Image Converter for WebP Security & Risk Analysis

wordpress.org/plugins/image-converter-webp

Convert your WordPress JPG and PNG images to efficient WebP format, improving performance, reducing file size, and enhancing website speed.

2K active installs v1.4.0 PHP 7.4+ WP 4.0+ Updated Dec 27, 2025
convertimagejpegpngwebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Converter for WebP Safe to Use in 2026?

Generally Safe

Score 100/100

Image Converter for WebP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'image-converter-webp' plugin version 1.4.0 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, SQL injection vulnerabilities due to the exclusive use of prepared statements, and all output being properly escaped. The presence of nonce checks adds a layer of protection against common cross-site request forgery attacks. The absence of external HTTP requests and taint analysis findings further mitigates risks related to code execution and data exfiltration. The plugin also boasts a clean vulnerability history with zero recorded CVEs, indicating a history of responsible development and maintenance.

However, a notable area for potential concern is the complete absence of capability checks for any of its entry points. While the current attack surface is zero, this indicates that if any entry points were to be introduced in future updates or if the analysis missed any, they would likely be unprotected by WordPress's role-based access control. Furthermore, the presence of two file operations, while not inherently risky without further context, warrants a brief mention as this is an area that can sometimes lead to vulnerabilities if not handled with extreme care, especially regarding path traversal or improper file handling. Overall, the plugin is very secure as of version 1.4.0, but the lack of capability checks is a weakness that could become more significant if the plugin's functionality expands.

Key Concerns

  • No capability checks present
  • File operations present (potential risk)
Vulnerabilities
None known

Image Converter for WebP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Converter for WebP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
2
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

Image Converter for WebP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_noticesimage-converter-webp.php:71
actionadmin_initinc\Services\Admin.php:27
actionadmin_menuinc\Services\Admin.php:28
actionadmin_enqueue_scriptsinc\Services\Admin.php:29
actioninitinc\Services\Boot.php:25
actionicfw_convertinc\Services\Logger.php:25
actionadd_attachmentinc\Services\Main.php:25
filterwp_generate_attachment_metadatainc\Services\Main.php:26
actiondelete_attachmentinc\Services\Main.php:27
filterattachment_fields_to_editinc\Services\Main.php:28
filterwp_prepare_attachment_for_jsinc\Services\Main.php:29
actionicfw_convertinc\Services\MetaData.php:25
actionicfw_convertinc\Services\MetaData.php:26
filterrender_blockinc\Services\PageLoad.php:26
filterwp_get_attachment_imageinc\Services\PageLoad.php:27
filterpost_thumbnail_htmlinc\Services\PageLoad.php:28
Maintenance & Trust

Image Converter for WebP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 27, 2025
PHP min version7.4
Downloads11K

Community Trust

Rating100/100
Number of ratings4
Active installs2K
Developer Profile

Image Converter for WebP Developer Profile

badasswp

13 plugins · 5K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Converter for WebP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-converter-webp/styles.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Image Converter for WebP