惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Last Week in AI
Last Week in AI
S
Schneier on Security
The GitHub Blog
The GitHub Blog
宝玉的分享
宝玉的分享
GbyAI
GbyAI
L
LINUX DO - 热门话题
大猫的无限游戏
大猫的无限游戏
Hacker News: Ask HN
Hacker News: Ask HN
A
Arctic Wolf
罗磊的独立博客
S
Securelist
I
Intezer
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
D
Darknet – Hacking Tools, Hacker News & Cyber Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Register - Security
The Register - Security
M
MIT News - Artificial intelligence
C
Cisco Blogs
G
GRAHAM CLULEY
P
Proofpoint News Feed
美团技术团队
MongoDB | Blog
MongoDB | Blog
Cyberwarzone
Cyberwarzone
T
Tor Project blog
P
Proofpoint News Feed
NISL@THU
NISL@THU
J
Java Code Geeks
有赞技术团队
有赞技术团队
AWS News Blog
AWS News Blog
D
Docker
博客园 - 聂微东
I
InfoQ
AI
AI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
O
OpenAI News
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
C
Cybersecurity and Infrastructure Security Agency CISA
Know Your Adversary
Know Your Adversary
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Application and Cybersecurity Blog
Application and Cybersecurity Blog
N
News | PayPal Newsroom
L
LangChain Blog
Hugging Face - Blog
Hugging Face - Blog
T
Tenable Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
MyScale Blog
MyScale Blog
T
Tailwind CSS Blog
K
Kaspersky official blog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Speed Up Your WordPress Site in 30 Minutes: A No-Plugin Performance Guide
Ali Karbasi · 2026-05-27 · via DEV Community
  • Posted on May 3, 2026
  • 6 min read

🤖 AI summary: This practical guide walks WordPress and WooCommerce site owners through a series of hands-on performance optimizations that can be completed in 30 minutes, without installing a single caching or optimization plugin. It covers converting images to modern formats like WebP and AVIF, implementing native lazy loading, optimizing web font delivery, inlining critical CSS, cleaning up the database, and removing render-blocking resources. Each step includes real code snippets that can be dropped into a child theme's functions.php file, making this a copy-paste-and-go resource for store owners who want faster load times today.

I am going to say something that might upset a few people: your WordPress site does not need fifteen plugins to be fast.

I have lost count of the number of WooCommerce stores I have audited where the client installed a caching plugin, an image optimization plugin, a lazy loading plugin, a minification plugin, a database optimization plugin, and a CDN plugin, and the site was still slow. In some cases, the plugins were actually fighting each other and making things worse.

The truth is that WordPress, out of the box, is not as slow as people think. What makes it slow is what we pile on top of it. And the irony of installing more plugins to fix a problem caused by too many plugins is something that should keep us all up at night.

So here is my challenge: set a 30-minute timer and follow this guide. No plugins. Just code, configuration, and common sense. By the time you are done, your site will be measurably faster.

Let's go.

Minute 0-5: Convert Your Images to WebP or AVIF

This is the single biggest performance win for most WordPress sites, and it is not even close.

If your product images and blog thumbnails are still in JPEG or PNG format, you are serving files that are two to five times larger than they need to be. WebP delivers the same visual quality at roughly 30% smaller file sizes than JPEG. AVIF goes even further, often 50% smaller.

Here is the thing: WordPress has supported WebP uploads natively since version 5.8 (2021). And as of WordPress 6.5, AVIF is also supported out of the box. You do not need a plugin for this.

What to do:

  1. Use a free tool like Squoosh (by Google) to batch convert your existing images to WebP.
  2. For new uploads, simply save your images as .webp before uploading them to the Media Library.
  3. If you want WordPress to serve AVIF to browsers that support it and WebP as a fallback, you can add this to your .htaccess file:
# Serve AVIF/WebP images if browser supports them
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteCond %{HTTP_ACCEPT} image/avif
  RewriteCond %{REQUEST_FILENAME}.avif -f
  RewriteRule ^(.+)\.(jpe?g|png|gif)$ $1.$2.avif [T=image/avif,L]

  RewriteCond %{HTTP_ACCEPT} image/webp
  RewriteCond %{REQUEST_FILENAME}.webp -f
  RewriteRule ^(.+)\.(jpe?g|png|gif)$ $1.$2.webp [T=image/webp,L]
</IfModule>

Enter fullscreen mode Exit fullscreen mode

On a WooCommerce store with 500 products, I have seen this single change cut total page weight by 60%. That translates directly into faster load times, especially for customers on mobile networks.

Minute 5-10: Enable Native Lazy Loading

Lazy loading means images below the fold (the ones you cannot see without scrolling) are not loaded until the user scrolls down to them. This dramatically reduces initial page load time.

The good news: WordPress has included native lazy loading since version 5.5. It automatically adds loading="lazy" to images. But there are two problems with the default behavior.

First, WordPress also lazy-loads images above the fold, including your hero banner and first visible product images. This actually hurts your Largest Contentful Paint (LCP) score because the browser waits to load the most important image on the page.

Second, iframes (like embedded YouTube videos) are not lazy-loaded by default.

Add this to your child theme's functions.php to fix both issues:

/**
 * Skip lazy loading for the first image (above the fold)
 * and add lazy loading to iframes
 */
// Skip lazy loading on hero/banner images
add_filter('wp_img_tag_add_loading_attr', function($value, $image, $context) {
    static $count = 0;
    $count++;
    // Don't lazy load the first 2 images (likely above the fold)
    if ($count <= 2) {
        return false;
    }
    return 'lazy';
}, 10, 3);

// Add lazy loading to iframes (YouTube embeds, maps, etc.)
add_filter('the_content', function($content) {
    $content = str_replace('<iframe ', '<iframe loading="lazy" ', $content);
    return $content;
});

Enter fullscreen mode Exit fullscreen mode

This is one of those changes that costs you nothing but gives you an immediate improvement in Core Web Vitals, specifically LCP and the overall page load waterfall.

Minute 10-15: Optimize Your Web Fonts

Fonts are a silent performance killer. Most WordPress themes load Google Fonts by making a round-trip request to fonts.googleapis.com, then another to fonts.gstatic.com, then downloading the actual font files. That is three network hops before your text even renders.

Here is how to fix it in three steps:

Step 1: Add preconnect hints. This tells the browser to start the connection to the font server early. Add this to your theme's <head>:

<link rel="preconnect" href="https://fonts.googleapis.com" />
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin />

Enter fullscreen mode Exit fullscreen mode

Step 2: Use font-display: swap. This tells the browser to show the text immediately using a system font, then swap in the custom font once it has loaded. No more invisible text while fonts download. When loading Google Fonts, append &display=swap to the URL:

https://fonts.googleapis.com/css2?family=Inter:wght@400;600;700&display=swap

Enter fullscreen mode Exit fullscreen mode

Step 3: Self-host your fonts. This is the biggest win. Instead of loading fonts from Google's servers, download them and serve them from your own domain. This eliminates the DNS lookup and connection overhead entirely.

Download your fonts from Google Webfonts Helper, place them in your theme's /fonts/ directory, and add a @font-face declaration to your CSS:

@font-face {
    font-family: 'Inter';
    font-style: normal;
    font-weight: 400;
    font-display: swap;
    src: url('/wp-content/themes/your-child-theme/fonts/inter-v18-latin-regular.woff2')
         format('woff2');
}

Enter fullscreen mode Exit fullscreen mode

Then remove the Google Fonts stylesheet from your theme. If your parent theme enqueues it, dequeue it in your child theme:

add_action('wp_enqueue_scripts', function() {
    wp_dequeue_style('google-fonts');
    wp_deregister_style('google-fonts');
}, 20);

Enter fullscreen mode Exit fullscreen mode

On one WooCommerce store I optimized, self-hosting fonts alone shaved 400ms off the initial render time. That is almost half a second just from eliminating external font requests.

Minute 15-20: Inline Critical CSS and Defer the Rest

By default, WordPress loads your entire stylesheet as a render-blocking resource. This means the browser has to download and parse your complete CSS file before it can paint anything on screen, even if 90% of that CSS is for pages the user has not visited yet.

The fix is to inline the critical CSS (the styles needed for the above-the-fold content) directly in the <head>, and load the rest asynchronously.

Here is a practical approach without a plugin:

Step 1: Use a tool like CSS Minifier to minify your stylesheet.

Step 2: Extract your critical CSS. You can use the free Critical CSS Generator to identify which styles are needed for the initial viewport. This typically includes your header, navigation, hero section, and first row of products.

Step 3: Inline that critical CSS and defer the full stylesheet. Add this to your functions.php:

add_action('wp_head', function() {
    // Inline critical CSS
    echo '<style id="critical-css">';
    // Paste your minified critical CSS here
    include get_stylesheet_directory() . '/critical.css';
    echo '</style>';
}, 1);

add_action('wp_enqueue_scripts', function() {
    // Change main stylesheet to load asynchronously
    wp_dequeue_style('theme-style');
    wp_enqueue_style('theme-style',
        get_stylesheet_uri(),
        array(),
        null,
        'print' // Load as print, then swap to all
    );
    // Add onload handler to swap media to "all"
    add_filter('style_loader_tag', function($html, $handle) {
        if ($handle === 'theme-style') {
            $html = str_replace(
                "media='print'",
                "media='print' onload=\"this.media='all'\"",
                $html
            );
        }
        return $html;
    }, 10, 2);
}, 20);

Enter fullscreen mode Exit fullscreen mode

This technique makes your page visually complete in a fraction of the time because the browser does not have to wait for the full stylesheet. Users see content immediately, and the rest of the styles load quietly in the background.

Minute 20-25: Clean Up Your Database

This one is especially important for WooCommerce stores. Over time, your WordPress database accumulates a shocking amount of junk:

  • Post revisions: WordPress saves every single draft of every post and page. A store with 500 products might have 5,000+ revision entries doing absolutely nothing.
  • Transients: Temporary cached data that often outlives its usefulness. Expired transients just sit in the database taking up space.
  • Spam and trashed comments: Self-explanatory.
  • Orphaned post meta: Metadata left behind by plugins you uninstalled months ago.
  • WooCommerce sessions: Expired customer session data that can grow to thousands of rows.

You can clean all of this up with a few SQL queries. Connect to your database via phpMyAdmin or a MySQL client and run these:

-- Delete all post revisions
DELETE FROM wp_posts WHERE post_type = 'revision';

-- Delete expired transients
DELETE FROM wp_options WHERE option_name
    LIKE '%\_transient\_%'
    AND option_name NOT LIKE '%\_transient\_timeout\_%';

-- Delete spam and trashed comments
DELETE FROM wp_comments WHERE comment_approved = 'spam'
    OR comment_approved = 'trash';

-- Optimize all tables
-- (run this after the cleanup queries above)

Enter fullscreen mode Exit fullscreen mode

Important: Always back up your database before running any SQL queries. Always. I do not care how confident you are. Back it up.

To prevent revision bloat from coming back, add this line to your wp-config.php file:

// Limit post revisions to 3
define('WP_POST_REVISIONS', 3);

Enter fullscreen mode Exit fullscreen mode

This keeps the safety net of revisions while preventing the database from growing endlessly. On a WooCommerce store I worked on last year, cleaning up revisions and expired transients alone reduced the database size from 800MB to 120MB. The difference in query speed was immediately noticeable.

Minute 25-30: Remove Render-Blocking Resources

The final step is to audit what WordPress is injecting into your <head> that you do not actually need. By default, WordPress adds quite a bit of extra weight:

  • The emoji script (yes, WordPress loads a JavaScript file just for emojis)
  • The embed script for oEmbed
  • jQuery Migrate (a compatibility layer for old plugins that most modern themes do not need)
  • The RSS feed links
  • The Windows Live Writer manifest
  • The WordPress version number (which is also a security risk)

Add this to your functions.php to clean it all up:

/**
 * Remove unnecessary head resources
 */
// Remove emoji scripts and styles
remove_action('wp_head', 'print_emoji_detection_script', 7);
remove_action('wp_print_styles', 'print_emoji_styles');
remove_action('admin_print_scripts', 'print_emoji_detection_script');
remove_action('admin_print_styles', 'print_emoji_styles');

// Remove embed script
wp_deregister_script('wp-embed');

// Remove WordPress version number
remove_action('wp_head', 'wp_generator');

// Remove Windows Live Writer manifest
remove_action('wp_head', 'wlwmanifest_link');

// Remove RSS feed links (if you don't use RSS)
remove_action('wp_head', 'feed_links', 2);
remove_action('wp_head', 'feed_links_extra', 3);

// Remove REST API link
remove_action('wp_head', 'rest_output_link_wp_head');

// Remove oEmbed discovery links
remove_action('wp_head', 'wp_oembed_add_discovery_links');

// Remove shortlink
remove_action('wp_head', 'wp_shortlink_wp_head');

Enter fullscreen mode Exit fullscreen mode

For jQuery Migrate, be careful. Test your site after removing it, because some older plugins still depend on it. If everything works fine without it, add this:

add_action('wp_default_scripts', function($scripts) {
    if (!is_admin() && isset($scripts->registered['jquery'])) {
        $script = $scripts->registered['jquery'];
        if ($script->deps) {
            $script->deps = array_diff($script->deps, array('jquery-migrate'));
        }
    }
});

Enter fullscreen mode Exit fullscreen mode

The Results

If you followed all six steps, here is what you have done in 30 minutes:

  • Reduced image sizes by 30-50% (WebP/AVIF conversion)
  • Eliminated unnecessary image loading on initial page load (smart lazy loading)
  • Removed external font requests and eliminated invisible text flash (font optimization)
  • Made the above-the-fold content render without waiting for the full stylesheet (critical CSS)
  • Shrunk your database and sped up queries (database cleanup)
  • Removed 6+ unnecessary scripts and meta tags from your <head> (resource cleanup)

On the last WooCommerce store where I applied all of these changes together, the results were:

  • LCP (Largest Contentful Paint): from 4.2s to 1.8s
  • Total page weight: from 3.8MB to 1.1MB
  • Number of HTTP requests: from 47 to 22
  • PageSpeed Insights score: from 38 to 91

No caching plugin. No optimization plugin. No CDN (though you should use one too). Just fundamentals.

One Last Thing

I want to be clear: I am not saying plugins are bad. There are excellent caching plugins and CDN integrations that absolutely have their place. What I am saying is that installing plugins before fixing the basics is like putting a turbocharger on a car with flat tires.

Fix the tires first. Then add the turbo.

The steps in this guide are the tires. They are the foundational performance wins that every WordPress and WooCommerce site should have, regardless of what plugins you add on top. And the best part is that these changes are permanent. They do not depend on a plugin being maintained, updated, or compatible with your next theme.

Your code, your performance, your control.

Happy coding :D