
Performance Optimisation Security & Risk Analysis
wordpress.org/plugins/performance-optimisationA plugin to enhance website performance by managing cache, minifying JavaScript, CSS, and optimizing images.
Is Performance Optimisation Safe to Use in 2026?
Generally Safe
Score 92/100Performance Optimisation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'performance-optimisation' plugin version 1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, or shortcodes without proper authentication or permission checks significantly reduces the attack surface. Furthermore, the code demonstrates good practices with a high percentage of properly escaped outputs and the use of prepared statements for most SQL queries. The limited file operations and single external HTTP request also appear to be handled with caution, supported by nonce and capability checks. The lack of any historical vulnerabilities or known CVEs further reinforces this positive assessment, suggesting a well-maintained and secure plugin.
While the static analysis does not reveal any critical or high-severity taint flows, and the code signals generally indicate robust security implementations, a minor concern could be the presence of raw SQL queries. Although the majority use prepared statements, the 20% that do not could potentially be an area for attackers to explore if specific conditions are met, especially if they are exposed to user-controlled input. However, given the overall analysis, this risk is mitigated. The plugin appears to be developed with security in mind, and the absence of known vulnerabilities indicates a reliable track record.
Key Concerns
- Raw SQL queries present
Performance Optimisation Security Vulnerabilities
Performance Optimisation Code Analysis
SQL Query Safety
Output Escaping
Performance Optimisation Attack Surface
WordPress Hooks 23
Scheduled Events 4
Maintenance & Trust
Performance Optimisation Maintenance & Trust
Maintenance Signals
Community Trust
Performance Optimisation Alternatives
WP Optimizer
wp-optimizer
WordPress performance optimization plugin with cache, minify, image optimization, database cleanup, security hardening and server tuning.
WP Compress – Instant Performance & Speed Optimization
wp-compress-image-optimizer
Everything you need for a faster website – smart optimization, advanced caching, adaptive images, WebP creation, script improvements, optional CDN del …
All in one Minifier
all-in-one-minifier
Reduce your page load by minify your HTML source on page with all the CSS and JS code present in your page.
OptiCache
opticache
Comprehensive performance optimization: page caching, cache warmup, CSS/JS minification, defer/async loading, and intelligent .htaccess management.
Quickfire Cache and Speed Booster
quickfire-cache-speed-booster
Boost website performance with page caching, HTML/CSS/JS minification, lazy loading, script deferring, and server optimization.
Performance Optimisation Developer Profile
1 plugin · 0 total installs
How We Detect Performance Optimisation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/performance-optimisation/assets/css/backend.css/wp-content/plugins/performance-optimisation/assets/css/frontend.css/wp-content/plugins/performance-optimisation/assets/js/backend.js/wp-content/plugins/performance-optimisation/assets/js/frontend.js/wp-content/plugins/performance-optimisation/assets/js/backend.js/wp-content/plugins/performance-optimisation/assets/js/frontend.jsperformance-optimisation/assets/css/backend.css?ver=performance-optimisation/assets/css/frontend.css?ver=performance-optimisation/assets/js/backend.js?ver=performance-optimisation/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wppo-settings-pagewppo-settings-content<!-- Performance Optimisation Plugin --><!-- Optimize CSS Delivery --><!-- Optimize JS Delivery -->data-wppo-noncedata-wppo-setting-groupdata-wppo-setting-idwindow.wppo_ajax_object/wp-json/performance-optimisation/v1/settings/wp-json/performance-optimisation/v1/cache/clear[performance_optimisation_status]