Total Findings
51
Security Grade
Coding Score
100/100
Oiko Boost is a well-engineered performance plugin that follows most WordPress security best practices including proper nonce verification, capability checks, and input sanitization through a centralized Sanitizer class. Two significant vulnerabilities were identified: a stored XSS vulnerability through the lazy-loading CSS background-image feature and an arbitrary file write risk in the Local Fonts module under a compromised CDN scenario. The codebase is modern, uses PHP 8.3 features appropriately, and shows a high level of craftsmanship.
Show your audit status in your README or website.
[](https://wphealthkit.com/directory/oiko-boost)
Paste this in your GitHub README or any Markdown file. The badge updates automatically on every re-audit — no need to refresh the snippet.
Claim this listing to get a Verified badge, control public audits, and get automatic re-scans.
Claim This PluginGet a comprehensive security audit for your WordPress plugin or theme. Upload your zip and get results in minutes.
Start Free Audit