
TNC Toolbox: Web Performance Security & Risk Analysis
wordpress.org/plugins/tnc-toolboxDesigned for ea-NGINX (Cache/Proxy) on cPanel+WHM. Made to help you fly online! 🚀
Is TNC Toolbox: Web Performance Safe to Use in 2026?
Generally Safe
Score 93/100TNC Toolbox: Web Performance has a strong security track record. Known vulnerabilities have been patched promptly.
The tnc-toolbox plugin v2.1.2 presents a mixed security posture. On the positive side, the static analysis shows good practices in several areas. There are no detected dangerous functions, and all SQL queries utilize prepared statements, which is excellent for preventing SQL injection. Furthermore, the plugin implements a substantial number of nonce and capability checks, indicating an effort to secure its entry points. The limited attack surface with only one AJAX handler, which is also properly authenticated, is a strength. However, a significant concern arises from the vulnerability history, which includes two known CVEs, one of which was critical, and another medium severity. The fact that both are listed as 'currently unpatched' (despite the last vulnerability date being in the future, which might be an anomaly in the data) is a serious red flag.
The static analysis reveals a moderate level of concern regarding output escaping, with 29% of outputs not being properly escaped. While not directly flagged as a specific vulnerability type in the history, unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities. The plugin also performs file operations, and without knowing the specifics, this could introduce risks if not handled with extreme care, especially if user-supplied data is involved in file paths or operations.
Overall, while the plugin demonstrates some good security hygiene in its code, the historical presence of critical and medium vulnerabilities, particularly those related to Missing Authorization and Insecure Storage of Sensitive Information, cannot be ignored. The unpatched status of these historical vulnerabilities, if accurate, significantly elevates the risk. The issues with output escaping and file operations, while not immediately critical based on this data alone, warrant attention as potential attack vectors.
Key Concerns
- Critical and Medium Severity Vulnerabilities in History
- Unescaped Output detected
- File Operations present
TNC Toolbox: Web Performance Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
TNC Toolbox: Web Performance <= 2.0.4 - Missing Authorization
TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover
TNC Toolbox: Web Performance Code Analysis
Output Escaping
TNC Toolbox: Web Performance Attack Surface
AJAX Handlers 1
WordPress Hooks 23
Maintenance & Trust
TNC Toolbox: Web Performance Maintenance & Trust
Maintenance Signals
Community Trust
TNC Toolbox: Web Performance Alternatives
Nginx Helper
nginx-helper
Cleans nginx's fastcgi/proxy cache or redis-cache whenever a post is edited/published. Also does a few more things.
Speed Optimizer – The All-In-One Performance-Boosting Plugin
sg-cachepress
Boost your website performance and page speed, and increase conversions with powerful caching, frontend, media, and environment optimizations.
Proxy Cache Purge
varnish-http-purge
Automatically empty proxy cached content when your site is modified.
Nginx Cache
nginx-cache
Purge the Nginx cache (FastCGI, Proxy, uWSGI) automatically when content changes or manually within WordPress.
LWSCache
lwscache
This plugin lets you manage and automatically purge your hosting's LWSCache whenever you edit your website's content
TNC Toolbox: Web Performance Developer Profile
1 plugin · 1K total installs
How We Detect TNC Toolbox: Web Performance
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tnc-toolbox/css/tnc-toolbox-admin.css/wp-content/plugins/tnc-toolbox/css/tnc-toolbox-frontend.css/wp-content/plugins/tnc-toolbox/js/tnc-toolbox-admin.js/wp-content/plugins/tnc-toolbox/js/tnc-toolbox-frontend.jstnc-toolbox/css/tnc-toolbox-admin.css?ver=tnc-toolbox/css/tnc-toolbox-frontend.css?ver=tnc-toolbox/js/tnc-toolbox-admin.js?ver=tnc-toolbox/js/tnc-toolbox-frontend.js?ver=HTML / DOM Fingerprints
tnc-toolbox-admin-bar-menutnc-cache-purge-statusdata-tnc-purge-typetnc_toolbox_ajax_object