Plus WebP or AVIF Security & Risk Analysis

wordpress.org/plugins/plus-webp

Generate WebP or AVIF.

5K active installs v5.11 PHP 8.1+ WP 6.6+ Updated Mar 29, 2026
avifmediauploadwebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plus WebP or AVIF Safe to Use in 2026?

Generally Safe

Score 100/100

Plus WebP or AVIF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plus-webp v5.11 plugin exhibits a strong static security posture with zero identified entry points, dangerous functions, file operations, or external HTTP requests. The code analysis indicates excellent practices regarding output escaping, with 100% of outputs being properly sanitized, and no critical or high severity taint analysis findings were present, suggesting a low risk of direct code injection or data leakage through untrusted input. Furthermore, the plugin has no recorded vulnerability history, with zero CVEs reported across all severities. This indicates a generally well-maintained and secure plugin.

Despite the strong static analysis, there are potential areas of concern that, while not currently manifesting as identified vulnerabilities, warrant attention. The plugin has zero capability checks and zero nonce checks. While the current attack surface is reported as zero, this could change with future updates or if new entry points are introduced. The complete absence of these security measures means that if any new, unauthenticated entry points were to be introduced in the future, they would be immediately exploitable. The plugin also uses raw SQL queries without prepared statements, which introduces a risk of SQL injection if the data used in these queries is not meticulously sanitized, though no such flows were detected in this analysis.

Key Concerns

  • Raw SQL without prepared statements
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Plus WebP or AVIF Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Plus WebP or AVIF Release Timeline

v5.11Current
v5.10
v5.04
v5.03
v5.02
v5.01
v5.00
v4.20
v4.11
v4.10
v4.09
v4.08
v4.07
v4.06
v4.05
v4.04
v4.03
v4.02
v4.01
v4.00
Code Analysis
Analyzed Mar 16, 2026

Plus WebP or AVIF Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries
Attack Surface

Plus WebP or AVIF Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Plus WebP or AVIF Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 29, 2026
PHP min version8.1
Downloads68K

Community Trust

Rating92/100
Number of ratings26
Active installs5K
Developer Profile

Plus WebP or AVIF Developer Profile

Katsushi Kawamori

54 plugins · 56K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
178 days
View full developer profile
Detection Fingerprints

How We Detect Plus WebP or AVIF

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/plus-webp/lib/js/plus-webp.js/wp-content/plugins/plus-webp/css/plus-webp-style.css
Script Paths
/wp-content/plugins/plus-webp/lib/js/plus-webp.js
Version Parameters
plus-webp/lib/js/plus-webp.js?ver=plus-webp-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
plus-webp-backgroundplus-webp-images
HTML Comments
Plus WebP
Data Attributes
data-plus-webp-src
JS Globals
plus_webp_data
FAQ

Frequently Asked Questions about Plus WebP or AVIF