
WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript Security & Risk Analysis
wordpress.org/plugins/wp-super-minifyA lightweight plugin that automatically minifies, compresses, and caches HTML, CSS, and JavaScript on demand to improve your website’s load speed.
Is WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript Safe to Use in 2026?
Generally Safe
Score 100/100WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-super-minify" plugin version 2.0.1 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by having no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks. Furthermore, all SQL queries utilize prepared statements, and a nonce check is present, indicating an awareness of common WordPress security vulnerabilities.
However, several concerns are flagged by the static analysis. The presence of a 'dangerous function' (preg_replace(/e)) is a notable risk, as this pattern can be exploited for remote code execution if not handled with extreme care and input validation. The low percentage of properly escaped output (22%) is also a significant weakness, suggesting a high potential for Cross-Site Scripting (XSS) vulnerabilities across various output points.
The plugin's vulnerability history shows one known CVE, which is thankfully patched, and the common vulnerability type being Cross-Site Request Forgery (CSRF). While there are no currently unpatched critical or high vulnerabilities, the history of CSRF and the static analysis concerns suggest that while the entry points are well-secured, the internal handling of data and output might not be as robust. The conclusion is that while the plugin has a small attack surface and secures its entry points well, the risk of XSS due to poor output escaping and the presence of a dangerous function warrant careful attention and potential remediation.
Key Concerns
- Dangerous function detected (preg_replace(/e))
- Low percentage of properly escaped output (22%)
- Bundled outdated library (jQuery v1.12.4)
- One known CVE in history
WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Super Minify <= 1.5.1 - Cross-Site Request Forgery via 'wpsmy_admin_options'
WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript Attack Surface
WordPress Hooks 10
Maintenance & Trust
WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript Maintenance & Trust
Maintenance Signals
Community Trust
WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript Alternatives
WP Minify Fix
wp-minify-fix
[Fixed] This plugin uses the Minify engine to combine and compress JS and CSS files to improve page load time.
WP Easy Tools Compression
wp-easy-tools-compression
dietIMAGE uses smart lossy compression techniques to reduce the file size of your PNG files. By selectively decreasing the number of colours in the im …
WP Fast Minify
wp-inline-js-converter
Compress HTML Code, And Converting Inline Script and Style To JavaScript and CSS Compressed File.
Asset CleanUp: Page Speed Booster
wp-asset-clean-up
Make your website load FASTER by stopping specific styles (.CSS) & scripts (.JS) from loading. It works best with a page caching plugin / service.
Minify HTML
minify-html-markup
Minify HTML output for clean looking markup and faster downloading.
WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript Developer Profile
4 plugins · 19K total installs
How We Detect WP Super Minify • Minify, Compress and Cache HTML, CSS & JavaScript
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-super-minify/assets/css/style.min.cssHTML / DOM Fingerprints
wpsmy_settingsname="wpsmy_combine_js"id="wpsmy_combine_js"name="wpsmy_combine_css"id="wpsmy_combine_css"name="wpsmy_clear_minified"