
AVIF Uploader Security & Risk Analysis
wordpress.org/plugins/avif-supportAVIF support plugin aims to support avif images in WordPress by overcome wp issues and limits regarding uploading, displaying and generating avif and …
Is AVIF Uploader Safe to Use in 2026?
Generally Safe
Score 99/100AVIF Uploader has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The avif-support plugin v1.1.2 presents a generally good security posture due to its minimal attack surface and strong adherence to secure coding practices. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the code shows a commendable commitment to security with 100% of SQL queries utilizing prepared statements and a high rate of properly escaped output (90%). Nonce and capability checks are present, albeit limited in number due to the plugin's simple functionality.
However, a historical vulnerability related to Cross-Site Scripting (XSS) indicates a past weakness in input sanitization or output encoding. While this specific vulnerability is now patched (as there are 0 currently unpatched CVEs), the pattern suggests that previous versions may have had issues that required remediation. The presence of a medium severity CVE in its history, even if patched, warrants continued vigilance. The plugin's reliance on the Select2 library also introduces a potential risk if this library is not kept up-to-date by the plugin author, as bundled libraries can become attack vectors if they contain known vulnerabilities.
In conclusion, avif-support v1.1.2 demonstrates good secure coding practices, particularly in handling database interactions and output. Its limited attack surface is a major strength. The primary concern stems from its past XSS vulnerability, which, despite being resolved, highlights the importance of ongoing security audits and prompt patching of any future issues. The management of bundled libraries is also a minor area for potential concern.
Key Concerns
- Past medium severity XSS vulnerability
- Bundled library (Select2) may require updates
AVIF Uploader Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AVIF & SVG Uploader <= 1.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
AVIF Uploader Release Timeline
AVIF Uploader Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
AVIF Uploader Attack Surface
WordPress Hooks 21
Maintenance & Trust
AVIF Uploader Maintenance & Trust
Maintenance Signals
Community Trust
AVIF Uploader Alternatives
Image Optimization – Compress Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
Imagify Image Optimization: Optimize Images | Compress & Convert to WebP/AVIF
imagify
Image optimization in 1‑click: compress, resize & convert to WebP/AVIF – free up to 20MB/month. Enjoy the easiest WordPress image optimizer to set up.
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
optimole-wp
Automatically optimize images with bulk compression, lazy loading, WebP/AVIF conversion & CloudFront image CDN. Boost Core Web Vitals & conversions.
Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF
robin-image-optimizer
Unlimited automatic image optimization for WordPress. Compress images, convert to WebP, and improve site speed without losing image quality.
Kraken.io Image Optimizer – Compress, Convert to WebP & AVIF, Resize & Bulk Optimize
kraken-image-optimizer
Optimize images automatically — compress, resize and convert to WebP, AVIF & more with Kraken.io. Faster pages, smaller files, same quality.
AVIF Uploader Developer Profile
22 plugins · 10K total installs
How We Detect AVIF Uploader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/avif-support/assets/css/avif-support-admin-style.css/wp-content/plugins/avif-support/assets/js/avif-support-admin-script.js/wp-content/plugins/avif-support/assets/css/avif-support-style.css/wp-content/plugins/avif-support/assets/js/avif-support-admin-script.jsavif-support/assets/css/avif-support-admin-style.css?ver=avif-support/assets/js/avif-support-admin-script.js?ver=avif-support/assets/css/avif-support-style.css?ver=HTML / DOM Fingerprints
gpls-avfstw-welcome-messagegpls-avfstw-settings-pagedata-gpls-avfstw-qualitydata-gpls-avfstw-speeddata-gpls-avfstw-packageavif_support_data