
WP Performance Security & Risk Analysis
wordpress.org/plugins/wp-performanceWP Performance is a cache & performance plugin which makes optimizing your site really easy.
Is WP Performance Safe to Use in 2026?
Generally Safe
Score 85/100WP Performance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-performance' plugin v1.1.8.3 presents a mixed security posture. While the absence of known CVEs and a lack of critical or high severity issues in taint analysis are positive indicators, significant concerns arise from the static analysis. The plugin exposes a substantial attack surface with 9 AJAX handlers, a concerning 7 of which lack proper authentication checks. This is a major weakness that could allow unauthorized users to trigger plugin functionality. Furthermore, the low percentage of properly escaped output (5%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities across various output points. The limited number of capability checks (2) and the high proportion of SQL queries not using prepared statements (73%) also indicate potential for SQL injection and privilege escalation vulnerabilities. The plugin's history of no recorded vulnerabilities might suggest it has not been extensively targeted or analyzed, rather than being inherently secure given the identified code signals.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping percentage
- SQL queries without prepared statements
- Low capability checks
- Unsanitized paths in taint analysis
WP Performance Security Vulnerabilities
WP Performance Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Performance Attack Surface
AJAX Handlers 9
WordPress Hooks 57
Scheduled Events 3
Maintenance & Trust
WP Performance Maintenance & Trust
Maintenance Signals
Community Trust
WP Performance Alternatives
JCH Optimize
jch-optimize
This plugin automatically performs several front end optimizations to your site to boost performance and increase PageSpeed scores.
WPSpeed – WordPress Speed, Cache & Performance Optimization (Core Web Vitals, PageSpeed 100)
wpspeed
WordPress speed optimization plugin to boost PageSpeed, improve Core Web Vitals, reduce TTFB and enable static HTML caching for 100/100 performance.
URLsLab
urlslab
Boost SEO and performance with minimal effort.
Cacheability
cacheability
HTTP optimization for WordPress. Fixes soft 404 errors and adds smart cache headers.
WP Blast | SEO & Performance Booster
wpblast
Improve your Wordpress SEO and performance by using dynamic rendering. Prerender your website and generate an easy-to-crawl version of your website.
WP Performance Developer Profile
1 plugin · 200 total installs
How We Detect WP Performance
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-performance/assets/css/wpp-styles.css/wp-content/plugins/wp-performance/assets/js/wpp-scripts.js/wp-content/plugins/wp-performance/includes/addons/cloudflare/assets/cloudflare.js/wp-content/plugins/wp-performance/assets/js/wpp-scripts.js/wp-content/plugins/wp-performance/includes/addons/cloudflare/assets/cloudflare.jswp-performance/assets/css/wpp-styles.css?ver=wp-performance/assets/js/wpp-scripts.js?ver=wp-performance/includes/addons/cloudflare/assets/cloudflare.js?ver=HTML / DOM Fingerprints
wpp-settings-menuwpp-addon-settings<!-- WP Performance --><!-- WP Performance - Cloudflare add-on -->data-wpp-actiondata-wpp-noncedata-wpp-targetWPP_URIWPP_ASSET_URLWPP_ADDONS_URL