PLUGIN SECURITY

Is Jetpack Boost safe?

Speed up your WordPress site with one-click optimizations like Page Cache, Critical CSS, and Image CDN to improve Core Web Vitals.

What this plugin does

  • Slug: jetpack-boost
  • Author: Automattic
  • 200000+ active installs
  • 94/100 rating (607 reviews on wordpress.org)
  • 13496251 all-time downloads
  • On WordPress.org since 2020-12-31

cacheCritical CSSperformancespeedweb vitals

Maintenance status

  • Last updated: 2026-08-17 1:20pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.2+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

1 known CVE on file for Jetpack Boost.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10076 Jetpack Boost – Website Speed, Performance and Critical CSS [jetpack-boost] < 3.4.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 3.4.8 3.4.8 2024-10-17
Jetpack Boost – Website Speed, Performance and Critical CSS [jetpack-boost] < 3.4.7 Server-Side Request Forgery (SSRF) Critical 9.1 < 3.4.7 3.4.7 0000-00-00

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.