atec WebP Security & Risk Analysis

wordpress.org/plugins/atec-webp

Auto convert all BMP, GIF, PNG & JPEG images into the much better WebP format. Supports the GD & ImageMagick libraries.

50 active installs v1.1.30 PHP 7.4+ WP 4.9+ Updated Mar 24, 2026
auto-convert-all-bmpgifpng-jpeg-images-into-the-much-better-webp-format-supports-the-gd-imagemagick-libraries
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is atec WebP Safe to Use in 2026?

Generally Safe

Score 100/100

atec WebP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'atec-webp' plugin v1.1.29 exhibits a generally strong security posture based on the provided static analysis. The code demonstrates excellent practices with 100% of SQL queries using prepared statements and nearly all output being properly escaped. The absence of critical or high-severity taint flows and a clean vulnerability history are also positive indicators. However, a significant concern exists due to a single AJAX handler that lacks authentication checks. This unprotected entry point represents a potential avenue for malicious actors to interact with the plugin in ways not intended by the developer, potentially leading to unauthorized actions or information disclosure.

While the plugin has no recorded CVEs and a clean history, this does not negate the risk posed by the unprotected AJAX endpoint. The developer has demonstrated good coding hygiene in other areas, but this single oversight could still be exploited if a vulnerability exists within that specific handler's functionality. The overall risk is moderate, with the primary weakness being the identified lack of authorization on an exposed entry point.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

atec WebP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

atec WebP Release Timeline

v1.1.30Current
v1.1.29
v1.1.28
v1.1.25
v1.1.24
v1.1.23
v1.1.22
v1.1.21
v1.1.20
v1.1.19
v1.1.18
v1.1.17
v1.1.16
v1.1.15
v1.1.14
v1.1.12
v1.1.10
v1.1.8
v1.1.7
v1.1.6
Code Analysis
Analyzed Mar 16, 2026

atec WebP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
324 escaped
Nonce Checks
2
Capability Checks
5
File Operations
14
External Requests
1
Bundled Libraries
0

Output Escaping

98% escaped329 total outputs
Attack Surface
1 unprotected

atec WebP Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_atec_admin_notice_dismissincludes\ATEC\LOADER.php:109
WordPress Hooks 6
actionadmin_menuatec-webp.php:29
actionadmin_enqueue_scriptsincludes\ATEC\INIT.php:564
actionadmin_noticesincludes\ATEC\INIT.php:647
actionadmin_footerincludes\ATEC\INIT.php:688
actionadmin_noticesincludes\ATEC\INIT.php:720
actionadmin_enqueue_scriptsincludes\atec-wpwp-install.php:6
Maintenance & Trust

atec WebP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 24, 2026
PHP min version7.4
Downloads5K

Community Trust

Rating90/100
Number of ratings2
Active installs50
Developer Profile

atec WebP Developer Profile

docjojo

17 plugins · 5K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect atec WebP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atec-webp/admin/assets/css/admin.css/wp-content/plugins/atec-webp/admin/assets/js/admin.js/wp-content/plugins/atec-webp/includes/ATEC/assets/css/tools.css/wp-content/plugins/atec-webp/includes/ATEC/assets/js/tools.js/wp-content/plugins/atec-webp/assets/css/atec-webp.css/wp-content/plugins/atec-webp/assets/js/atec-webp.js
Script Paths
/wp-content/plugins/atec-webp/admin/assets/js/admin.js/wp-content/plugins/atec-webp/includes/ATEC/assets/js/tools.js/wp-content/plugins/atec-webp/assets/js/atec-webp.js
Version Parameters
atec-webp/admin/assets/css/admin.css?ver=atec-webp/admin/assets/js/admin.js?ver=atec-webp/includes/ATEC/assets/css/tools.css?ver=atec-webp/includes/ATEC/assets/js/tools.js?ver=atec-webp/assets/css/atec-webp.css?ver=atec-webp/assets/js/atec-webp.js?ver=

HTML / DOM Fingerprints

CSS Classes
atec-admin-bar-row
JS Globals
ATEC
FAQ

Frequently Asked Questions about atec WebP