PLUGIN SECURITY

Is Autoptimize safe?

Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.

What this plugin does

  • Slug: autoptimize
  • Author: Optimizing Matters
  • 800000+ active installs
  • 94/100 rating (1428 reviews on wordpress.org)
  • 44178600 all-time downloads
  • On WordPress.org since 2009-07-09

core web vitalsimagesOptimizepagespeedperformance

Maintenance status

  • Latest known version: 3.1.15.1
  • Last updated: 2026-08-20 7:09pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.1+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

12 known CVEs on file for Autoptimize.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-3220 Autoptimize [autoptimize] < 3.1.15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.1.15 3.1.15 2026-04-27 ✓ fixed in latest
CVE-2025-13401 Autoptimize [autoptimize] < 3.1.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.1.14 3.1.14 2025-12-03 ✓ fixed in latest
CVE-2023-2113 Autoptimize [autoptimize] < 3.1.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.1.7 3.1.7 2023-04-25 ✓ fixed in latest
Autoptimize [autoptimize] < 3.1.7 Unknown < 3.1.7 3.1.7 2023-04-23 ✓ fixed in latest
CVE-2022-4057 Autoptimize [autoptimize] < 3.1.0 Direct Request ('Forced Browsing') Medium 5.3 < 3.1.0 3.1.0 2022-12-05 ✓ fixed in latest
CVE-2022-2635 Autoptimize [autoptimize] < 3.1.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.1.1 3.1.1 2022-07-19 ✓ fixed in latest
CVE-2021-24332 Autoptimize [autoptimize] < 2.8.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.8.4 2.8.4 2021-05-07 ✓ fixed in latest
Autoptimize [autoptimize] < 2.8.4 Unknown < 2.8.4 2.8.4 2021-05-04 ✓ fixed in latest
+ 10 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24378 Autoptimize [autoptimize] < 2.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.7.8 2.7.8 2020-10-09 ✓ fixed in latest
CVE-2021-24376 Autoptimize [autoptimize] < 2.7.8 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 2.7.8 2.7.8 2020-10-09 ✓ fixed in latest
CVE-2021-24377 Autoptimize [autoptimize] < 2.7.8 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') High 8.1 < 2.7.8 2.7.8 2020-10-09 ✓ fixed in latest
CVE-2020-24948 Autoptimize [autoptimize] < 2.7.7 Unrestricted Upload of File with Dangerous Type High 7.2 < 2.7.7 2.7.7 2020-08-24 ✓ fixed in latest
Autoptimize [autoptimize] < 2.1.1 Unknown < 2.1.1 2.1.1 2017-06-19 ✓ fixed in latest
Autoptimize [autoptimize] < 3.1.15 Unknown < 3.1.15 3.1.15 0000-00-00 ✓ fixed in latest
Autoptimize [autoptimize] < 3.1.15 Unknown < 3.1.15 3.1.15 0000-00-00 ✓ fixed in latest
Autoptimize [autoptimize] < 3.1.0 Unknown < 3.1.0 3.1.0 ✓ fixed in latest
CVE-2026-2352 Autoptimize < 3.1.15 - Contributor+ Stored XSS via 'ao_post_preload' Meta Value Unknown < 3.1.15 3.1.15 ✓ fixed in latest
CVE-2026-2430 Autoptimize < 3.1.15 - Contributor+ Stored XSS via Lazy-loaded Image Attributes Unknown < 3.1.15 3.1.15 ✓ fixed in latest

How to fix it

Keep Autoptimize updated — 3.1.15.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.