Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce Security & Risk Analysis

wordpress.org/plugins/wp-disable

Reduce HTTP requests - Disable Emojis, Disable Gravatars, Disable Embeds and Remove Querystrings. SpeedUp WooCommerce, Added support to disable pingba …

10K active installs v1.6.1 PHP + WP 4.5+ Updated Aug 9, 2020
disable-embedsdisable-emojidisable-gravatarsreduce-http-requestsremove-querystrings
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wp-disable plugin v1.6.1 exhibits a generally good security posture based on the static analysis. The absence of any detected dangerous functions, raw SQL queries, or critical taint flows is a strong indicator of sound coding practices. The high percentage of properly escaped output and the presence of a capability check further bolster its security. The plugin also has a clean vulnerability history with no known CVEs, suggesting a low risk of exploitation through previously discovered flaws.

However, the lack of nonce checks on AJAX handlers (though there are none in this version) and the presence of file operations without explicit mention of sanitization or validation warrant consideration. While the attack surface appears minimal in this version, any future expansion or changes to entry points should be carefully scrutinized. The plugin's strengths lie in its minimal attack surface and apparent adherence to secure coding principles regarding SQL and output escaping. The primary weakness, if any, would be potential risks if new entry points are added without corresponding robust authorization and input validation mechanisms, which are not explicitly detailed in the provided signals.

Overall, wp-disable v1.6.1 appears to be a secure plugin at this version. The data suggests a low risk of direct exploitation. Continuous monitoring for new vulnerabilities and careful review of any future updates, particularly concerning new entry points or file operations, are recommended best practices. The absence of critical findings in static analysis and vulnerability history provides a high degree of confidence in its current security.

Key Concerns

  • Missing nonce checks on AJAX
  • File operations without explicit sanitization/validation
  • Output escaping not 100% proper
Vulnerabilities
None known

Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
14 escaped
Nonce Checks
0
Capability Checks
1
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped17 total outputs
Attack Surface

Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionupdate_local_gawpperformance.php:66
filtercron_scheduleswpperformance.php:151
actionplugins_loadedwpperformance.php:153
actionin_plugin_update_message-your-plugin/your-plugin.phpwpperformance.php:164

Scheduled Events 1

update_local_ga
Maintenance & Trust

Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedAug 9, 2020
PHP min version
Downloads310K

Community Trust

Rating82/100
Number of ratings45
Active installs10K
Developer Profile

Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce Developer Profile

hosting.io

3 plugins · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-disable/cache/local-ga.js

HTML / DOM Fingerprints

HTML Comments
<!-- Google Analytics Local by Optimisation.io -->
JS Globals
window.ga
FAQ

Frequently Asked Questions about Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce