Subresource Integrity (SRI) Manager
by Meitar · Security
Also makes 13 other plugins · 1.4K+ installs across the portfolio →
Adds Subresource Integrity (SRI) attributes to your page's elements for better protection against JavaScript DDoS attacks.
40 health vs 64 average across 997 Security plugins
Removal-risk signals
53/100Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.
- Long abandoned. No update in 5+ years — the top precursor to removal once a vulnerability is found.
- Falling behind WordPress. Tested up to WordPress 5.6.19.
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Under-optimized
Biggest win: Update recency
To rank higher: Last updated 2095 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
202
now · peak 440
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 100% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “900+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2016-04-27 · 1,425 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ Kevin de Bie2.1y ago
Plugin doesn’t appear to do anything/work on any of my WordPress 6 installations.I have been testing with Mozzilla’s observatory. This topic was modified 2 years ago by Kevin de Bie. Reason: Clarification This topic was modified 2 years ago by Kevin de Bie.
Read on wp.org ↗ - ★★★★★ darkknight833.0y ago
in the age of page-caching (wp-super-cache) and minification/consolidation of scripts/styles (autoptimization), this probably needs to be hooked in after all that gets done otherwise the hash generated won’t match. Ideally, this tests the consolidated minimized script locally even before it gets uploaded to the CDN to cover the pathological case that the script gets mutated at the CDN even before it gets it’s SHA hash done.
Read on wp.org ↗ - ★★★★★ apollosk4.9y ago
The plugin works as advertised, out of the box. Kudos to the developers. It would be smart to update the compatibility info, Tested up to:…
Read on wp.org ↗ - ★★★★★ forkenbrock5.6y ago
Plugin caused my BrainTree payment gateway to fail payments.
Read on wp.org ↗ - ★★★★★ techguysa5.9y ago
Using the Plug in Yoco Payment Gateway by Yoco for credit cards and this plug in prevents Yoco from poping up and then redirects to the confirm order page like if it was an EFT when customer make payment via card. This prevents card payments. So I disabled it. This worked but im not sacrificing a function to kill revenue. There must be another way had another way just cant remember what the htaccess code was for this. This topic was modified 5 years, 9 months ago by techguysa. Reason: Author Rude
Read on wp.org ↗ - ★★★★★ kiranrs6.1y ago
I appreciate your effort for making this plugin, really helpful. But not working for all external scripts.Still you’re my hero. This topic was modified 5 years, 11 months ago by kiranrs.
Read on wp.org ↗ - ★★★★★ Kenny Moore6.3y ago
I am confident your advice … Ensure your assets (scripts, stylesheets) were added using the WordPress API hooks, such as wp_enqueue_script(), and so on. … is sound. It is just a bit beyond my skill set/comfort level. This reflects my limitations, not the plugin. The SRI thing badly needs a solution that dunderhead WP users like myself can implement, and you seem to be the only one trying to address it. So, good for you. Much appreciated. I’ll do some learning and muster my courage and perhaps try again.
Read on wp.org ↗ - ★★★★★ vedmant6.9y ago
For my installation it added integrity only on one resource, a font css from googleapis.com, but site has tons of other resources loaded from googletagmanager.com, uberflip.com, leadspace.com and so on.
Read on wp.org ↗
Known vulnerabilities
via Wordfence Intelligence1 disclosed vulnerability on record for this plugin, 1 still affects the current version.
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 7.4.8 · WP 5.5.3
Languages
via translate.wordpress.orgTranslated into 132 languages, 1 at 90% or more · development strings
Plus 108 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-05-28 1K+ → 900+ down after 2 days in tier
- 2026-05-26 900+ → 1K+ up after 1 days in tier
- 2026-05-25 1K+ → 900+ down after 2 days in tier
- 2026-05-23 900+ → 1K+ up after 1 days in tier
- 2026-05-22 1K+ → 900+ down after 3 days in tier
- 2026-05-19 900+ → 1K+ up after 1 days in tier
- 2026-05-18 1K+ → 900+ down after 818 days in tier
- 2024-02-20 900+ → 1K+ up after 1 days in tier
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Auto SRI 500+ installs · 3.6★ · 2 shared tags B -
Wordfence Security – Firewall, Malware Scan, and Login Security 5M+ installs · 4.7★ · 1 shared tag A
-
Hostinger Tools 3M+ installs · 3.6★ · 1 shared tag B
-
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) 3M+ installs · 4.9★ · 1 shared tag A -
Jetpack – WP Security, Backup, Speed, & Growth 3M+ installs · 3.8★ · 1 shared tag A
-
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention 1M+ installs · 4.8★ · 1 shared tag A
Embed this report card
Drop a live Pulse card for Subresource Integrity (SRI) Manager into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wp-sri" width="480" height="300" style="border:0" loading="lazy" title="Subresource Integrity (SRI) Manager — Plugin Pulse"></iframe> Subresource Integrity (SRI) Manager: 900+ active installs, 2.9★ (11 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/wp-sri