SpeedMetriks Security & Risk Analysis

wordpress.org/plugins/speedmetriks

A self-contained service to see how visitors experience your site.

10 active installs v1.4.4 PHP 7.0+ WP 4.7+ Updated Apr 25, 2019
anonymous-dataperformancereal-user-monitoringvisitor-experience
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SpeedMetriks Safe to Use in 2026?

Generally Safe

Score 85/100

SpeedMetriks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of speedmetriks v1.4.4 reveals a very clean codebase with no identified vulnerabilities or concerning code patterns. The absence of dangerous functions, unsanitized taint flows, raw SQL queries, unescaped output, and file operations suggests a strong adherence to secure coding practices. Furthermore, the plugin has no recorded vulnerability history, indicating a history of stability and security. The fact that all identified components (AJAX handlers, REST API routes, shortcodes, cron events) are either absent or properly secured with authentication and permission checks is a significant strength. The lack of external HTTP requests also minimizes potential risks from compromised third-party services. While the plugin presents a minimal attack surface with no exposed entry points without authentication, the total absence of certain security checks like nonces and capability checks might be less of a concern given the lack of direct interaction points, but it's a practice that could be improved for future versions to establish even more robust defenses. Overall, this plugin demonstrates a strong security posture.

Vulnerabilities
None known

SpeedMetriks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SpeedMetriks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

SpeedMetriks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_enqueue_scriptsadmin\class-speed-metriks-admin-page.php:8
actionadmin_menuadmin\class-speed-metriks-admin-plots-menuitem.php:13
Maintenance & Trust

SpeedMetriks Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedApr 25, 2019
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SpeedMetriks Developer Profile

bookwyrm

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SpeedMetriks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/speedmetriks/dist/main.js
Script Paths
dist/main.js
Version Parameters
speedmetriks/dist/main.js?ver=

HTML / DOM Fingerprints

JS Globals
SpeedMetriksSetup
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about SpeedMetriks