[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4IThBEzmMQ5ACTrgAcQqoHFA_6-luJggFScNCnzXpcw":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":32,"crawl_stats":29,"alternatives":38,"analysis":142,"fingerprints":298},"wp-head-optimizer","WP Head Optimizer","1.0.0","gr8nilay","https:\u002F\u002Fprofiles.wordpress.org\u002Fgr8nilay\u002F","\u003Cp>WordPress always add many meta tags as well as links, urls scripts and many additional things to WordPress head section and this plugin helps to remove that additional added code stuff and that will increase site performance, security and reduce the HTTP requests of the page and that definitely helps to the site.\u003C\u002Fp>\n\u003Cp>For backwards compatibility, if this section is missing, the full length of the short description will be used, and\u003Cbr \u002F>\nMarkdown parsed.\u003C\u002Fp>\n\u003Cp>Using this plugin you can enable \u002F disable below things that can surely helps your site to load faster and provide some security as well.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Disable WP Emoji CSS & Script\u003C\u002Fli>\n\u003Cli>Remove Canonical URL\u003C\u002Fli>\n\u003Cli>Remove WordPress Version for security purpose\u003C\u002Fli>\n\u003Cli>Remove Shortlink\u003C\u002Fli>\n\u003Cli>Remove RSS Feed URL\u003C\u002Fli>\n\u003Cli>Remove EditURI Link\u003C\u002Fli>\n\u003Cli>Disable JSON API\u003C\u002Fli>\n\u003Cli>Remove Style and Script Versions\u003C\u002Fli>\n\u003Cli>Remove WLW Manifest\u003C\u002Fli>\n\u003Cli>Remove Next\u002FPrevious Post URLs Links\u003C\u002Fli>\n\u003Cli>Remove REST API link tag\u003C\u002Fli>\n\u003Cli>Remove oEmbed Discovery Links\u003C\u002Fli>\n\u003C\u002Ful>\n","This plugin allow you to remove unnecessary tags, links, urls, scrips and many additional things from your WordPress header to speed up site loading t &hellip;",300,6010,100,5,"2024-02-10T20:21:00.000Z","6.4.8","3.0.1","",[20,21,22,23,24],"clean-head","optimization","remove","wphead","wphead-clean","http:\u002F\u002Fstore.wphound.com\u002Fwp-head-optimizer\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-head-optimizer.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":34,"avg_security_score":27,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},10,1930,30,84,"2026-04-04T09:04:30.016Z",[39,63,85,103,123],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":47,"downloaded":48,"rating":49,"num_ratings":13,"last_updated":50,"tested_up_to":51,"requires_at_least":52,"requires_php":53,"tags":54,"homepage":60,"download_link":61,"security_score":62,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"disable-dashboard-for-woocommerce","Disable Bloat for WordPress & WooCommerce","3.5.0","Rock Solid","https:\u002F\u002Fprofiles.wordpress.org\u002Fmikewire_rocksolid\u002F","\u003Cp>🚀 \u003Cstrong>Boost Your Site’s Speed and Cleanliness with Disable Bloat!\u003C\u002Fstrong> 🚀\u003C\u002Fp>\n\u003Ch3>Over 400k downloads and 20k+ active installs! And many 5 star reviews\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>“This plugin will from now on be on my ‘required plugins’ list 🙂”\u003C\u002Fstrong>\u003Cbr \u002F>\n⭐️⭐️⭐️⭐️⭐️\u003Cbr \u002F>\n\u003Cem>— Janca\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>“So much easier than manually maintaining a list of filters to remove!”\u003C\u002Fstrong>\u003Cbr \u002F>\n⭐️⭐️⭐️⭐️⭐️\u003Cbr \u002F>\n\u003Cem>— Hollowdev\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>“Wow – just wow!!!”\u003C\u002Fstrong>\u003Cbr \u002F>\n⭐️⭐️⭐️⭐️⭐️\u003Cbr \u002F>\n\u003Cem>— Hebhensen\u003C\u002Fem>\u003C\u002Fp>\n\u003Cp>Bloat is the silent killer of your site’s performance, often slowing down your entire website. Ensure your site stays lightning-fast with \u003Cstrong>Disable Bloat\u003C\u002Fstrong>, the ultimate plugin to disable unnecessary features that drag your site down.\u003C\u002Fp>\n\u003Cp>By default, the WordPress admin panel is cluttered with preinstalled elements that can distract you from your work. \u003Cstrong>Disable Bloat\u003C\u002Fstrong> smooths and cleans the admin panel by removing these unnecessary elements.\u003C\u002Fp>\n\u003Cp>✨ \u003Cstrong>Why Choose Disable Bloat?\u003C\u002Fstrong> ✨\u003Cbr \u002F>\n– Make Your Admin Panel Fast and Clean by disabling unwanted features\u003Cbr \u002F>\n– Accelerate Your WordPress Website and enhance user experience\u003Cbr \u002F>\n– Boost Security by turning off features you don’t use\u003Cbr \u002F>\n– Eliminate Third-Party Plugin Bloat to keep your site lean and fast-loading\u003C\u002Fp>\n\u003Cp>Enjoy the perfect blend of aesthetics and speed. With \u003Cstrong>Disable Bloat\u003C\u002Fstrong>, every tweak is seamless and live, giving you the fast, clean WordPress admin panel you deserve.\u003C\u002Fp>\n\u003Cp>🔓 \u003Cstrong>Premium Version\u003C\u002Fstrong> 🔓\u003Cbr \u002F>\nUnlock all features with \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">Disable Bloat for WordPress & WooCommerce PRO\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>🚫 \u003Cstrong>Disable WooCommerce Bloat\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>Turn Off WooCommerce Admin\u003C\u002Fstrong> to lighten your back-end\u003Cbr \u002F>\n– \u003Cstrong>Remove WooCommerce Promotions\u003C\u002Fstrong> cluttering your admin panel\u003Cbr \u002F>\n– \u003Cstrong>Reduce CSS and JavaScript Load\u003C\u002Fstrong> for a faster front-end and back-end\u003C\u002Fp>\n\u003Cp>📊 \u003Cstrong>WooCommerce Admin\u003C\u002Fstrong>\u003Cbr \u002F>\nWooCommerce Admin is a JavaScript-driven dashboard that can slow down your website. Disabling it can help speed up your site and improve user experience. Use these options to disable WooCommerce Admin, Analytics, Home screen, and other features slowing your admin panel:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable WooCommerce Admin\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Choose Admin Features to Disable\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Turn Off Marketing Hub and Promotions\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>📧 \u003Cstrong>WooCommerce Emails\u003C\u002Fstrong>\u003Cbr \u002F>\nAnnoyed by WooCommerce’s promotional emails? Stay balanced by disabling:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>WooCommerce Guide Emails\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove “Get the App” from Emails \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🛠️ \u003Cstrong>WooCommerce Back-end Scripts\u003C\u002Fstrong>\u003Cbr \u002F>\nSpeed up your site by disabling unwanted scripts:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable WooCommerce Status Meta Box\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WooCommerce Dashboard Setup Widget\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable New WooCommerce Product Editor\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WooCommerce Blocks (back-end) \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🌐 \u003Cstrong>Your Store’s Front-end\u003C\u002Fstrong>\u003Cbr \u002F>\nDisable unnecessary scripts and styles loading on your shop’s front-end:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable WooCommerce Widgets\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WooCommerce Scripts and Styles\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WooCommerce Cart Fragments\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WooCommerce Blocks (front-end) \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Unnecessary Stripe Scripts \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🧼 \u003Cstrong>Optimize WordPress Admin Panel\u003C\u002Fstrong>\u003Cbr \u002F>\nMake the admin panel smooth and clean by removing unnecessary elements:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Clean Admin Interface\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Update Notice for Non-admin Users\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WordPress Editor Autosave\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Dashboard Widgets \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove WordPress Logo from Admin Bar \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Admin Footer Text \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🔒 \u003Cstrong>WordPress Login Page\u003C\u002Fstrong>\u003Cbr \u002F>\nCustomize the login page to your preference:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Hide WordPress Logo from Login Page \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change Logo Link on Login Page \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Change Logo Title Parameter on Login Page \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Login Language Switcher \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🚀 \u003Cstrong>Boost Your Site’s Performance\u003C\u002Fstrong>\u003Cbr \u002F>\nDisable features you never use to improve load times and user experience:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable Password Strength Meter\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Load Comments Script Only When Needed\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WordPress Dashicons on Front-end\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove DNS Prefetch to s.w.org \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable jQuery Migrate \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Sidebar Widgets \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Meta Generator Tag \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Emoji Scripts \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable wp-embed \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🗑️ \u003Cstrong>Remove Scripts from Header\u003C\u002Fstrong>\u003Cbr \u002F>\nClean up your site’s header by removing unwanted scripts:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Remove RSS Feed Links \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable All RSS Feeds \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Generator Tag from RSS Feeds \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Link to Windows Live Writer Manifest File \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Shortlink from HTTP Header \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🔧 \u003Cstrong>Disable Unused Core WordPress Features\u003C\u002Fstrong>\u003Cbr \u002F>\nEnhance performance and security by disabling unused features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable XML-RPC API \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Post Revisions\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Turn Off Built-in File Editor\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🔄 \u003Cstrong>Updates\u003C\u002Fstrong>\u003Cbr \u002F>\nControl how your website updates to save resources:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable Themes Auto-updates\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Plugins Auto-updates\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable All WordPress Core Updates \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🛡️ \u003Cstrong>Speed and Security\u003C\u002Fstrong>\u003Cbr \u002F>\nKeep your site fast and secure by managing core features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable File Editor \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Post Revisions \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Application Passwords \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Script\u002FStyle Version Parameter \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🌐 \u003Cstrong>WordPress API\u003C\u002Fstrong>\u003Cbr \u002F>\nManage various WordPress APIs to improve performance:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable XML-RPC API \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WordPress Heartbeat API \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable REST API \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>✍️ \u003Cstrong>Block Editor\u003C\u002Fstrong>\u003Cbr \u002F>\nManage Block Editor features to keep your site fast:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable Gutenberg\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Specific Gutenberg Features \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>🔗 \u003Cstrong>Third-Party Plugins Bloat\u003C\u002Fstrong>\u003Cbr \u002F>\nOptimize your site by managing third-party plugin bloat:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Remove Jetpack Installation Notice\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Jetpack Promotions and Blaze\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Elementor Dashboard Widget\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Elementor Google Fonts Package\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable SkyVerge Dashboard\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Yoast Ads, Premium Nags, and Admin Bar Item \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Yoast HTML Comments \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Contact Form 7 JavaScript and CSS \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide UpDraftPlus on Admin Toolbar \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide Advanced Custom Fields Admin Menu \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove WPML Meta Generator Tag \u003Ca href=\"https:\u002F\u002Fdisablebloat.com\u002F?utm_source=wp_org&utm_medium=referral&utm_campaign=readme\" rel=\"nofollow ugc\">PRO\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Flexible Shipping Extensions Menu Entry\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable WP Desk Dashboard Widget\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>⚙️ \u003Cstrong>Usage\u003C\u002Fstrong>\u003Cbr \u002F>\nGo to the configuration page: \u003Cstrong>Settings -> Disable Bloat\u003C\u002Fstrong> to get started. 🚀\u003C\u002Fp>\n","All-in-One solution to speed up your WordPress & WooCommerce. Remove unnecessary features and make your site faster and cleaner.",10000,472209,96,"2025-02-05T12:44:00.000Z","6.7.5","4.5","5.6",[55,56,57,58,59],"admin-panel-customization","remove-bloat","website-cleanup","woocommerce","wordpress-optimization","https:\u002F\u002Fdisablebloat.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdisable-dashboard-for-woocommerce.3.5.0.zip",92,{"slug":64,"name":65,"version":66,"author":67,"author_profile":68,"description":69,"short_description":70,"active_installs":13,"downloaded":71,"rating":72,"num_ratings":73,"last_updated":74,"tested_up_to":75,"requires_at_least":76,"requires_php":18,"tags":77,"homepage":83,"download_link":84,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"bpwp-cleaner","BlankPress WordPress Cleaner","1.1","dharmapoudel","https:\u002F\u002Fprofiles.wordpress.org\u002Fdharmapoudel\u002F","\u003Cp>This plugin allows users to selectively clean up the WordPress header, removes unwanted dashboard widgets  and tweaks annoying WordPress features.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Head Cleanup\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>removes the Generator\u002FWordPress Version number\u003C\u002Fli>\n\u003Cli>removes link to Really Simple Discovery service endpoint\u003C\u002Fli>\n\u003Cli>removes link to Windows Live Writer manifest file\u003C\u002Fli>\n\u003Cli>removes displaying links to the extra feeds such as category feeds\u003C\u002Fli>\n\u003Cli>removes displaying links to the general feeds: Post and Comment Feed\u003C\u002Fli>\n\u003Cli>removes adjacent posts links : Index link, Next link, Start link\u003C\u002Fli>\n\u003Cli>removes WordPress cannonical link\u003C\u002Fli>\n\u003Cli>removes WordPress Shortlink\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Dashboard widgets Cleanup\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>removes help tab on dashboard screen or all whole screen\u003C\u002Fli>\n\u003Cli>removes WordPress Welcome Panel\u003C\u002Fli>\n\u003Cli>removes update submenu under ‘Dashboard’ menu\u003C\u002Fli>\n\u003Cli>removes wordpress update nag\u003C\u002Fli>\n\u003Cli>removes update browser nag\u003C\u002Fli>\n\u003Cli>removes wordpress dashboard widgets At a Glance\u002FQuick Draft\u002FWordPress News\u002FActivity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Misc Cleanup\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>removes versions from css and js source link\u003C\u002Fli>\n\u003Cli>removes javascripts and styles from header & moves to footer\u003C\u002Fli>\n\u003Cli>removes default styles set by WordPress recent comments widget\u003C\u002Fli>\n\u003Cli>removes width and height dynamic attributes to thumbnails\u002Fpost images\u003C\u002Fli>\n\u003Cli>removes WordPress generated category and tag atributes for W3C validation\u003C\u002Fli>\n\u003Cli>removes admin bar from the frontend\u003C\u002Fli>\n\u003Cli>removes and\u002For changes WordPress login error message\u003C\u002Fli>\n\u003Cli>removes WordPress login shake effect\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Consequences\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Page load speed increases drastically.\u003C\u002Fli>\n\u003Cli>Better site performance.\u003C\u002Fli>\n\u003Cli>Google will love your site. Also users will love your site.\u003C\u002Fli>\n\u003Cli>Better security : stay safe, sleep well!\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Recommended Plugins\u003C\u002Fh4>\n\u003Cp>The following are recommended by the author:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.wordpress.org\u002Fplugins\u002Fpage-specific-menu-items\u002F\" rel=\"nofollow ugc\">Page Specific Menu Items\u003C\u002Fa> – Allows you to selectively hide the menu items. One menu different menu items on different page(posts).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fdharmapoudel\u002Fblankpress\" rel=\"nofollow ugc\">BlankPress Theme Framework\u003C\u002Fa> – Simple yet flexible HTML5 blank WordPress theme framework based on underscores. Use this as a base theme for your WP projects.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n","Allows user to clean up the WordPress  mess. Better performance, Faster page load, Better security and Better WP experience.",6446,86,6,"2014-12-20T00:59:00.000Z","4.1.42","3.5",[78,79,80,81,82],"dashboard-cleaner","header-cleaner","springclean-wordpress","wordpress-cleaner","wphead-cleaner","http:\u002F\u002Fwww.wordpress.org\u002Fplugins","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbpwp-cleaner.1.1.zip",{"slug":86,"name":87,"version":88,"author":89,"author_profile":90,"description":91,"short_description":92,"active_installs":13,"downloaded":93,"rating":13,"num_ratings":94,"last_updated":95,"tested_up_to":96,"requires_at_least":97,"requires_php":18,"tags":98,"homepage":101,"download_link":102,"security_score":62,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"wp-head-cleanup","WP Head Cleanup","1.0","nablasol","https:\u002F\u002Fprofiles.wordpress.org\u002Fnablasol\u002F","\u003Cp>WP Head Cleanup helps you to remove unnecessary extra links from the page header.\u003C\u002Fp>\n\u003Cp>The Plugin will remove following links:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>rsd_link\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove Really Simple Discovery link from the header.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>wp_generator\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove the WordPress generator tag.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>feed_links\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove the standard feed links.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>feed_links_extra\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove the extra feed links.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>index_rel_link\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove index link.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>wlwmanifest_link\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove wlwmanifest\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>parent_post_rel_link\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove parent post link\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>start_post_rel_link\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove start post link\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>adjacent_posts_rel_link_wp_head\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove the prev and next post link\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>wp_shortlink_wp_head\u003C\u002Fstrong>\u003Cbr \u002F>\nThis will remove shortlink for the page\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Docs & Support\u003C\u002Fh4>\n\u003Cp>You can find \u003Ca href=\"http:\u002F\u002Fwww.wpshore.com\u002Fplugins\u002Fwp-headcleanup\u002F\" rel=\"nofollow ugc\">docs\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Recommended Plugins\u003C\u002Fh4>\n\u003Cp>The following are other recommended plugins by the author of WP Head Cleanup:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fwww.wpshore.com\u002Fplugins\u002Fcontact-form-7-leads-tracking\u002F\" rel=\"nofollow ugc\">Contact Form 7 Leads Tracking\u003C\u002Fa> – With Contact Form 7 Leads Tracking,you can track the user who has filled the form.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fwww.wpshore.com\u002Fplugins\u002Fwpshore-breadcrumb\u002F\" rel=\"nofollow ugc\">WPshore Breadcrumb\u003C\u002Fa> – With WPshore Breadcrumb, user can see where the current page is in relation to the website’s hierarchy.\u003C\u002Fli>\n\u003C\u002Ful>\n","WP Head Cleanup helps you to remove unnecessary extra links from the page header.",6903,1,"2025-01-21T18:20:00.000Z","4.0.38","3.0",[99,100,79,82],"cleaner","head-cleanup","http:\u002F\u002Fwww.wpshore.com\u002Fplugins","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-head-cleanup.1.0.zip",{"slug":104,"name":105,"version":106,"author":107,"author_profile":108,"description":109,"short_description":110,"active_installs":13,"downloaded":111,"rating":13,"num_ratings":112,"last_updated":113,"tested_up_to":114,"requires_at_least":115,"requires_php":18,"tags":116,"homepage":121,"download_link":122,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"wp-version-in-query-string-modifier","WP Version in Query String Modifier","1.0.0.7","joesat","https:\u002F\u002Fprofiles.wordpress.org\u002Fjoesat\u002F","\u003Cp>Depending on your needs, this plugin is useful for:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>updating the version value to an incrementing number (with a single click) for cache-busting purposes (this is the default value)\u003C\u002Fli>\n\u003Cli>removing the version parameter for optimization purposes\u003C\u002Fli>\n\u003Cli>option to disable modifying the url without disabling the plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The author have dealt with issues when the server is running ATS, Varnish or similar cache utility that the author has no control over. Sometimes cache files stick around for a while and users have no control over caching applications. If you want your css, javascript, image or other asset updates to be reflected instantly, this is the perfect solution for you.\u003C\u002Fp>\n\u003Cp>The plugin has been tested extensively with WP_DEBUG enabled and works seamlessly with multi-site network setup.\u003C\u002Fp>\n\u003Cp>For questions, suggestions or issues with this plugin, visit the plugin support page or contact me at wp [dot] joesat [at] gmail [dot ]com.\u003C\u002Fp>\n","Removes or modifies the version (query string 'ver' parameter) in media resources' url.",3527,4,"2016-07-31T00:04:00.000Z","4.5.33","3.9.3",[21,117,118,119,120],"query-string","remove-query-string","remove-version","version","https:\u002F\u002Fwordpress.org\u002Fplugins\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-version-in-query-string-modifier.1.0.0.7.zip",{"slug":124,"name":125,"version":88,"author":126,"author_profile":127,"description":128,"short_description":129,"active_installs":130,"downloaded":131,"rating":13,"num_ratings":94,"last_updated":132,"tested_up_to":133,"requires_at_least":134,"requires_php":135,"tags":136,"homepage":140,"download_link":141,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"basic-optimization","Basic Optimization","Shah Alom","https:\u002F\u002Fprofiles.wordpress.org\u002Fshahalom\u002F","\u003Cp>Basic Optimization for WordPress plugin help to manage basic optimization like – Disable Emoticons, Remove Shortlink, Disable Embeds, Disable XML-RPC, Hide WordPress Version, etc. Basic Optimization for WordPress plugin is an open source project, made possible by your contribution (code).\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Disable Emoticons\u003C\u002Fstrong> – Remove extra code related to emojis from WordPress which was added recently to support emoticons in an older browser.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove Shortlink.\u003C\u002Fstrong> – Starting from version 3, WordPress added shortlink (shorter link of web page address) in header code. For ex: \u003Ccode>\u003Clink rel='shortlink' href='https:\u002F\u002Fmcqacademy.com\u002F?p=187' \u002F>\u003C\u002Fcode>. If not using shortlink for any functionality then we ned to remove them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove asset files version\u003C\u002Fstrong> – Having query strings in the files may cause CDN not to cache the files; hence you may not be utilizing all caching benefits provided.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove RSD Links\u003C\u002Fstrong> – RSD (Really Simple Discovery) is needed if you intend to use XML-RPC client, pingback, etc. However, if you don’t need pingback or remote client to manage post then get rid of this unnecessary header.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Embeds\u003C\u002Fstrong> – WordPress introduced oEmbed features in 4.4. The function will prevent others from embedding your blog post and disable loading related JS file.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable XML-RPC\u003C\u002Fstrong> – Do you have a requirement to use WordPress API (XML-RPC) to publish\u002Fedit\u002Fdelete a post, edit\u002Flist comments, upload file? Also having XML-RPC enabled and not hardened properly may lead to DDoS & brute force attacks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remove WLManifest Link\u003C\u002Fstrong> – Do you use tagging support with Windows live writer? If not remove it by adding below.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disable Self Pingback\u003C\u002Fstrong> – I don’t know why you need the self-pingback details on your blog post and I know it’s not just I get annoyed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hide WordPress Version\u003C\u002Fstrong> – This doesn’t help in performance but more to mitigate information leakage vulnerability. By default, WordPress adds meta name generator with the version details which is visible in source code and HTTP header.\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Disable Heartbeat\u003C\u002Fstrong> – WordPress use heartbeat API to communicate with a browser to a server by frequently calling admin-ajax.php. This may slow down the overall page load time and increase CPU utilization if on shared hosting.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Support\u003C\u002Fstrong> – Active support through \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FMicro-Solutions-Bangladesh\u002Fbasic-optimization\u002Fissues\" rel=\"nofollow ugc\">GitHub issues page\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Note that Basic Optimization requires PHP 7+ to run.\u003C\u002Fp>\n\u003Cp>Basic Optimization for WordPress is an open source project and I would like to invite anyone to contribute. The development and issue tracker is located on GitHub, see: \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FMicro-Solutions-Bangladesh\u002Fbasic-optimization\" rel=\"nofollow ugc\">https:\u002F\u002Fgithub.com\u002FMicro-Solutions-Bangladesh\u002Fbasic-optimization\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Reporting problems\u003C\u002Fh3>\n\u003Cp>Report bugs, issues, questions and\u002For feature request on our \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FMicro-Solutions-Bangladesh\u002Fbasic-optimization\u002Fissues\" rel=\"nofollow ugc\">GitHub issues page\u003C\u002Fa>.\u003C\u002Fp>\n","Very basic features offering by Basic Optimization for WordPress plugin. Like - Disable Emoticons, Remove Shortlink, Disable Embeds, Disable XML-RPC,  &hellip;",20,1136,"2020-08-12T11:33:00.000Z","5.5.18","5.1","7.0",[124,137,138,139,59],"disable-emoji","remove-css-version","remove-shortlink","https:\u002F\u002Fgithub.com\u002FMicro-Solutions-Bangladesh\u002Fbasic-optimization","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbasic-optimization.zip",{"attackSurface":143,"codeSignals":195,"taintFlows":263,"riskAssessment":289,"analyzedAt":297},{"hooks":144,"ajaxHandlers":183,"restRoutes":191,"shortcodes":192,"cronEvents":193,"entryPointCount":194,"unprotectedCount":194},[145,151,154,156,159,162,168,172,175,180],{"type":146,"name":147,"callback":148,"file":149,"line":150},"action","plugins_loaded","anonymous","includes\\class-wp-head-optimizer.php",125,{"type":146,"name":152,"callback":148,"file":149,"line":153},"admin_enqueue_scripts",140,{"type":146,"name":152,"callback":148,"file":149,"line":155},141,{"type":146,"name":157,"callback":148,"file":149,"line":158},"admin_menu",142,{"type":146,"name":160,"callback":148,"file":149,"line":161},"init",161,{"type":163,"name":164,"callback":165,"file":166,"line":167},"filter","tiny_mce_plugins","disable_wp_emojicons_tinymce","public\\class-wp-head-optimizer-public.php",75,{"type":163,"name":169,"callback":170,"file":166,"line":171},"json_enabled","__return_false",107,{"type":163,"name":173,"callback":170,"file":166,"line":174},"json_jsonp_enabled",108,{"type":163,"name":176,"callback":177,"priority":178,"file":166,"line":179},"style_loader_src","wpho_remove_ver_css_js",9999,114,{"type":163,"name":181,"callback":177,"priority":178,"file":166,"line":182},"script_loader_src",115,[184,188],{"action":185,"nopriv":186,"callback":148,"hasNonce":186,"hasCapCheck":186,"file":149,"line":187},"save_wpho_value",false,143,{"action":185,"nopriv":189,"callback":148,"hasNonce":186,"hasCapCheck":186,"file":149,"line":190},true,144,[],[],[],2,{"dangerousFunctions":196,"sqlUsage":197,"outputEscaping":199,"fileOperations":28,"externalRequests":28,"nonceChecks":94,"capabilityChecks":28,"bundledLibraries":262},[],{"prepared":28,"raw":28,"locations":198},[],{"escaped":28,"rawEcho":200,"locations":201},31,[202,205,208,210,211,213,215,216,218,220,222,224,226,228,230,232,234,236,238,240,242,244,246,248,250,251,253,255,257,258,260],{"file":203,"line":153,"context":204},"admin\\class-wp-head-optimizer-admin.php","raw output",{"file":206,"line":207,"context":204},"admin\\partials\\wp-head-optimizer-admin-display.php",14,{"file":206,"line":209,"context":204},16,{"file":206,"line":130,"context":204},{"file":206,"line":212,"context":204},21,{"file":206,"line":214,"context":204},27,{"file":206,"line":35,"context":204},{"file":206,"line":217,"context":204},33,{"file":206,"line":219,"context":204},35,{"file":206,"line":221,"context":204},38,{"file":206,"line":223,"context":204},40,{"file":206,"line":225,"context":204},43,{"file":206,"line":227,"context":204},45,{"file":206,"line":229,"context":204},48,{"file":206,"line":231,"context":204},50,{"file":206,"line":233,"context":204},53,{"file":206,"line":235,"context":204},55,{"file":206,"line":237,"context":204},58,{"file":206,"line":239,"context":204},60,{"file":206,"line":241,"context":204},63,{"file":206,"line":243,"context":204},65,{"file":206,"line":245,"context":204},68,{"file":206,"line":247,"context":204},70,{"file":206,"line":249,"context":204},73,{"file":206,"line":167,"context":204},{"file":206,"line":252,"context":204},78,{"file":206,"line":254,"context":204},80,{"file":206,"line":256,"context":204},83,{"file":206,"line":27,"context":204},{"file":206,"line":259,"context":204},88,{"file":206,"line":261,"context":204},90,[],[264,281],{"entryPoint":265,"graph":266,"unsanitizedCount":28,"severity":280},"save_wpho_form_data (admin\\class-wp-head-optimizer-admin.php:117)",{"nodes":267,"edges":278},[268,273],{"id":269,"type":270,"label":271,"file":203,"line":272},"n0","source","$_REQUEST",123,{"id":274,"type":275,"label":276,"file":203,"line":272,"wp_function":277},"n1","sink","update_option() [Settings Manipulation]","update_option",[279],{"from":269,"to":274,"sanitized":189},"low",{"entryPoint":282,"graph":283,"unsanitizedCount":28,"severity":280},"\u003Cclass-wp-head-optimizer-admin> (admin\\class-wp-head-optimizer-admin.php:0)",{"nodes":284,"edges":287},[285,286],{"id":269,"type":270,"label":271,"file":203,"line":272},{"id":274,"type":275,"label":276,"file":203,"line":272,"wp_function":277},[288],{"from":269,"to":274,"sanitized":189},{"summary":290,"deductions":291},"The wp-head-optimizer plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not utilizing dangerous functions, performing no file operations, and making no external HTTP requests. It also correctly uses prepared statements for all SQL queries and includes a nonce check, indicating some awareness of security fundamentals.\n\nHowever, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This presents a clear risk as any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure if not properly secured within the handler logic itself. Furthermore, the analysis reveals that 100% of the plugin's outputs are not properly escaped, which is a critical vulnerability. This means that any data displayed to the user that originates from the plugin could be manipulated to include malicious scripts, leading to Cross-Site Scripting (XSS) attacks. The absence of any recorded vulnerabilities in its history is a positive indicator, but it does not negate the risks identified in the current code analysis. A balanced conclusion suggests that while the plugin has avoided known historic vulnerabilities and employs some secure coding practices like prepared statements, the lack of authentication on AJAX endpoints and the universal lack of output escaping create substantial security weaknesses that require immediate attention.",[292,294],{"reason":293,"points":33},"AJAX handlers without authentication",{"reason":295,"points":296},"100% of outputs not properly escaped",8,"2026-03-16T20:04:44.098Z",{"wat":299,"direct":308},{"assetPaths":300,"generatorPatterns":303,"scriptPaths":304,"versionParams":305},[301,302],"\u002Fwp-content\u002Fplugins\u002Fwp-head-optimizer\u002Fadmin\u002Fcss\u002Fwp-head-optimizer-admin.css","\u002Fwp-content\u002Fplugins\u002Fwp-head-optimizer\u002Fadmin\u002Fjs\u002Fwp-head-optimizer-admin.js",[],[],[306,307],"wp-head-optimizer\u002Fadmin\u002Fcss\u002Fwp-head-optimizer-admin.css?ver=","wp-head-optimizer\u002Fadmin\u002Fjs\u002Fwp-head-optimizer-admin.js?ver=",{"cssClasses":309,"htmlComments":310,"htmlAttributes":311,"restEndpoints":313,"jsGlobals":314,"shortcodeOutput":316},[],[],[312],"wpho_nonce",[],[315],"wphoAjax",[]]