Plugin Pulse
← Pulse

W3 Total Cache

by BoldGrid · Performance

Also makes 13 other plugins · 1.1M+ installs across the portfolio →

Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.

How scoring works →
94 Health · A
Maintenance 100/100
Rating quality 86/100
Support 96/100

94 health vs 67 average across 1,076 Performance plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

97 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 88/100
Listing tuning 100/100
Support resolution 94/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

+30% vs prior 30d
12KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

1.2M

now · peak 1.5M

1.19M30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

W3 Total Cache · #71 you LiteSpeed Cache · #5 WP Fastest Cache · #49 Autoptimize · #77

Rating trend

Star average over time · dips mark rough releases

4.4Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.3Kper 1k installs · Aug 26

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 35% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v2.10 35%
v2.9 23%
v2.8 16%
v2.7 5.9%
v2.1 2.2%
Older / other versions 17%

Estimated active installs

The public count shows “900K+”. Our estimate pins where the real number sits.

tracked estimate
900K–1M ≈970K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-04-01 · 1,487 observations

900KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

high confidence

Est. annual revenue

≈$750K range $220K–$2.6M

Est. acquisition value

≈$2.5M range $550K–$12M

A large install base, a clear pro tier and a steady trend. As reliable as an outside estimate gets. The range spans more than 10x because wp.org publishes install counts as broad bands, and conversion and price compound on top. Read the midpoint as an order of magnitude, not a valuation.

How we estimate this

Assumptions

  • Free → paid conversion. 0.5%–2% of active installs pay for the pro tier. Typical for freemium WordPress plugins; the real rate varies a lot by product.
  • Annual price per customer. $49–$129 a year, typical for Performance plugins rather than this plugin's own pricing.
  • Acquisition multiple. 2.5x–4.5x annual revenue, the going range for small WordPress-plugin businesses, stretched a little because downloads are growing.
  • Install base. 900K–1M active installs, from our install estimate (wp.org only publishes the floor).

Inputs

Active installs
900K–1M
Category
Performance
Pro tier
detected (known freemium plugin with a public paid tier)
Download trend
growing (30d downloads up vs prior 30d)
Reviews
5,420
Last updated
7 days ago

Revenue is installs × conversion × price; value is revenue × a typical acquisition multiple. Every factor is an assumption band, so the output is a wide range on purpose. If you're buying or selling, treat this as a starting point for due diligence.

Details

Version
2.10.5
Last updated
7d ago
Added
2009-07-29 · 17 yrs old
Requires WP
6.0
Tested up to
7.1
Requires PHP
7.4

Recent review vibe

read from the latest 12 reviews to 2026-07-13
Mixed Broken updatesSupport gone quietCompatibilityPraise

Recent five-star praise for speed and support sits next to unresolved complaints about a security issue met with deleted comments and updates that broke Redis auth or the JSON API.

Recent reviews

All reviews on wp.org ↗
  1. prolibre
    1mo ago

    An effective plugin with an effective team of developers. / Un plugin efficace avec une équipe de développeur efficace.

    Read on wp.org ↗
  2. OnePressTech
    2mo ago

    Excellent plugin. Been using it for over a decade with no issues except for one release. Very flexible and powerful.

    Read on wp.org ↗
  3. remonoesine
    2mo ago

    After installing W3 Total Cache, I noticed a significant improvement in my website’s loading speed. The plugin offers many optimization options and helped reduce page load times, improving the overall user experience. It took a little time to configure properly, but the results were definitely worth it. If you’re serious about improving your WordPress site’s performance, this plugin is an excellent choice.

    Read on wp.org ↗
  4. theorygeorgiou
    5mo ago

    Worked great for years, I setup redis for page cache and it worked great then one day it will no longer recognize my redis auth (nothing changed) and now I get millions of errors a day making my error logs usesless and changing settings turning off redis, reinstalling the plugin, nothing will stop the errors. This plugin has fucked all our websites that we setup redis for with no communication or acknowledgement from their team.So the plugin works great then you rely on it and get comfortable then after a couple years it breaks your website to try and pressure you to purchase their paid only support. I can’t think of anything more scummy.A.I. search engines, seo, reddit. Anyone looking up this plugin on the internet will see my content warning people about this company going forward. This topic was modified 3 months, 2 weeks ago by theorygeorgiou. This topic was modified 3 months, 2 weeks ago by theorygeorgiou.

    Read on wp.org ↗
  5. weeix
    5mo ago

    I’ve been a long-time user of W3 Total Cache and have generally appreciated its performance benefits over the years. However, my recent experience with version 2.9.3 was quite concerning. After updating, the JSON API stopped working and I was unable to edit content for a while, which disrupted normal operations. I would strongly recommend more thorough testing before releasing updates, especially for critical functionality. Unfortunately, after this experience, I’m hesitant to continue using or recommending the plugin.

    Read on wp.org ↗
  6. Luca
    6mo ago

    A serious security issue was discovered in the plugin two weeks ago, leaving it vulnerable. No updated version has been released yet. Worst of all, they’re deleting comments requesting updates on this issue. This is unprofessional and arrogant behavior, disregarding the needs of thousands of webmasters and customers. Shame on you! This topic was modified 4 months, 2 weeks ago by Luca.

    Read on wp.org ↗
  7. Lenni
    6mo ago

    It’s powerful on it’s own, and almost mandatory. This topic was modified 5 months ago by Lenni. This topic was modified 5 months ago by Lenni.

    Read on wp.org ↗
  8. ashaman112
    6mo ago

    We had been using the free version of the plugin for a while now and were happy with the speed it provided. So we decided to upgrade to the Pro version. We did run into issues with it causing an error on our site, however, after contacting support the issue was resolved. They went into our site and fixed whatever was causing the error. Happy with the result.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 2.10.2 Fix: Disk cache: Restore file-locking writes on PHP 8+ Fix: Apache: Limit Options -MultiViews in page cache rules to compatibility mode Fix: Page Cache: Skip storing redirect responses 2.10.2
  2. Version 2.10.1 Fix: General Settings: “The link you followed has expired” when emptying all caches Fix: Redis/Memcached/CDN: Restore connection handling after 2.10.0 at-rest credential encryption Fix: At-rest credentials: Defer encrypt 2.10.1
  3. Version 2.10.0 Security: Hardened authorization, capability, and request-verification (nonce/CSRF) checks across admin and AJAX endpoints Security: Improved input validation and output escaping to prevent cross-site scripting (XSS) Sec 2.10.0
  4. Version 2.9.4 Fix: Output buffering: Reverted to the previous output buffering from 2.9.1 Fix: Cloudflare: Token/Key validation Fix: Prevent mfunc processing bypass by user-agent 2.9.4
  5. Version 2.9.3 Fix: Output buffering: Discard nested OB contents for non-HTML responses (JSON/AJAX) to prevent HTML prepended to JSON output Fix: Output buffering: Add wp_die_ajax_handler and wp_die_json_handler filters to properly han 2.9.3
  6. Version 2.9.2 Fix: Patch broken access control for Image Service AJAX operations Fix: mfunc dynamic output buffering fatal error causing blank pages Fix: Patch mfunc security vulnerability 2.9.2

Known vulnerabilities

via Wordfence Intelligence

35 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-21 CVE-2026-18051 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 2.10.5 Patched in 2.10.5
  2. 2026-08-13 CVE-2026-18109 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.3 Patched in 2.10.4
  3. 2026-07-31 CVE-2026-66695 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.10.2 Patched in 2.10.3
  4. 2026-07-10 CVE-2026-9282 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.9.4 Patched in 2.10.0
  5. 2026-06-29 CVE-2026-57623 Improper Control of Generation of Code ('Code Injection') Affects <= 2.9.4 Patched in 2.10.0
  6. 2026-04-01 CVE-2026-5032 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.9.3 Patched in 2.9.4
  7. 2026-03-12 CVE-2026-39595 Missing Authorization Affects <= 2.9.1 Patched in 2.9.2
  8. 2026-02-24 CVE-2026-27384 Improper Control of Generation of Code ('Code Injection') Affects <= 2.9.1 Patched in 2.9.2
  9. 2025-10-27 CVE-2025-9501 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Affects <= 2.8.12 Patched in 2.8.13
  10. 2025-01-13 CVE-2024-12365 Missing Authorization Affects <= 2.8.1 Patched in 2.8.2
  11. 2025-01-13 CVE-2024-12006 Missing Authorization Affects <= 2.8.1 Patched in 2.8.2
  12. 2025-01-13 CVE-2024-12008 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.8.1 Patched in 2.8.2
  13. 2024-09-23 CVE-2023-5359 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.7.5 Patched in 2.7.6
  14. 2022-06-20 CVE-2022-31090 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.2.2 Patched in 2.2.3
  15. 2021-06-28 CVE-2021-24436 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.1.4 Patched in 2.1.4
  16. 2021-06-28 CVE-2021-24452 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 0.5 - 2.1.4 Patched in 2.1.5
  17. 2021-06-16 CVE-2021-24427 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.1.3 Patched in 2.1.3
  18. 2020-12-22 CVE-2019-6715 Exposure of Sensitive Information to an Unauthorized Actor Affects 0.9.2.6 - 0.9.3 Patched in 0.9.4
  19. 2020-09-22 CVE-2012-6077 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 0.9.2.4 Patched in 0.9.2.5
  20. 2020-09-22 CVE-2012-6079 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 0.9.2.4 Patched in 0.9.2.5
  21. 2020-09-22 CVE-2012-6078 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 0.9.2.4 Patched in 0.9.2.5
  22. 2019-05-22 Server-Side Request Forgery (SSRF) Affects <= 0.9.7.3 Patched in 0.9.7.4
  23. 2019-05-07 Improper Input Validation Affects <= 0.9.7.3 Patched in 0.9.7.4
  24. 2019-05-07 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.9.7.3 Patched in 0.9.7.4
  25. 2016-11-10 Improper Input Validation Affects <= 0.9.4.1 Patched in 0.9.5
  26. 2016-10-31 Server-Side Request Forgery (SSRF) Affects <= 0.9.4 Patched in 0.9.5
  27. 2016-09-26 Authentication Bypass by Primary Weakness Affects <= 0.9.4.1 Patched in 0.9.5
  28. 2016-09-26 Unrestricted Upload of File with Dangerous Type Affects <= 0.9.4.1 Patched in 0.9.5
  29. 2016-09-26 Affects <= 0.9.4.1 Patched in 0.9.5
  30. 2016-09-26 Improper Control of Generation of Code ('Code Injection') Affects <= 0.9.4.1 Patched in 0.9.5
  31. 2016-07-29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.9.4.1 Patched in 0.9.5
  32. 2014-12-16 CVE-2014-8724 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 0.9.4 Patched in 0.9.4.1
  33. 2014-12-10 CVE-2014-9414 Cross-Site Request Forgery (CSRF) Affects <= 0.9.4 Patched in 0.9.4.1
  34. 2014-09-08 Cross-Site Request Forgery (CSRF) Affects <= 0.9.4 Patched in 0.9.4.1
  35. 2014-08-01 CVE-2013-2010 Improper Control of Generation of Code ('Code Injection') Affects <= 0.9.2.8 Patched in 0.9.2.9

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 61 languages, 10 at 90% or more

Dutch 100%
Dutch (Formal) 100%
English (UK) 100%
Persian 100%
Russian 100%
Spanish (Argentina) 100%
Spanish (Chile) 100%
Spanish (Spain) 100%
Lao 99%
Korean 92%
Chinese (China) 71%
Japanese 64%
German 60%
Ukrainian 58%
Romanian 43%
English (South Africa) 42%
French (France) 42%
Spanish (Colombia) 38%
Spanish (Ecuador) 38%
Spanish (Venezuela) 38%
Swedish 35%
German (Formal) 30%
Bosnian 25%
Croatian 25%

Plus 37 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-02-10 1M+ → 900K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for W3 Total Cache into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/w3-total-cache" width="480" height="300" style="border:0" loading="lazy" title="W3 Total Cache — Plugin Pulse"></iframe>
Preview card ↗

W3 Total Cache: 900K+ active installs, 4.4★ (5,420 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/w3-total-cache