{"id":339943,"date":"2026-07-21T19:12:18","date_gmt":"2026-07-21T19:12:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/qaiyo-web-performance-surgeon\/"},"modified":"2026-08-31T07:27:19","modified_gmt":"2026-08-31T07:27:19","slug":"qaiyo-web-performance-surgeon","status":"publish","type":"plugin","link":"https:\/\/pcm.wordpress.org\/plugins\/qaiyo-web-performance-surgeon\/","author":23510315,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.0","stable_tag":"1.4.0","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Qaiyo Web Performance Surgeon","header_author":"Qaiyo","header_description":"Diagnose what actually slows your site down \u2014 file- and function-level attribution of SQL, hooks, HTTP and assets, measured on a real front-end render.","assets_banners_color":"","last_updated":"2026-08-31 07:27:19","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/qaiyo-plugins.com\/qaiyo-web-performance-surgeon","header_author_uri":"https:\/\/qaiyo-plugins.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":352,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"qaiyo","date":"2026-07-21 19:12:05","revision":3617633},"1.0.1":{"tag":"1.0.1","author":"qaiyo","date":"2026-07-22 15:07:14","revision":3618839},"1.1.0":{"tag":"1.1.0","author":"qaiyo","date":"2026-08-24 09:17:12","revision":3663005},"1.2.0":{"tag":"1.2.0","author":"qaiyo","date":"2026-08-26 08:29:11","revision":3666528},"1.3.0":{"tag":"1.3.0","author":"qaiyo","date":"2026-08-31 07:27:19","revision":3673551},"1.4.0":{"tag":"1.4.0","author":"qaiyo","date":"2026-08-31 07:27:19","revision":3673551}},"upgrade_notice":{"1.4.0":"<p>Adds a 0\u2013100 performance score with a speedometer gauge, shown on your dashboard through the shared Qaiyo ecosystem widget.<\/p>","1.3.0":"<p>Fixes scans failing on cached\/CDN sites, a false-positive on the XML-RPC recommendation, and misleading advice on page-builder and cache-plugin findings.<\/p>","1.2.0":"<p>Adds an optional one-click fix for removing version query strings from static assets.<\/p>","1.1.0":"<p>Image and duplicate-asset checks, a Server &amp; environment tab, before\/after comparison with your last scan, and three more safe one-click fixes.<\/p>","1.0.1":"<p>Lighter front-end footprint (deferred scan classes, autoloaded fixes option) and internal version\/annotation tidy-up.<\/p>","1.0.0":"<p>First public release on WordPress.org.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3619182,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.1.0","1.2.0","1.3.0","1.4.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[153,23519,187,247,23044],"plugin_category":[52,54,59],"plugin_contributors":[267332],"plugin_business_model":[],"class_list":["post-339943","plugin","type-plugin","status-publish","hentry","plugin_tags-database","plugin_tags-diagnostics","plugin_tags-optimization","plugin_tags-performance","plugin_tags-profiling","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-qaiyo","plugin_committers-qaiyo"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/qaiyo-web-performance-surgeon\/assets\/icon-256x256.png?rev=3619182","icon_2x":"https:\/\/ps.w.org\/qaiyo-web-performance-surgeon\/assets\/icon-256x256.png?rev=3619182","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Most performance tools tell you <em>that<\/em> your site is slow. Qaiyo Web Performance Surgeon tells you <strong>what<\/strong> is slow, <strong>where<\/strong> it comes from, and <strong>how much<\/strong> you would save by fixing it \u2014 then fixes the safe ones in one click.<\/p>\n\n<p>It measures a real, anonymous visitor render (not your logged-in admin view) by running a tokened loopback request, and attributes every cost back to the exact plugin, file and line responsible.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>File- and function-level attribution<\/strong> \u2014 every slow query, hook and asset is traced to the exact plugin, file and line responsible, not just \"the database is slow\".<\/li>\n<li><strong>Measures the real visitor render<\/strong> \u2014 a tokened, anonymous loopback captures the logged-out front-end page, not your admin-skewed view.<\/li>\n<li><strong>Estimated time saving per finding<\/strong> \u2014 every issue is ranked with an honest millisecond estimate, so you fix the biggest wins first.<\/li>\n<li><strong>Database profiling<\/strong> \u2014 per-query timing, duplicate-query detection and bloated autoloaded-option detection.<\/li>\n<li><strong>Hook and callback timing<\/strong> \u2014 per-callback cost with plugin attribution, captured with low overhead (no per-call backtraces).<\/li>\n<li><strong>Blocking HTTP detection<\/strong> \u2014 flags slow external requests made while the page renders.<\/li>\n<li><strong>Asset inventory<\/strong> \u2014 enqueued scripts and styles listed with their owning plugin.<\/li>\n<li><strong>Real browser metrics<\/strong> \u2014 Largest Contentful Paint, Cumulative Layout Shift, long tasks and navigation timing from an actual browser render.<\/li>\n<li><strong>Image checks<\/strong> \u2014 finds images served far larger than they are displayed (with the wasted kilobytes) and images that render without width\/height, which makes the page jump.<\/li>\n<li><strong>Duplicate asset detection<\/strong> \u2014 spots the same library shipped twice by different plugins, or the same file registered under two handles.<\/li>\n<li><strong>Server &amp; environment tab<\/strong> \u2014 the performance checks WordPress itself runs (object cache, page cache, PHP and database versions, cron, debug mode), collected in one place.<\/li>\n<li><strong>Compared with your last scan<\/strong> \u2014 every scan shows whether server time, query count and findings went up or down since the previous scan of the same URL.<\/li>\n<li><strong>Performance score on your dashboard<\/strong> \u2014 your latest scan is condensed into a single 0\u2013100 score on a speedometer gauge, shown in the shared Qaiyo ecosystem dashboard widget (provided by Qaiyo Admin Booster) so you see how the site is doing without opening the plugin.<\/li>\n<li><strong>Safe one-click fixes<\/strong> \u2014 reversible toggles for common wins; no source files are ever modified.<\/li>\n<li><strong>Zero overhead on live traffic<\/strong> \u2014 measurement only runs for a tokened scan request; normal visits pay nothing.<\/li>\n<li><strong>Available in 11 languages.<\/strong><\/li>\n<\/ul>\n\n<h4>What it measures<\/h4>\n\n<ul>\n<li><strong>Database<\/strong> \u2014 every query with its execution time, paired to the calling plugin\/file\/line (via SAVEQUERIES), plus duplicate-query and autoloaded-option detection.<\/li>\n<li><strong>Hooks<\/strong> \u2014 per-callback timing with plugin attribution, captured without per-call backtraces (low overhead).<\/li>\n<li><strong>HTTP<\/strong> \u2014 outbound requests made during render, flagging blocking external calls.<\/li>\n<li><strong>Assets<\/strong> \u2014 enqueued scripts and styles with their owners.<\/li>\n<li><strong>Browser<\/strong> \u2014 real LCP, CLS, long tasks and navigation timing, captured from an actual browser render.<\/li>\n<\/ul>\n\n<h4>Diagnosis and one-click fixes<\/h4>\n\n<p>The rule engine turns raw measurements into ranked findings with an estimated time saving for each, and offers safe, reversible one-click fixes for common wins:<\/p>\n\n<ul>\n<li>Disable the emoji detection script<\/li>\n<li>Disable wp-embed.js<\/li>\n<li>Remove jQuery Migrate<\/li>\n<li>Dequeue front-end Dashicons<\/li>\n<li>Stop autoloading a bloated option<\/li>\n<li>Remove the legacy RSD \/ Windows Live Writer links from the page head<\/li>\n<li>Turn off XML-RPC (only offered when nothing on the site appears to need it)<\/li>\n<li>Stop self-pingbacks when you link between your own posts<\/li>\n<li>Remove the \"?ver=\" query string from static assets, for caching layers that skip versioned URLs<\/li>\n<\/ul>\n\n<p>Every fix is a toggle you can undo \u2014 no source files are ever rewritten.<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>Scans run on your own site. No data is sent to any third party.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/<\/code> and activate it.<\/li>\n<li>Open <strong>Performance Surgeon<\/strong> in the admin menu.<\/li>\n<li>Install the scan helper when prompted (a tiny must-use plugin that only activates during a scan and is removed on deactivation).<\/li>\n<li>Enter a URL and run a scan.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20slow%20down%20my%20live%20site%3F\"><h3>Does it slow down my live site?<\/h3><\/dt>\n<dd><p>No. Measurement only runs for a tokened scan request; every normal page load exits on the first line of the scan helper at zero cost.<\/p><\/dd>\n<dt id=\"why%20does%20it%20install%20a%20must-use%20plugin%3F\"><h3>Why does it install a must-use plugin?<\/h3><\/dt>\n<dd><p>To capture the <em>whole<\/em> request \u2014 including the earliest database queries \u2014 the SAVEQUERIES flag must be set before WordPress loads its database layer. A tiny must-use loader does this, but only during a scan. It is removed automatically when you deactivate the plugin.<\/p><\/dd>\n<dt id=\"are%20the%20estimated%20savings%20exact%3F\"><h3>Are the estimated savings exact?<\/h3><\/dt>\n<dd><p>They are honest estimates based on measured data, shown under instrumentation. Treat them as a prioritised guide, not a guarantee.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New: <strong>Performance score<\/strong> \u2014 every scan now produces a single 0\u2013100 score from its findings and measured server time, shown on a speedometer gauge.<\/li>\n<li>New: the score appears as a card in the shared <strong>Qaiyo ecosystem<\/strong> dashboard widget and settings panel (provided by Qaiyo Admin Booster), alongside the cards other Qaiyo plugins report. Nothing is required for this to work \u2014 if Admin Booster is not installed, no card is reported and nothing changes.<\/li>\n<li>The score is now the single source of truth across the plugin: the Pro add-on's multi-URL site health score reads the same formula, so the number on the dashboard always matches the number on the scan page.<\/li>\n<li>Fixed: uninstalling the plugin left the XML-RPC usage-monitor option behind in the database.<\/li>\n<li>Fixed: the score-band label (\"Poor\" \/ \"Needs work\" \/ \"Good\") on the Qaiyo ecosystem card could render with glitchy, incorrect-looking glyphs in some browsers. It was placed inside the SVG gauge as a small <code>&lt;text&gt;<\/code> element, which some browser\/OS combinations render inconsistently at small sizes; it is now plain HTML text under the gauge instead. The translated strings themselves were always correct \u2014 this was a rendering issue, not a translation bug.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Fixed: on sites behind a full-page cache or CDN, a scan could report \"no measurements came back\" even with the scan helper installed. The scanner now detects and purges known caching plugins before scanning, and \u2014 if that still fails \u2014 names the caching layer it found instead of a generic message.<\/li>\n<li>Fixed: \"Turn off XML-RPC\" could be offered even when the endpoint was in real use by something outside this site (a publishing app, an automation tool). It now watches for real XML-RPC calls for at least 7 days before recommending anything, and never recommends it while recent real traffic is seen.<\/li>\n<li>Fixed: findings for a page builder's own rendering step (e.g. Elementor building the page from its saved layout) recommended adding conditional tags to code you cannot edit. These are now labelled as the builder's own baseline cost, with guidance that is actually actionable.<\/li>\n<li>Fixed: a caching plugin writing its own page cache after render could be flagged as \"slow\" with advice to cache its own output. This is now recognised as the cache doing its job, not a bug.<\/li>\n<li>Fixed: WordPress's own wp_enqueue_scripts() dispatcher could appear as a separate \"slow hook\" finding, double-counting time already reported under the individual plugin callbacks it fires.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>New one-click fix: remove the \"?ver=\" query string from static assets, for proxies and CDN setups that will not cache a versioned URL. Off by default and reversible \u2014 the version is also what busts caches after an update, so turn it on only if your caching layer needs it.<\/li>\n<li>Fixed: the Qaiyo plugin group in the admin sidebar could break apart on sites where another plugin (WooCommerce, Elementor, an admin-menu tool) reorders the admin menu.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: image checks \u2014 oversized images (with the wasted kilobytes) and images rendering without width\/height.<\/li>\n<li>New: duplicate asset detection \u2014 the same library loaded by two different plugins, or the same file behind two handles.<\/li>\n<li>New: large-DOM finding, based on the element count from the real browser render.<\/li>\n<li>New: \"Server &amp; environment\" tab showing WordPress's own Site Health performance checks (object cache, page cache, PHP\/database version, cron, debug mode).<\/li>\n<li>New: each scan is compared with the previous scan of the same URL, so you can see whether a change helped.<\/li>\n<li>New one-click fixes: remove the legacy RSD\/Windows Live Writer head links, turn off XML-RPC (only offered when nothing appears to need it), and stop self-pingbacks.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Deferred the scan\/measurement classes to admin and scan requests only, so normal front-end page loads stay lighter.<\/li>\n<li>The enabled-fixes option is now autoloaded, removing an extra database read on every front-end request.<\/li>\n<li>Aligned all internal version constants with the plugin header and tidied a few developer-facing code annotations.<\/li>\n<li>Added a SECURITY.md with a vulnerability-disclosure contact.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release on WordPress.org.<\/li>\n<li>File- and function-level performance attribution for SQL, hooks, HTTP and assets, measured on a real anonymous visitor render via a tokened loopback.<\/li>\n<li>Real-browser metrics (LCP, CLS, long tasks, navigation timing) captured from an actual render.<\/li>\n<li>Rule engine with ranked findings, estimated time savings, and safe reversible one-click fixes.<\/li>\n<li>Tabbed admin page (Diagnostics, Browser metrics, Loopback test) with the Qaiyo design system.<\/li>\n<li>Bundled translations for 11 languages.<\/li>\n<li>Clean uninstall: removes the plugin's option, cached transient and scan-helper on deletion.<\/li>\n<\/ul>","raw_excerpt":"Diagnose what actually slows your site down \u2014 file- and function-level attribution of SQL, hooks, HTTP and assets, measured on a real visitor render.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/339943","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=339943"}],"author":[{"embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/qaiyo"}],"wp:attachment":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=339943"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=339943"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=339943"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=339943"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=339943"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=339943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}