
Speedtest Pro Security & Risk Analysis
wordpress.org/plugins/speedtest-proSpeedtest Pro analyzes your site's performance with comprehensive server benchmarks and speed testing tools.
Is Speedtest Pro Safe to Use in 2026?
Generally Safe
Score 100/100Speedtest Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Speedtest Pro plugin v1.1.1 exhibits a generally strong security posture with commendable adherence to secure coding practices. A very high percentage of its SQL queries utilize prepared statements and output is overwhelmingly properly escaped, indicating a proactive approach to preventing common vulnerabilities like SQL injection and cross-site scripting. The plugin also demonstrates robust use of nonces and capability checks for most of its entry points.
However, there are notable areas of concern. The plugin exposes a significant attack surface with 61 AJAX handlers, and a concerning 11 of these lack any authentication checks. This is further exacerbated by a critical taint analysis finding of one flow with unsanitized paths. While no known CVEs are recorded, this combination of a large unprotected attack surface and a critical taint flow presents a significant risk. The absence of historical vulnerabilities might suggest a lack of previous scrutiny or that potential issues have been mitigated effectively in the past, but the current static analysis findings warrant immediate attention.
In conclusion, Speedtest Pro v1.1.1 shows strengths in core security practices like prepared statements and output escaping. Nevertheless, the presence of unprotected AJAX endpoints and a critical unsanitized path flow represents a serious risk that could be exploited without proper authentication. Addressing these specific points of exposure is paramount for improving the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- Critical taint flow with unsanitized paths
Speedtest Pro Security Vulnerabilities
Speedtest Pro Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Speedtest Pro Attack Surface
AJAX Handlers 61
WordPress Hooks 48
Scheduled Events 7
Maintenance & Trust
Speedtest Pro Maintenance & Trust
Maintenance Signals
Community Trust
Speedtest Pro Alternatives
Super Host Speed Benchmark
super-host-speed-benchmark
Test and benchmark the speed of your hosting provider, based on the speed of their mysql database, which tends to be the main cause of Wordpress being …
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
Autoptimize
autoptimize
Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
Speedtest Pro Developer Profile
1 plugin · 30 total installs
How We Detect Speedtest Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/speedtest-pro/admin/css/wpspeedtestpro-admin.css/wp-content/plugins/speedtest-pro/public/css/speedtest-pro.css/wp-content/plugins/speedtest-pro/public/js/speedtest-pro.js/wp-content/plugins/speedtest-pro/admin/js/wpspeedtestpro-admin.js/wp-content/plugins/speedtest-pro/admin/js/wpspeedtestpro-admin.js/wp-content/plugins/speedtest-pro/public/js/speedtest-pro.jsspeedtest-pro/css/wpspeedtestpro-admin.css?ver=speedtest-pro/css/speedtest-pro.css?ver=speedtest-pro/js/speedtest-pro.js?ver=speedtest-pro/js/wpspeedtestpro-admin.js?ver=HTML / DOM Fingerprints
wpspeedtestpro-dashboardspeedtest-pro-admin-wrapWP Speedtest Pro Admin Settings StartWP Speedtest Pro Admin Settings Enddata-wpspt-admin-settingswpspeedtestpro/wp-json/wpspeedtestpro/v1/admin-settings[wpspt_dashboard][wpspt_speedtest]