
Torque – Optimise the transport of your Website Security & Risk Analysis
wordpress.org/plugins/torqueA Wordpress plugin to optimise the transport of your website to the client. Reduce the load on your server and make your Wordpress website fly!
Is Torque – Optimise the transport of your Website Safe to Use in 2026?
Generally Safe
Score 92/100Torque – Optimise the transport of your Website has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "torque" plugin v1.0.0 exhibits a concerning security posture despite the absence of known CVEs and a limited attack surface. Static analysis reveals significant issues with output escaping, with only 3% of 30 identified outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the context of a user's browser. Furthermore, the taint analysis identified two flows with unsanitized paths, suggesting potential for path traversal or arbitrary file access vulnerabilities, even though they are not classified as critical or high severity. The complete lack of capability checks and nonce checks on identified entry points, combined with the low percentage of properly escaped outputs, means that any interaction with these points could be exploited by unauthenticated users or without proper verification. The vulnerability history being clean is a positive sign, but it cannot mitigate the immediate risks identified in the static and taint analysis. The plugin's strengths lie in its absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests. However, the critical weakness in output sanitization and the presence of unsanitized paths represent substantial security risks that need immediate attention.
Key Concerns
- Low percentage of properly escaped outputs
- Taint flows with unsanitized paths
- No nonce checks on entry points
- No capability checks on entry points
Torque – Optimise the transport of your Website Security Vulnerabilities
Torque – Optimise the transport of your Website Release Timeline
Torque – Optimise the transport of your Website Code Analysis
Output Escaping
Data Flow Analysis
Torque – Optimise the transport of your Website Attack Surface
Maintenance & Trust
Torque – Optimise the transport of your Website Maintenance & Trust
Maintenance Signals
Community Trust
Torque – Optimise the transport of your Website Alternatives
JetHost Total Care – Security & Enhancements
jethost-total-care
JetHost Total Care simplifies WordPress management by consolidating features like security, site enhancements and performance into a single plugin.
WP safely disable directory browsing
wp-safely-disable-directory-browsing
This essential .htaccess rules plugin allow you to improve security of your wordpress blog.
CSS Above The Fold
css-above-the-fold
Faster CSS browser rendering displaying selected fragments of your theme stylesheet file directly into the head section.
DiveWP – Boost Site Performance with Clear, Actionable Steps
divewp-boost-site-performance
Learn WP Best Practices Through Your Own Site! Get clear insights about Performance, Security, and Best Practices – explained in plain English.
RationalCleanup
rationalcleanup
Clean up legacy WordPress bloat, improve security, and optimize performance with toggleable, opinionated defaults.
Torque – Optimise the transport of your Website Developer Profile
1 plugin · 0 total installs
How We Detect Torque – Optimise the transport of your Website
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/torque/javascript/csp.js/wp-content/plugins/torque/stylesheets/csp.css/wp-content/plugins/torque/javascript/csp.jstorque/javascript/csp.js?ver=torque/stylesheets/csp.css?ver=HTML / DOM Fingerprints
nav-tabnav-tab-activedata-tab