
Media Webp Security & Risk Analysis
wordpress.org/plugins/media-webpAutomatically creates webp images when you upload compatible media. This plugin also manages any updates and changes to the linked attachment images.
Is Media Webp Safe to Use in 2026?
Generally Safe
Score 85/100Media Webp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "media-webp" v1.0.3 plugin demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection risks through prepared statements, and fully escaped output are excellent indicators of secure coding practices. The presence of nonce checks further mitigates common attack vectors for its single AJAX handler. The plugin also boasts a clean vulnerability history, with no known CVEs, suggesting a history of secure development and maintenance.
However, the lack of capability checks on the AJAX handler presents a potential concern. While nonce checks help prevent cross-site request forgery, they do not restrict access based on user roles. An authenticated attacker with lower privileges might be able to trigger the AJAX action. Despite this single area for improvement, the overall security of the plugin appears to be very good, with no critical or high-severity issues identified in the static analysis or vulnerability history.
Key Concerns
- Missing capability checks on AJAX handler
Media Webp Security Vulnerabilities
Media Webp Release Timeline
Media Webp Code Analysis
Output Escaping
Media Webp Attack Surface
AJAX Handlers 1
WordPress Hooks 25
Maintenance & Trust
Media Webp Maintenance & Trust
Maintenance Signals
Community Trust
Media Webp Alternatives
OrigiSafe — Advanced Image Optimizer (WebP) — Keep Originals Safe
origisafe-advanced-image-optimizer
Convert JPG/PNG uploads (and existing library) to WebP, move originals to /uploads/_originals/, and update Media Library metadata - WP serves .webp
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1‑click: compress, resize & convert to WebP/AVIF - free up to 20MB/month. Enjoy the easiest WordPress image optimizer to set up.
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN
wp-smushit
Compress and optimize images, enable lazy load, serve WebP & AVIF, and speed up your site with a global image CDN.
Converter for Media – Optimize images | Convert WebP & AVIF
webp-converter-for-media
Speed up your website by using our WebP & AVIF Converter. Optimize images and serve WebP and AVIF images instead of standard formats!
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
shortpixel-image-optimiser
Optimize images & PDFs smartly. Create and compress next-gen WebP and AVIF formats. Smart crop and resize.
Media Webp Developer Profile
1 plugin · 90 total installs
How We Detect Media Webp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-webp/assets/css/tools.css/wp-content/plugins/media-webp/assets/js/tools.js/wp-content/plugins/media-webp/assets/js/tools.jsmedia-webp/assets/js/tools.js?ver=1.0.0HTML / DOM Fingerprints
media_wtsdata-mediawebp-iddata-mediawebp-webp-idmedia_webp_object