plugin-icon

VelocityForge

Core Web Vitals from your real visitors, named down to the element, file and plugin behind them, with safe delivery hints and regression checks.
Version
1.2.5
Last updated
Oct 2, 2026
VelocityForge

VelocityForge gives WordPress sites measurable Core Web Vitals improvements without the catastrophic “white screen after update” failures that aggressive caching plugins are famous for. It measures on your own server and keeps every measurement in your own database — nothing is loaded from a CDN, and no field reading ever leaves the site.

It does not stop at the number. A slow interaction is reported with the control that was hit, the split between input delay, your own handler and the repaint afterwards, and the plugin that shipped the script; a slow first paint is reported with the element and the file it loaded. Those are different problems with different fixes, and until a measurement carries one of them a number is only a number.

Free

Everything here is measurement and the hints that cost nothing to give. None of it is capped to make a paid tier look better.

  • Core Web Vitals beacon — passive LCP / INP / CLS / TTFB / FCP collection from real visitors, stored in your own database
  • And what each measurement points at: which element was your LCP, which control the slow interaction hit, what moved during a layout shift — and, for an interaction, whether the time went on a busy main thread, on the site’s own handler, or on the repaint afterwards. Three different problems with three different fixes.
  • What slows INP and what delays LCP — two cards on the Monitoring screen: the ten controls that cost the most interaction time and the five elements that most delay the first paint, each with the file and the plugin behind it. Every figure is a 75th percentile per element over 28 days and appears only once that element has at least three measurements, because a p75 of two measurements is the larger of two under a borrowed name
  • 30 days of field-data history by default, and up to 90 if you ask for it in Settings
  • LCP hints — fetchpriority="high" and <link rel="preload"> on the detected hero, decoding="async" everywhere, loading="lazy" below the fold
  • Page profiler — manual single-URL or batch audit of this site’s own pages, up to 50 URLs per scan
  • Speculation rules — steer the prefetch/prerender WordPress 6.8 already does, with a cart, checkout and add-to-cart exclusion list that cannot be switched off
  • Asset inventory — full script/style handle map with owner attribution
  • Database health — autoloaded-option weight, expired transients, overdue cron, and the twenty heaviest autoloaded options each named with the plugin that wrote it. “wp_options is four megabytes” is not something you can act on until the rows have owners beside them
  • Regression monitor — post-update CWV delta check, and the e-mail to the site owner when one lands
  • And what the update changed: the regression row names the scripts and stylesheets the front end gained, lost or resized, read from a snapshot of the real page taken immediately before the files were replaced. “LCP is up 400 ms” is a symptom; “this update added three render-blocking stylesheets” is something you can take to its author
  • Trend chart — daily 75th percentile for LCP, INP, CLS and TTFB over the last 30 days, on the Monitoring screen. Inline SVG, no JavaScript, no chart library and no CDN, with the same numbers in a table for a screen reader
  • Cache plugin coexistence — seventeen caching and optimisation plugins are recognised, from WP Rocket, W3 Total Cache and LiteSpeed to Jetpack Boost, SiteGround Optimizer, WP-Optimize, Breeze and WP Fastest Cache, and our overlapping work stands down while one of them is active. The notice names every feature that stepped back, not only the one that obviously overlaps
  • Safe Mode — one-click panic recovery that disables all VelocityForge mutations, and a toggle in the admin bar on the front end as well as in wp-admin, because the front end is where you notice the breakage. It goes through the same rollback manager the form does, so it lands in the same audit trail
  • Recovery drill — a button that presses the escape hatches on a day when nothing is wrong: the panic constant, a real loopback request to the secret panic route with the real secret, the safe-mode option’s round trip, and the autoload backups table. Everything it touches is put back exactly as it was found. It writes no files.
  • Rollback manager — restore previously saved rule snapshots
  • Performance budgets — LCP 2500 ms, INP 200 ms, CLS 0.100, TTFB 800 ms and Total Blocking Time 300 ms, in one map on the Settings screen, against which a regression is banded. TBT is the odd one out and the screen says so: no field source populates it, because Total Blocking Time needs a long-tasks trace the real-user beacon does not capture, so that budget is read only by a Pro lab audit’s comparison

Pro

VelocityForge Pro is a separate add-on, installed alongside this free plugin. Its features are Pro because their code ships in the add-on, not because this plugin refuses to run code you already downloaded.

  • The Optimiser, as one purchase — everything that changes how the page is built:
    • Asset rules — defer / async / delay-until-interaction / dequeue / preload / preconnect per handle, scoped globally, to the front end, to a post type or to a URL pattern
    • Critical CSS — PHP heuristic extractor with a 14 KB inline cap and safe preload+swap defer
    • Image conversion — WebP / AVIF sidecars (Imagick or GD; originals are never deleted)
    • Autoload and transient cleanup — switch autoload off with a mandatory backup and a deny-list, and purge expired transients
  • Rules that take themselves back — when a rule starts applying, VelocityForge records what real visitors measured over the previous week, waits out a window (24 hours by default, settable 6 to 72), then compares. If LCP or INP is worse by more than your threshold (10 % by default) it reverts the rule through the same revert your own button uses, writes the reason onto the rollback event, and e-mails you what was applied, what the numbers were and how to put it back. It refuses six ways first: no licence, no beacon, fewer measurements than your sample floor (30 by default), Safe Mode on, a hard-railed handle, and a rule you pinned. One open watch per rule and one verdict per watch, so a retried job cannot revert twice or send a second e-mail
  • Regression alerts to Telegram, Slack or your own webhook — for the sites whose mailbox nobody reads. A card per channel with Add, Remove and a “Send test” that really sends and saves nothing, instead of a textarea of raw JSON. Bot tokens, webhook URLs and HMAC secrets are encrypted at rest and shown back only as their last four characters; leaving a field empty keeps what is stored, so the first save through the new form migrates an old clear-text secret without you touching it. Every URL goes through the same SSRF guard on the test path as on the save path — https only, and never a private or loopback address
  • The CSV export of your field data
  • AI Performance Advisor — reads your own field data and handle list, returns an ordered plan. It costs one AI credit per run, it refuses to answer when there is no field data to reason about, and it applies nothing: you read the plan and click the rules you agree with
  • Scheduled lab audits — Lighthouse runs against a list of your pages once a day through your own PageSpeed Insights key. The results draw a second line on the free trend chart beside what real visitors measured, and a lab regression lands in the same history and reaches you through the same alerts. Useful exactly where field data cannot help: a page nobody has visited yet, a staging site, a change made at midnight. Lab runs band Total Blocking Time alongside LCP, CLS and TTFB, and the panel’s status line is the run’s own — nothing started says nothing, an open run says when it was queued, and a finished one repeats exactly the wording the history table uses, so the line and the table can never disagree.

VelocityForge is part of the Forge Suite. Learn more and get Pro at https://avakode.com.

External services

Field data from the beacon is stored in your own database and is never sent anywhere — no measurement leaves your site in either tier.

This free plugin’s own performance work does make HTTP requests, and every one of them is aimed at your own site: the page profiler fetches the pages of this site you audit or batch-scan (a URL on another host is refused), the regression monitor fetches your front page after you update a plugin or theme so it can compare the assets before and after, the asset inventory sends a HEAD request to each script and stylesheet your pages load from this site to read its size (assets served from other hosts are listed without one), and the recovery drill makes a real loopback request to your own secret panic route when you press its button. None of them is aimed at us or at anyone else.

The code also names some third-party hosts — js.stripe.com, paypal.com/sdk, www.google.com/recaptcha, challenges.cloudflare.com and the chat widgets of Intercom, Drift, HubSpot, Crisp, Tawk.to, Zendesk and Olark. They are match patterns, not services: a script from one of them that is already on your pages is recognised and left alone, so payments, captchas and chat keep working. This plugin never connects to any of them.

Telemetry. This free plugin sends no telemetry and has no switch for it. With the separate VelocityForge Pro add-on installed, Settings shows “Share anonymous usage telemetry”, off by default, and Pro sends nothing until you turn it on.

Bundled libraries

  • web-vitals 4.2.4 by Google Chrome, licensed Apache-2.0 (compatible with this plugin’s GPLv2-or-later). This is the script that measures LCP / INP / CLS / TTFB / FCP in the visitor’s browser. It is bundled with the plugin and served from your own site — it is not loaded from a CDN, and it makes no request of its own. Source: https://github.com/GoogleChrome/web-vitals

The Pro add-on

The Pro add-on talks to three parties, each for a reason you can see in Settings:

  • Your alert channels — Telegram, Slack or your own webhook — only when you configure one and a regression fires.
  • The AI performance advisor, and only when you run it: your aggregated Core Web Vitals and the list of render-blocking handles this site enqueues are sent for a plan. No page content, no visitor data, and nothing at all until you press the button.
  • Scheduled lab audits, and only after you paste your own PageSpeed Insights API key. This call goes to Google (https://pagespeedonline.googleapis.com), not to us — it carries the URL of the page being audited and your key, and it spends your own Google quota under your own billing relationship with Google. Nothing is proxied through our servers and we never see the key: it is encrypted at rest with a value from your wp-config.php. Google’s terms: https://developers.google.com/speed/docs/insights/v5/about — Google’s privacy policy: https://policies.google.com/privacy

Terms: https://avakode.com/terms — Privacy: https://avakode.com/privacy

Freeon paid plans
Tested up to
WordPress 7.1.2
This plugin is available for download for your site.