Autoptimize
by Optimizing Matters · Performance
Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.
90 health vs 67 average across 1,076 Performance plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
85.2K
now · peak 895.4K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Occasionally updatedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
3
releases in the last 12 months
5mo ago
latest release · v3.1.15.1
106
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 87% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “800K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-01 · 1,491 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 3.1.15.1 fix for “Uncaught Error: Using $this when not in object context” when preloads are set 3.1.15.1
- — Version 3.1.15 also add fetchpriority=high to preload set on Extra tab improve exit survey display in RTL languages security enhancements for 2 authenticated stored XSS issues responsibly reported by stealhcopter and bashu multiple min 3.1.15
- — Version 3.1.14 improve HTML output for let the 404-handler issue a 302 iso 301 HTTP response (as mentioned by thefitrv) small improvement in critical CSS cron job handling in case of an empty “time limit” (thanks for the help Jason) fi 3.1.14
- — Version 3.1.13 multiple minor changes/ improvements/ bugfixes, see the GitHub commit log . 3.1.13
- — Version 3.1.12 image optimization: improvements to the favicon regex javascript optimization: integrate most recent version of jsmin.php critical CSS: improve blocklist (url/ paths that should not be added to the job queue) some other 3.1.12
- — Version 3.1.11 code quality improvements see the GitHub commit log . some other minor changes/ improvements/ filters, see the GitHub commit log . 3.1.11
Known vulnerabilities
via Wordfence Intelligence13 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-04-27 CVE-2026-3220 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.1.15 Patched in 3.1.15
- Medium · 6.4 Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ao_post_preload' Meta Value ↗2026-03-20 CVE-2026-2352 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.14 Patched in 3.1.15
- Medium · 6.4 Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy-loaded Image Attributes ↗2026-03-20 CVE-2026-2430 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.14 Patched in 3.1.15
- 2025-12-03 CVE-2025-13401 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.13 Patched in 3.1.14
- Medium · 4.4 Autoptimize <= 3.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting via Critical CSS Rules ↗2023-04-25 CVE-2023-2113 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.6 Patched in 3.1.7
- 2022-12-05 CVE-2022-4057 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.0.4 Patched in 3.1.0
- Medium · 5.5 Autoptimize <= 3.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting via Critical CSS Settings ↗2022-07-19 CVE-2022-2635 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.0 Patched in 3.1.1
- Medium · 5.5 Autoptimize <= 2.8.3 - Stored Cross-Site Scripting ↗2021-05-07 CVE-2021-24332 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.8.4 Patched in 2.8.4
- Critical · 9.8 Autoptimize <= 2.7.7 - Arbitrary File Upload (and Remote Code Execution) via Import Settings ↗2020-10-09 CVE-2021-24376 Unrestricted Upload of File with Dangerous Type Affects < 2.7.8 Patched in 2.7.8
- 2020-10-09 CVE-2021-24378 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.7.8 Patched in 2.7.8
- 2020-10-09 CVE-2021-24377 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Affects < 2.7.8 Patched in 2.7.8
- 2020-08-24 CVE-2020-24948 Unrestricted Upload of File with Dangerous Type Affects <= 2.7.6 Patched in 2.7.7
- 2017-06-19 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 2.1.0 Patched in 2.1.1
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 60 languages, 19 at 90% or more
Plus 36 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-06-19 900K+ → 800K+ down after 273 days in tier
- 2025-09-19 1M+ → 900K+ down after 10 days in tier
- 2025-09-09 900K+ → 1M+ up after 4 days in tier
- 2025-09-05 1M+ → 900K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
WP Fastest Cache – WordPress Cache Plugin 1M+ installs · 4.9★ · 4 shared tags B -
AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization 2K+ installs · 3.5★ · 4 shared tags B -
LiteSpeed Cache 7M+ installs · 4.8★ · 3 shared tags A -
W3 Total Cache 900K+ installs · 4.4★ · 3 shared tags A -
Aruba HiSpeed Cache 100K+ installs · 3.5★ · 3 shared tags B
-
10Web Booster – Website speed optimization, Cache & Page Speed optimizer 70K+ installs · 4.6★ · 3 shared tags B
Embed this report card
Drop a live Pulse card for Autoptimize into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/autoptimize" width="480" height="300" style="border:0" loading="lazy" title="Autoptimize — Plugin Pulse"></iframe> Autoptimize: 800K+ active installs, 4.7★ (1,428 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/autoptimize