W3 Total Cache
by BoldGrid · Performance
Also makes 13 other plugins · 1.1M+ installs across the portfolio →
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
94 health vs 67 average across 1,076 Performance plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
1.2M
now · peak 1.5M
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 35% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “900K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-04-01 · 1,487 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
A large install base, a clear pro tier and a steady trend. As reliable as an outside estimate gets. The range spans more than 10x because wp.org publishes install counts as broad bands, and conversion and price compound on top. Read the midpoint as an order of magnitude, not a valuation.
How we estimate this
Assumptions
- Free → paid conversion. 0.5%–2% of active installs pay for the pro tier. Typical for freemium WordPress plugins; the real rate varies a lot by product.
- Annual price per customer. $49–$129 a year, typical for Performance plugins rather than this plugin's own pricing.
- Acquisition multiple. 2.5x–4.5x annual revenue, the going range for small WordPress-plugin businesses, stretched a little because downloads are growing.
- Install base. 900K–1M active installs, from our install estimate (wp.org only publishes the floor).
Inputs
- Active installs
- 900K–1M
- Category
- Performance
- Pro tier
- detected (known freemium plugin with a public paid tier)
- Download trend
- growing (30d downloads up vs prior 30d)
- Reviews
- 5,420
- Last updated
- 7 days ago
Revenue is installs × conversion × price; value is revenue × a typical acquisition multiple. Every factor is an assumption band, so the output is a wide range on purpose. If you're buying or selling, treat this as a starting point for due diligence.
Details
Recent review vibe
read from the latest 12 reviews to 2026-07-13Recent five-star praise for speed and support sits next to unresolved complaints about a security issue met with deleted comments and updates that broke Redis auth or the JSON API.
Recent reviews
All reviews on wp.org ↗- ★★★★★ prolibre1mo ago
An effective plugin with an effective team of developers. / Un plugin efficace avec une équipe de développeur efficace.
Read on wp.org ↗ - ★★★★★ OnePressTech2mo ago
Excellent plugin. Been using it for over a decade with no issues except for one release. Very flexible and powerful.
Read on wp.org ↗ - ★★★★★ remonoesine2mo ago
After installing W3 Total Cache, I noticed a significant improvement in my website’s loading speed. The plugin offers many optimization options and helped reduce page load times, improving the overall user experience. It took a little time to configure properly, but the results were definitely worth it. If you’re serious about improving your WordPress site’s performance, this plugin is an excellent choice.
Read on wp.org ↗ - ★★★★★ theorygeorgiou5mo ago
Worked great for years, I setup redis for page cache and it worked great then one day it will no longer recognize my redis auth (nothing changed) and now I get millions of errors a day making my error logs usesless and changing settings turning off redis, reinstalling the plugin, nothing will stop the errors. This plugin has fucked all our websites that we setup redis for with no communication or acknowledgement from their team.So the plugin works great then you rely on it and get comfortable then after a couple years it breaks your website to try and pressure you to purchase their paid only support. I can’t think of anything more scummy.A.I. search engines, seo, reddit. Anyone looking up this plugin on the internet will see my content warning people about this company going forward. This topic was modified 3 months, 2 weeks ago by theorygeorgiou. This topic was modified 3 months, 2 weeks ago by theorygeorgiou.
Read on wp.org ↗ - ★★★★★ weeix5mo ago
I’ve been a long-time user of W3 Total Cache and have generally appreciated its performance benefits over the years. However, my recent experience with version 2.9.3 was quite concerning. After updating, the JSON API stopped working and I was unable to edit content for a while, which disrupted normal operations. I would strongly recommend more thorough testing before releasing updates, especially for critical functionality. Unfortunately, after this experience, I’m hesitant to continue using or recommending the plugin.
Read on wp.org ↗ - ★★★★★ Luca6mo ago
A serious security issue was discovered in the plugin two weeks ago, leaving it vulnerable. No updated version has been released yet. Worst of all, they’re deleting comments requesting updates on this issue. This is unprofessional and arrogant behavior, disregarding the needs of thousands of webmasters and customers. Shame on you! This topic was modified 4 months, 2 weeks ago by Luca.
Read on wp.org ↗ - ★★★★★ Lenni6mo ago
It’s powerful on it’s own, and almost mandatory. This topic was modified 5 months ago by Lenni. This topic was modified 5 months ago by Lenni.
Read on wp.org ↗ - ★★★★★ ashaman1126mo ago
We had been using the free version of the plugin for a while now and were happy with the speed it provided. So we decided to upgrade to the Pro version. We did run into issues with it causing an error on our site, however, after contacting support the issue was resolved. They went into our site and fixed whatever was causing the error. Happy with the result.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 2.10.2 Fix: Disk cache: Restore file-locking writes on PHP 8+ Fix: Apache: Limit Options -MultiViews in page cache rules to compatibility mode Fix: Page Cache: Skip storing redirect responses 2.10.2
- — Version 2.10.1 Fix: General Settings: “The link you followed has expired” when emptying all caches Fix: Redis/Memcached/CDN: Restore connection handling after 2.10.0 at-rest credential encryption Fix: At-rest credentials: Defer encrypt 2.10.1
- — Version 2.10.0 Security: Hardened authorization, capability, and request-verification (nonce/CSRF) checks across admin and AJAX endpoints Security: Improved input validation and output escaping to prevent cross-site scripting (XSS) Sec 2.10.0
- — Version 2.9.4 Fix: Output buffering: Reverted to the previous output buffering from 2.9.1 Fix: Cloudflare: Token/Key validation Fix: Prevent mfunc processing bypass by user-agent 2.9.4
- — Version 2.9.3 Fix: Output buffering: Discard nested OB contents for non-HTML responses (JSON/AJAX) to prevent HTML prepended to JSON output Fix: Output buffering: Add wp_die_ajax_handler and wp_die_json_handler filters to properly han 2.9.3
- — Version 2.9.2 Fix: Patch broken access control for Image Service AJAX operations Fix: mfunc dynamic output buffering fatal error causing blank pages Fix: Patch mfunc security vulnerability 2.9.2
Known vulnerabilities
via Wordfence Intelligence35 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-21 CVE-2026-18051 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 2.10.5 Patched in 2.10.5
- High · 7.2 W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name ↗2026-08-13 CVE-2026-18109 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.3 Patched in 2.10.4
- 2026-07-31 CVE-2026-66695 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.10.2 Patched in 2.10.3
- High · 7.5 W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter ↗2026-07-10 CVE-2026-9282 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.9.4 Patched in 2.10.0
- 2026-06-29 CVE-2026-57623 Improper Control of Generation of Code ('Code Injection') Affects <= 2.9.4 Patched in 2.10.0
- High · 7.5 W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header ↗2026-04-01 CVE-2026-5032 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.9.3 Patched in 2.9.4
- Medium · 4.3 W3 Total Cache <= 2.9.1 - Missing Authorization ↗
- 2026-02-24 CVE-2026-27384 Improper Control of Generation of Code ('Code Injection') Affects <= 2.9.1 Patched in 2.9.2
- 2025-10-27 CVE-2025-9501 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Affects <= 2.8.12 Patched in 2.8.13
- 2025-01-13 CVE-2024-12008 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.8.1 Patched in 2.8.2
- 2024-09-23 CVE-2023-5359 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.7.5 Patched in 2.7.6
- 2022-06-20 CVE-2022-31090 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.2.2 Patched in 2.2.3
- 2021-06-28 CVE-2021-24436 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.1.4 Patched in 2.1.4
- 2021-06-28 CVE-2021-24452 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 0.5 - 2.1.4 Patched in 2.1.5
- 2021-06-16 CVE-2021-24427 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.1.3 Patched in 2.1.3
- 2020-12-22 CVE-2019-6715 Exposure of Sensitive Information to an Unauthorized Actor Affects 0.9.2.6 - 0.9.3 Patched in 0.9.4
- 2020-09-22 CVE-2012-6077 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 0.9.2.4 Patched in 0.9.2.5
- 2020-09-22 CVE-2012-6079 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 0.9.2.4 Patched in 0.9.2.5
- 2020-09-22 CVE-2012-6078 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 0.9.2.4 Patched in 0.9.2.5
- 2019-05-22 Server-Side Request Forgery (SSRF) Affects <= 0.9.7.3 Patched in 0.9.7.4
- 2019-05-07 Improper Input Validation Affects <= 0.9.7.3 Patched in 0.9.7.4
- 2019-05-07 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.9.7.3 Patched in 0.9.7.4
- 2016-11-10 Improper Input Validation Affects <= 0.9.4.1 Patched in 0.9.5
- High · 8.6 W3 Total Cache <= 0.9.4 - Server-Side Request Forgery leading to Host Information Disclosure ↗2016-10-31 Server-Side Request Forgery (SSRF) Affects <= 0.9.4 Patched in 0.9.5
- 2016-09-26 Authentication Bypass by Primary Weakness Affects <= 0.9.4.1 Patched in 0.9.5
- 2016-09-26 Unrestricted Upload of File with Dangerous Type Affects <= 0.9.4.1 Patched in 0.9.5
- 2016-09-26 Affects <= 0.9.4.1 Patched in 0.9.5
- 2016-09-26 Improper Control of Generation of Code ('Code Injection') Affects <= 0.9.4.1 Patched in 0.9.5
- 2016-07-29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.9.4.1 Patched in 0.9.5
- Medium · 5.4 W3 Total Cache <= 0.9.4 - Cross-Site Scripting ↗2014-12-16 CVE-2014-8724 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.9.4 Patched in 0.9.4.1
- High · 8.8 W3 Total Cache <= 0.9.4 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting ↗2014-09-08 Cross-Site Request Forgery (CSRF) Affects <= 0.9.4 Patched in 0.9.4.1
- Critical · 9.8 W3 Total Cache <= 0.9.2.8 - Remote Code Execution ↗2014-08-01 CVE-2013-2010 Improper Control of Generation of Code ('Code Injection') Affects <= 0.9.2.8 Patched in 0.9.2.9
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 61 languages, 10 at 90% or more
Plus 37 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-02-10 1M+ → 900K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
LiteSpeed Cache 7M+ installs · 4.8★ · 4 shared tags A -
WP Fastest Cache – WordPress Cache Plugin 1M+ installs · 4.9★ · 3 shared tags B -
Autoptimize 800K+ installs · 4.7★ · 3 shared tags A -
Breeze Cache 300K+ installs · 3.6★ · 3 shared tags B -
Aruba HiSpeed Cache 100K+ installs · 3.5★ · 3 shared tags B
-
10Web Booster – Website speed optimization, Cache & Page Speed optimizer 70K+ installs · 4.6★ · 3 shared tags B
Embed this report card
Drop a live Pulse card for W3 Total Cache into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/w3-total-cache" width="480" height="300" style="border:0" loading="lazy" title="W3 Total Cache — Plugin Pulse"></iframe> W3 Total Cache: 900K+ active installs, 4.4★ (5,420 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/w3-total-cache