LehmannLabs WebP Optimizer Security & Risk Analysis

wordpress.org/plugins/lehmannlabs-webp-optimizer

Improve page speed in WordPress with a free WebP optimizer for Elementor workflows. No ads, no tracking, no paid upsells.

0 active installs v1.0.0 PHP 7.4+ WP 6.2+ Updated Mar 19, 2026
elementorimagesoptimizationperformancewebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LehmannLabs WebP Optimizer Safe to Use in 2026?

Generally Safe

Score 100/100

LehmannLabs WebP Optimizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The lehmannlabs-webp-optimizer plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices concerning SQL queries, which are exclusively executed using prepared statements, and all output is properly escaped. There are no recorded historical vulnerabilities, suggesting a generally well-maintained codebase. However, a significant concern arises from the extensive attack surface exposed by AJAX handlers. All six identified AJAX handlers lack authentication checks, presenting a substantial risk. While taint analysis revealed no issues, indicating no evident flows with unsanitized paths or critical/high severity issues, the absence of authorization on these entry points could still lead to unauthorized actions if the functions they trigger are sensitive or can be manipulated.

The plugin's lack of historical vulnerabilities is a positive indicator. However, this does not negate the risks introduced by the unprotected AJAX endpoints. The presence of nonce checks and capability checks on some functions is encouraging, but their absence on the AJAX handlers is a critical oversight. The plugin's strengths lie in its secure handling of database interactions and output rendering. The primary weakness is the direct exposure of functionality via AJAX without proper authorization mechanisms, which could be exploited by unauthenticated users to trigger unintended actions within the plugin.

Key Concerns

  • 6 AJAX handlers without auth checks
  • Large attack surface without auth
Vulnerabilities
None known

LehmannLabs WebP Optimizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LehmannLabs WebP Optimizer Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

LehmannLabs WebP Optimizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
0
135 escaped
Nonce Checks
3
Capability Checks
7
File Operations
7
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

100% escaped135 total outputs
Attack Surface
6 unprotected

LehmannLabs WebP Optimizer Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_slimage_optimize_batchincludes/class-slimage-admin.php:25
authwp_ajax_slimage_restore_batchincludes/class-slimage-admin.php:26
authwp_ajax_slimage_delete_webp_batchincludes/class-slimage-admin.php:27
authwp_ajax_slimage_repair_paths_batchincludes/class-slimage-admin.php:28
authwp_ajax_slimage_repair_metadata_batchincludes/class-slimage-admin.php:29
authwp_ajax_slimage_conversion_statusincludes/class-slimage-admin.php:30
WordPress Hooks 15
actionadmin_menuincludes/class-slimage-admin.php:20
actionadmin_initincludes/class-slimage-admin.php:21
actionadmin_enqueue_scriptsincludes/class-slimage-admin.php:22
actionadmin_noticesincludes/class-slimage-admin.php:23
filtermedia_row_actionsincludes/class-slimage-admin.php:32
filtersite_status_testsincludes/class-slimage-admin.php:33
actionadmin_post_slimage_restore_singleincludes/class-slimage-admin.php:34
actionadmin_post_slimage_delete_backupincludes/class-slimage-admin.php:35
actionplugins_loadedincludes/class-slimage-optimizer.php:32
filterwp_generate_attachment_metadataincludes/class-slimage-optimizer.php:46
filterwp_get_attachment_imageincludes/class-slimage-output.php:19
filterwp_get_attachment_urlincludes/class-slimage-output.php:20
filterwp_get_attachment_image_srcincludes/class-slimage-output.php:21
filterwp_calculate_image_srcsetincludes/class-slimage-output.php:22
filterthe_contentincludes/class-slimage-output.php:23
Maintenance & Trust

LehmannLabs WebP Optimizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 19, 2026
PHP min version7.4
Downloads69

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LehmannLabs WebP Optimizer Developer Profile

lehmannlabs

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LehmannLabs WebP Optimizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lehmannlabs-webp-optimizer/assets/js/admin-tools.js
Script Paths
/wp-content/plugins/lehmannlabs-webp-optimizer/assets/js/admin-tools.js
Version Parameters
lehmannlabs-webp-optimizer/assets/js/admin-tools.js?ver=

HTML / DOM Fingerprints

JS Globals
SLIMAGE_TOOLS
FAQ

Frequently Asked Questions about LehmannLabs WebP Optimizer