shouldiuse.io

VERDICT

Should I use NitroPack?

NitroPack's the leading site speed and performance service that helps you pass Core Web Vitals, achieve a 90+ PageSpeed score, and increase revenue. - nitropack.io

Depends. Buy NitroPack if you run a WordPress or WooCommerce site and want Core Web Vitals fixed without a developer. Skip it if you need transparent billing, fine-grained control, or a clean security record.

Confidence

Medium. Based on ~45 public sources: G2, Trustpilot, Reddit threads, CVE databases, and vendor pages. Several snippets were truncated, so some pricing and review details are incomplete.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$7/mo

Starter

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Plus / Pro / AgencyPaid tiers above Starter

Best for

  • Non-technical WordPress owners
  • WooCommerce stores chasing Core Web Vitals
  • Agencies managing many client sites
  • Page-builder sites (Elementor, WPBakery)

Not for

  • Developers needing fine-grained script control
  • Tiny sites — free caching plugins and Cloudflare suffice
  • Anyone wary of usage-based billing surprises
  • High-security sites tracking plugin CVEs

Gotchas - check before you buy

high

Pricing page reportedly hides limits; users hit surprise overage and upgrade charges

high

Multiple auth bypass CVEs disclosed; keep the plugin updated or reconsider

medium

Score gains come from deferred loading; verify real-user metrics, not just Lighthouse

medium

Exclusion settings don't always work; complex or customized sites may break

Pros and cons

Pros

  • Users say it beats every performance plugin they tried
  • Users report clear speed boosts on real sites
  • Bundles caching, CDN, and image optimization in one service
  • Reviewed as strong for agencies running many client sites
  • Non-developers install and manage it without coding

Cons

  • Users report unexpected charges beyond advertised pricing
  • Multiple auth bypass CVEs in the WordPress plugin
  • Critics say it games PageSpeed tests rather than real speed
  • Resource exclusions sometimes ignored, limiting control
  • Reported stripping security headers from responses

Sources & method

Analyzed 9/21/2026 - 14 sources - Multiple WordPress plugin vulnerabilities disclosed, including auth bypasses; vendor publishes a DPA and security page.

official x3review x7security x3news x1
  • CVE-2024-11848 — Auth Bypass, Authentication bypass vulnerability in the NitroPack WordPress plugin.
  • CVE-2025-8778 — Missing Authorization, Broken access control in NitroPack plugin versions up to 1.19.3.
  • CVE-2026-39669 — Auth Bypass, Another authentication bypass vulnerability in the NitroPack WordPress plugin.
  • Removed security headers, Users report NitroPack removing security headers from site responses.

Key stats

  • Value for money: 3/5

    Rating

  • $7/mo

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 3/5. $7/mo entry is cheap; overage complaints erode value
  • Ease of use: 4/5. Non-developers report using it successfully
  • Feature depth: 4/5. Caching, CDN, image optimization bundled; 60+ features claimed
  • Support quality: 4/5. 24/7 support advertised; 5-star Trustpilot
  • Security posture: 2/5. Repeated auth bypass CVEs in the plugin
  • 4.9/5 G2 rating Seller rating across 4 G2 reviews
  • $7/mo Starting price Starter plan
  • 5/5 Trustpilot Customer rating
  • 4M+ pages Scale Optimized, up from 900k

Pricing

Starter

$7/mo

  • Entry plan for small sites
  • Costs scale with pageviews

Plus / Pro / Agency

Paid tiers above Starter

  • More pageviews
  • Agency-scale limits
  • Exact upper-tier prices not shown in sources

Security

Multiple WordPress plugin vulnerabilities disclosed, including auth bypasses; vendor publishes a DPA and security page.

  • CVE-2024-11848 — Auth BypassAuthentication bypass vulnerability in the NitroPack WordPress plugin.12
  • CVE-2025-8778 — Missing AuthorizationBroken access control in NitroPack plugin versions up to 1.19.3.11
  • CVE-2026-39669 — Auth BypassAnother authentication bypass vulnerability in the NitroPack WordPress plugin.13
  • Removed security headersUsers report NitroPack removing security headers from site responses.

What users say

Users love the speed gains over free caching plugins but frequently complain about surprise costs and limited control.

“Tried all the performance plugins nothing works like this”
Reddit, r/Wordpress
“It boosted our website’s”
Reddit, r/Wordpress
“NitroPack has 5 stars!”
Trustpilot reviewer

Alternatives

Compare NitroPack with each alternative.

  • WP Rocket

    One-time-payment caching plugin; simpler, no monthly fees.

    NitroPack vs WP Rocket
  • LiteSpeed Cache

    Free deep caching if your host runs LiteSpeed.

  • Cloudflare

    Free CDN and caching layer; start here before paying.

Companies that use it

  • Dad's Life
  • BionicWP
  • IPRoyal
Full analysis

Based on ~45 public sources: G2, Trustpilot, Reddit threads, CVE databases, and vendor pages. Several snippets were truncated, so some pricing and review details are incomplete.

Fast scores out of the box, but surprise overage costs, limited control, and repeated plugin CVEs. Good for non-devs, not tinkerers.

Methodology

Based on ~45 public sources: G2, Trustpilot, Reddit threads, CVE databases, and vendor pages. Several snippets were truncated, so some pricing and review details are incomplete.

Sources

  1. official
  2. NitroPack pricingapplication-api.nitropack.io
    official
  3. official
  4. review
  5. Trustpilot reviewstrustpilot.com
    review
  6. review
  7. review
  8. review
  9. review
  10. review
  11. security
  12. security
  13. security
  14. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.