
Image Compressor WebP by htmlrunner Security & Risk Analysis
wordpress.org/plugins/image-compressor-webp-by-htmlrunnerConvert your media library images to WebP format — fully on your own server, with zero data shared externally.
Is Image Compressor WebP by htmlrunner Safe to Use in 2026?
Generally Safe
Score 100/100Image Compressor WebP by htmlrunner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'image-compressor-webp-by-htmlrunner' plugin version 1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and it has no recorded vulnerability history, suggesting a generally well-maintained codebase. The absence of external HTTP requests and taint analysis revealing no critical or high severity flows is also reassuring. However, a significant concern lies in its attack surface. The plugin exposes one AJAX handler that lacks any authentication checks, creating a direct entry point for potential attackers. Furthermore, while nonces are present in some areas, the lack of capability checks for entry points is a critical oversight that leaves these functions open to unauthorized access. The relatively low percentage of properly escaped output also introduces a risk of cross-site scripting (XSS) vulnerabilities, although the absence of taint flows with unsanitized paths mitigates this to some extent.
Overall, while the plugin avoids common pitfalls like raw SQL and known vulnerabilities, the unprotected AJAX handler is a serious security flaw that needs immediate attention. The lack of capability checks for entry points significantly weakens its security. The mixed output escaping suggests potential for XSS if further analysis were to reveal specific vulnerabilities. The absence of a vulnerability history is a good sign, but it doesn't negate the risks identified in the static analysis. A balanced conclusion is that the plugin has potential strengths in its database interaction and lack of historical vulnerabilities, but its current implementation has a critical security gap with its unprotected AJAX handler and insufficient capability checks for entry points.
Key Concerns
- AJAX handler without auth checks
- No capability checks on entry points
- Unescaped output detected
Image Compressor WebP by htmlrunner Security Vulnerabilities
Image Compressor WebP by htmlrunner Code Analysis
Output Escaping
Data Flow Analysis
Image Compressor WebP by htmlrunner Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
Image Compressor WebP by htmlrunner Maintenance & Trust
Maintenance Signals
Community Trust
Image Compressor WebP by htmlrunner Alternatives
Image Optimizer PRO – Optimize Images, Convert AVIF & WebP
image-optimizer-pro
Optimize and serve your images in AVIF or webp format on-the-fly, boosting site performance and decreasing load times with our network distribution.
Auto WebP & Alt Optimizer
auto-webp-alt-optimizer
Automatically convert uploaded images to WebP format using native GD library for maximum compatibility, and auto-fill image Alt text for better SEO.
JPrompt's Pixengine – Image Converter & Optimizer
jprompts-pixengine
Automatically convert and optimize images to WebP and AVIF formats with intelligent resizing, lazy loading, and caching. Boost page speed by 40-70% wi …
Toolszu Image Optimizer
toolszu-image-optimizer
Toolszu Image Optimizer is a lightweight WordPress image compression, resizing, and WebP conversion plugin designed for content writers, bloggers, and …
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
Image Compressor WebP by htmlrunner Developer Profile
1 plugin · 0 total installs
How We Detect Image Compressor WebP by htmlrunner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-compressor-webp-by-htmlrunner/webp.js/wp-content/plugins/image-compressor-webp-by-htmlrunner/webp-style.css/wp-content/plugins/image-compressor-webp-by-htmlrunner/webp.jsimage-compressor-webp-by-htmlrunner/webp.js?ver=1.0image-compressor-webp-by-htmlrunner/webp-style.css?ver=HTML / DOM Fingerprints
wpc-wrapwpc-bulk-barbulk-infowpc-global-progresswpc-global-barwpc-btn-primarywpc-headerwpc-stats-mini+23 moredata-idWPC