shouldiuse.io

VERDICT

Should I use Perfmatters?

Slow WordPress sites have higher bounce rates and fewer conversions. The perfmatters plugin was created by web performance geeks to speed up your site! - perfmatters.io

Worth it. Buy if you run WordPress, already have caching in place, and want granular speed control for about $25/year. Skip it if you're non-technical, want one-click fixes, or need a spotless security record.

Confidence

High. Based on 25+ public sources: Trustpilot, Reddit, Wordfence, WPScan, NVD, and vendor docs. Some review snippets truncated.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$24.95/yr

Entry

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierNo
Top tier$124.95/yr

Best for

  • WordPress owners chasing the 'final 10%' of speed
  • Tinkerers comfortable disabling scripts per page
  • Agencies optimizing client sites
  • Sites already running WP Rocket or LiteSpeed Cache

Not for

  • Non-technical users wanting one-click speed fixes
  • Anyone expecting a caching plugin — it isn't one
  • Simple blogs already fast on default themes
  • Security-sensitive orgs needing a clean CVE history

Gotchas - check before you buy

high

Run the latest version: 2026 flaws were fixed in rapid patch releases.

medium

Buy it alongside caching, not instead: users pair it with WP Rocket or LiteSpeed Cache.

medium

No free trial — evaluating means paying first.

low

Annual renewals; multi-site licenses climb to $124.95/year.

Pros and cons

Pros

  • Perfect 5/5 Trustpilot rating.
  • Trims the 'final 10%' of load time other plugins miss.
  • Complements caching plugins like WP Rocket; works in LiteSpeed stacks.
  • Lightweight plugin focused purely on performance bloat removal.
  • Entry price of $24.95/year undercuts most premium alternatives.

Cons

  • Not a caching plugin — pair it with WP Rocket or LiteSpeed.
  • Requires manual tuning; vendor ships troubleshooting docs for breakage.
  • Premium-only; no free tier to try before buying.
  • Multiple 2026 CVEs, including high-severity unauthenticated directory traversal.
  • File-deletion flaw exposed ~200,000 sites before patching.

Sources & method

Analyzed 9/23/2026 - 11 sources - Repeated 2025–2026 vulnerabilities, including high-severity ones; update immediately and never run outdated versions.

official x2review x6security x3
  • CVE-2026-13251 — unauthenticated directory traversal, Rated high severity; fixed in a later release.
  • Arbitrary file deletion (CVE-2026-4350), Affected ~200,000 WordPress sites; disclosed March 2026.
  • CVE-2026-4351 — path traversal flaw, Path traversal vulnerability in the plugin.
  • Reflected XSS in versions < 2.6.4, Cross-site scripting fixed in 2.6.4.
  • Arbitrary file overwrite in <= 2.5.9, Authenticated (Subscriber+) arbitrary file overwrite via snippets parameter.

Key stats

  • Value for money: 5/5

    Rating

  • $24.95/yr

    Starting price

  • 11

    Sources

  • Analyzed

  • Value for money: 5/5. From $24.95/yr; reviewers call it worth it.
  • Ease of use: 4/5. Lightweight, but setup needs technical comfort.
  • Feature depth: 4/5. Script Manager, snippets, lazy loading; granular control.
  • Support quality: 4/5. 5/5 Trustpilot suggests satisfied, supported customers.
  • Security posture: 2/5. Multiple high-severity CVEs in 2026.
  • 5/5 Trustpilot rating Customer reviews
  • $24.95/yr Starting price Entry annual license
  • No Free tier Premium-only plugin
  • ~200,000 Sites hit by 2026 file-deletion bug Patched March 2026

Pricing

Entry

$24.95/yr

  • Annual license
  • Full plugin features

Top tier

$124.95/yr

  • Annual license
  • Multi-site use

Security

Repeated 2025–2026 vulnerabilities, including high-severity ones; update immediately and never run outdated versions.

  • CVE-2026-13251 — unauthenticated directory traversalRated high severity; fixed in a later release.⁸
  • Arbitrary file deletion (CVE-2026-4350)Affected ~200,000 WordPress sites; disclosed March 2026.⁷
  • CVE-2026-4351 — path traversal flawPath traversal vulnerability in the plugin.
  • Reflected XSS in versions < 2.6.4Cross-site scripting fixed in 2.6.4.⁹
  • Arbitrary file overwrite in <= 2.5.9Authenticated (Subscriber+) arbitrary file overwrite via snippets parameter.

Companies that use it

  • Guess: Microsoft Advertising⁴
Full analysis

Based on 25+ public sources: Trustpilot, Reddit, Wordfence, WPScan, NVD, and vendor docs. Some review snippets truncated.

Loved $25/yr WordPress speed plugin for tinkerers — but not a caching plugin, and 2026 brought several CVEs.

Methodology

Based on 25+ public sources: Trustpilot, Reddit, Wordfence, WPScan, NVD, and vendor docs. Some review snippets truncated.

Sources

  1. review
  2. review
  3. review
  4. review
  5. Perfmatters vs. Asset CleanUponlinemediamasters.com
    review
  6. review
  7. security
  8. security
  9. security
  10. official
  11. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.