Falcon – Cache, Performance, Security, Cleanup, and Tweaks

Falcon – Cache, Performance, Security, Cleanup, and Tweaks has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 2 of the records (100%).

Every one of the 2 issues recorded for Falcon – Cache, Performance, Security, Cleanup, and Tweaks has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Falcon – Cache, Performance, Security, Cleanup, and Tweaks is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.8/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Falcon – Cache, Performance, Security, Cleanup, and Tweaks vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-59531

Falcon – WordPress Optimizations & Tweaks <= 2.10.0 - Missing Authorization

Read the full analysis

Vulnerability Records

2 records
Falcon – Cache, Performance, Security, Cleanup, and Tweaks banner
Latestv2.11.2

Falcon – Cache, Performance, Security, Cleanup, and Tweaks

Anh Tran

Author

Anh Tran

5.0(10)
100/100
Last Updated
2026-08-17 (27d ago)
Active Installs
2,000+
Downloads
73,723
Requires WP
6.7+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2015-12-29 (11y ago)

Falcon is a lightweight WordPress plugin that helps you speed up your site, harden security, clean up bloat, and fine-tune how WordPress works — without a heavy stack of separate tools. Toggle only what you need from a clear settings UI. Export and import settings to reuse the same setup across sites. Features Performance Make pages load faster and cut unnecessary front-end work. HTML page cache — serve static HTML and skip WordPress, themes, and plugins on cache hits Disable Heartbeat to reduce server load Remove ?ver= query strings from CSS/JS for better browser caching Disable emoji scripts and styles Remove jQuery Migrate on the front end Load selected CSS files asynchronously to reduce render-blocking Security Reduce common attack surfaces and protect your content. Limit login attempts (block an IP after 3 failed tries for 1 hour) Hide detailed login error messages Force login to view the site Disable the REST API for unauthenticated requests Disable XML-RPC Restrict upload file types (including WebP and AVIF when enabled) Comment spam protection with a simple honeypot Block common AI crawlers via robots.txt Use scheme-less asset URLs to avoid mixed content warnings Cleanup Strip unused markup and keep the database lean. Header Hide WordPress version Remove shortlink, REST API link, adjacent posts links, feed links, RSD link, and WLW manifest link Admin Use the site icon on the login screen Hide update nags Remove default dashboard widgets Remove admin footer text and the WordPress admin bar logo Frontend Disable embeds Clean up menu item classes and IDs Remove Recent Comments widget CSS Database Clean revisions, auto drafts, trashed posts, spam/trashed comments, expired transients, orphaned meta, unused terms, and optimize tables Content Control the editor, comments, media, and publishing behavior. Editor Disable the block editor (Gutenberg) and use the classic editor Disable post revisions Disable texturize (smart quotes and auto formatting) Comments Disable comments site-wide Remove the website field from the comment form Media Disable thumbnail generation Disable big image scaling Disable EXIF-based image rotation Publishing Limit front-end search to posts only Disable self pingbacks System Site-wide controls for maintenance and WordPress internals. Maintenance mode (customize the message with maintenance.php in the active theme) Block external HTTP requests Disable application passwords Disable auto-updates Disable WP-Cron (use a real server cron instead) Remove privacy tools from the admin menu Email Cut noisy notifications and send mail reliably. Notifications Disable admin email verification prompts Disable update notification emails Disable new user emails to admins Disable password change/reset emails Delivery Change the default from name and email address Send WordPress email via SMTP You might also like If you like this plugin, you might also like our other WordPress products: Meta Box – A powerful WordPress plugin for creating custom post types and custom fields. Slim SEO – A fast, lightweight and full-featured SEO plugin for WordPress with minimal configuration. GretaThemes – Free and premium WordPress themes that clean, simple and just work. Auto Listings – A car sale and dealership plugin for WordPress.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C