Media WebP Converter Security & Risk Analysis

wordpress.org/plugins/media-webp-converter

Converts all media images to WebP format with options to overwrite originals, control output image quality, and optionally generate new attachments.

0 active installs v1.0.0 PHP 7.4+ WP 5.6+ Updated Unknown
image-converterimage-optimizationmediaperformancewebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Media WebP Converter Safe to Use in 2026?

Generally Safe

Score 100/100

Media WebP Converter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The media-webp-converter plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests, coupled with the consistent use of prepared statements for database interactions, indicates a solid development foundation. Furthermore, the presence of nonce checks and a high percentage of properly escaped output are excellent security practices. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a well-maintained and secure codebase over time. The limited attack surface, comprised solely of AJAX handlers, and the fact that none are unprotected, further bolsters its security profile.

However, a minor area for attention is the complete lack of capability checks on its two AJAX entry points. While nonce checks are present, which help prevent CSRF attacks, the absence of capability checks means that any authenticated user, regardless of their role or permissions, could potentially trigger these AJAX actions. Although the taint analysis shows no critical or high severity issues, and the attack surface is small, relying solely on nonces for access control to AJAX actions is not as robust as incorporating role-based permission checks. Overall, the plugin is commendably secure, but the addition of capability checks would further harden its defenses against potential privilege escalation or unauthorized actions by lower-privileged authenticated users.

Key Concerns

  • Missing capability checks on AJAX handlers
  • 79% output escaping, some outputs unescaped
Vulnerabilities
None known

Media WebP Converter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Media WebP Converter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
34 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped43 total outputs
Attack Surface

Media WebP Converter Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_media_webp_converter_get_imagesmedia-webp-converter.php:330
authwp_ajax_media_webp_converter_convert_individual_imagemedia-webp-converter.php:370
WordPress Hooks 5
actionadmin_enqueue_scriptsmedia-webp-converter.php:49
actionadmin_menumedia-webp-converter.php:64
actiondelete_attachmentmedia-webp-converter.php:131
filtermedia_row_actionmedia-webp-converter.php:384
filterwp_generate_attachment_metadatamedia-webp-converter.php:420
Maintenance & Trust

Media WebP Converter Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads257

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Media WebP Converter Developer Profile

Subrata Sarkar

3 plugins · 0 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Media WebP Converter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/media-webp-converter/assets/mwcnv-admin.min.css/wp-content/plugins/media-webp-converter/assets/mwcnv-admin.min.js
Script Paths
/wp-content/plugins/media-webp-converter/assets/mwcnv-admin.min.js
Version Parameters
media-webp-converter/assets/mwcnv-admin.min.js?ver=media-webp-converter/assets/mwcnv-admin.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
mwc-table-default
JS Globals
MWCNV
FAQ

Frequently Asked Questions about Media WebP Converter