin functionalities that might have unintended consequences or reveal sensitive information.
The taint analysis shows two flows with unsanitized paths, although these are not categorized as critical or high severity. This suggests a potential for path traversal or similar vulnerabilities if these flows are not properly handled. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong positive. This history, combined with the generally good coding practices, indicates that the developers have historically prioritized security. Nevertheless, the unprotected AJAX endpoints represent a clear and present risk that needs immediate attention. The overall risk is moderate, largely due to the unprotected AJAX handlers, which, despite the lack of critical taint flows and a clean vulnerability history, introduce a direct and exploitable weakness.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
Performance Checker by DMUK Security Vulnerabilities
Performance Checker by DMUK Code Analysis
Output Escaping
Data Flow Analysis
Performance Checker by DMUK Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Performance Checker by DMUK Maintenance & Trust
Maintenance Signals
Community Trust
Performance Checker by DMUK Alternatives
Site Demo Content
sample-data
One click import demo content which includes post, pages, comments etc. Also, import demo content for different plugins such as WooCommerce, bbPress e …
BlazeMeter
blazemeter
The BlazeMeter module provides WordPress users a way to seamlessly load test their web or mobile site or application for performance.
Productive Demo Importer
productive-demo-importer
Easily import demo data to test our themes' functionality and performance.
supervisor.com
supervisor-com
supervisor.com load testing and monitoring plugin for WordPress.
Performance Checker by DMUK Developer Profile
3 plugins · 0 total installs
How We Detect Performance Checker by DMUK
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/performance-checker-by-dmuk/dmuk-bo-main.cssdmuk-bo-main.css?ver=HTML / DOM Fingerprints
hidden<!-- File: includes/admin-page.php --><!-- Security Check: Exit if accessed directly --><!-- Include Necessary Files --><!-- ON ACTIVATION -->+14 morename="dmuk_bo_admin_nonce"value="dmuk_bo_admin_nonce"