
AVIF Uploader Security & Risk Analysis
wordpress.org/plugins/avif-supportAVIF support plugin aims to support avif images in WordPress by overcome wp issues and limits regarding uploading, displaying and generating avif and …
Is AVIF Uploader Safe to Use in 2026?
Generally Safe
Score 91/100AVIF Uploader has a strong security track record. Known vulnerabilities have been patched promptly.
The avif-support plugin v1.1.2 presents a generally good security posture due to its minimal attack surface and strong adherence to secure coding practices. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the code shows a commendable commitment to security with 100% of SQL queries utilizing prepared statements and a high rate of properly escaped output (90%). Nonce and capability checks are present, albeit limited in number due to the plugin's simple functionality.
However, a historical vulnerability related to Cross-Site Scripting (XSS) indicates a past weakness in input sanitization or output encoding. While this specific vulnerability is now patched (as there are 0 currently unpatched CVEs), the pattern suggests that previous versions may have had issues that required remediation. The presence of a medium severity CVE in its history, even if patched, warrants continued vigilance. The plugin's reliance on the Select2 library also introduces a potential risk if this library is not kept up-to-date by the plugin author, as bundled libraries can become attack vectors if they contain known vulnerabilities.
In conclusion, avif-support v1.1.2 demonstrates good secure coding practices, particularly in handling database interactions and output. Its limited attack surface is a major strength. The primary concern stems from its past XSS vulnerability, which, despite being resolved, highlights the importance of ongoing security audits and prompt patching of any future issues. The management of bundled libraries is also a minor area for potential concern.
Key Concerns
- Past medium severity XSS vulnerability
- Bundled library (Select2) may require updates
AVIF Uploader Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AVIF & SVG Uploader <= 1.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
AVIF Uploader Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
AVIF Uploader Attack Surface
WordPress Hooks 21
Maintenance & Trust
AVIF Uploader Maintenance & Trust
Maintenance Signals
Community Trust
AVIF Uploader Alternatives
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1-click: compress images, convert to WebP & AVIF, resize, and boost your site with the easiest WordPress image optimization plugin!
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization
shortpixel-adaptive-images
Start serving properly sized, smart cropped & optimized images, plus CSS, JS and fonts from our CDN with a click; Automatic AVIF & WebP support.
Pressidium Performance
pressidium-performance
Speed up your WordPress site, improve Core Web Vitals and enhance user experience with one-click image optimization, CSS & JavaScript minification.
Automatic Image Optimizer & CDN by wpimg.io
automatic-image-optimizer-cdn
Instantly speed up your site with automated image optimization, WebP/AVIF, and global CDN. Zero setup required.
AVIF Uploader Developer Profile
20 plugins · 9K total installs
How We Detect AVIF Uploader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/avif-support/assets/css/avif-support-admin-style.css/wp-content/plugins/avif-support/assets/js/avif-support-admin-script.js/wp-content/plugins/avif-support/assets/css/avif-support-style.css/wp-content/plugins/avif-support/assets/js/avif-support-admin-script.jsavif-support/assets/css/avif-support-admin-style.css?ver=avif-support/assets/js/avif-support-admin-script.js?ver=avif-support/assets/css/avif-support-style.css?ver=HTML / DOM Fingerprints
gpls-avfstw-welcome-messagegpls-avfstw-settings-pagedata-gpls-avfstw-qualitydata-gpls-avfstw-speeddata-gpls-avfstw-packageavif_support_data