
Disable WebP Security & Risk Analysis
wordpress.org/plugins/disable-webpA small plugin to disable the new WebP standard in the settings.
Is Disable WebP Safe to Use in 2026?
Generally Safe
Score 85/100Disable WebP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'disable-webp' plugin v1.0.3 exhibits a generally good security posture with no identified vulnerabilities in its history and a seemingly small attack surface. The static analysis reveals no dangerous functions, no raw SQL queries, and all SQL queries are performed using prepared statements. The presence of a nonce check is also a positive sign. However, a significant concern arises from the output escaping. With 11 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts into the WordPress admin area or publicly viewable parts of the site through improperly handled output. The lack of any recorded historical vulnerabilities might suggest either a very niche plugin with low visibility to attackers or that past security oversights haven't yet been publicly disclosed or exploited. Despite the lack of critical technical flaws like unsanitized taint flows or raw SQL, the pervasive unescaped output represents a serious, evidence-backed security weakness that could be easily exploited.
Key Concerns
- All outputs are unescaped
Disable WebP Security Vulnerabilities
Disable WebP Code Analysis
Output Escaping
Disable WebP Attack Surface
WordPress Hooks 2
Maintenance & Trust
Disable WebP Maintenance & Trust
Maintenance Signals
Community Trust
Disable WebP Alternatives
Disable WebP By Default
disable-webp-by-default
A small plugin to control WebP image creation when JPEG images are uploaded.
Disable Media Sizes
disable-media-sizes
Provides options to disable the extra images generated by WordPress.
Support WebP – Upload webp files in wordpress without hassle
support-webp
This plugin will help you to upload webp format image in WordPress media library regardless of the theme. That is, it works with every theme.
Image Converter for WebP
image-converter-webp
Convert your WordPress JPG and PNG images to efficient WebP format, improving performance, reducing file size, and enhancing website speed.
HEIC to JPEG
heic-to-jpeg
Convert HEIC images to JPEG format when upload to the Media Library.
Disable WebP Developer Profile
2 plugins · 100 total installs
How We Detect Disable WebP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.