TGG – WP Optimizer Security & Risk Analysis

wordpress.org/plugins/tgg-wp-optimizer

This plugin is a collection of various WP tweaks.

600 active installs v1.25 PHP 7.0+ WP 5.0+ Updated Apr 4, 2025
auto-saveemojisimage-captionoptimizertrash
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMar 28, 2025
Safety Verdict

Is TGG – WP Optimizer Safe to Use in 2026?

Mostly Safe

Score 79/100

TGG – WP Optimizer is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Mar 28, 2025Updated 12mo ago
Risk Assessment

The "tgg-wp-optimizer" v1.25 plugin exhibits a mixed security posture. On the positive side, the static analysis shows strong adherence to several secure coding practices. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all identified output is properly escaped. Furthermore, the plugin includes a nonce check, suggesting some level of protection against replay attacks. The absence of file operations and external HTTP requests further minimizes potential attack vectors within the code itself.

However, a significant concern arises from the plugin's vulnerability history. It has one known CVE, which is currently unpatched and classified as medium severity, specifically related to Cross-Site Scripting. This indicates a past flaw that has not been remediated, posing a direct and present risk to users running this version. The fact that the vulnerability is a Cross-Site Scripting issue, a common type of web vulnerability, suggests a potential for inadequate input sanitization or output encoding in certain scenarios, even though the static analysis found no immediate issues in the analyzed code paths for this specific version.

In conclusion, while the static analysis of v1.25 reveals a generally robust codebase with good practices like prepared statements and proper output escaping, the presence of an unpatched medium-severity XSS vulnerability is a critical weakness. This historical vulnerability overrides the positive findings of the static analysis, making the plugin a medium to high risk until the CVE is addressed. The lack of demonstrated capability checks on entry points is also a minor concern given the historical vulnerability.

Key Concerns

  • Unpatched medium severity CVE
  • Potential for XSS due to historical vulnerability
  • No capability checks on entry points
Vulnerabilities
1

TGG – WP Optimizer Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31463medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

TGG WP Optimizer <= 1.22 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 28, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

TGG – WP Optimizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

TGG – WP Optimizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionadmin_menuindex.php:18
actionadmin_initindex.php:78
actioninitindex.php:281
filtertiny_mce_pluginsindex.php:282
actionwp_enqueue_scriptsindex.php:294
actionwp_print_scriptsindex.php:355
actionadmin_headindex.php:363
filterredirect_post_locationindex.php:401
filteruse_block_editor_for_postindex.php:407
actionafter_setup_themeindex.php:415
filterxmlrpc_enabledindex.php:424
filterxmlrpc_methodsindex.php:425
filtercomment_form_default_fieldsindex.php:436
filterwp_sitemaps_add_providerindex.php:449
filterwp_sitemaps_taxonomiesindex.php:459
actionadd_attachmentindex.php:477
filteradmin_email_check_intervalindex.php:482
filterexcerpt_moreindex.php:491
filterexcerpt_lengthindex.php:505
Maintenance & Trust

TGG – WP Optimizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 4, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs600
Developer Profile

TGG – WP Optimizer Developer Profile

preetindersodhi

1 plugin · 600 total installs

79
trust score
Avg Security Score
79/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TGG – WP Optimizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Generator Patterns
WordPress \d+\.\d+\.\d+ by WordPress

HTML / DOM Fingerprints

CSS Classes
wpotggswitchslider
Data Attributes
data-wpotgg-option-name
FAQ

Frequently Asked Questions about TGG – WP Optimizer