
Plus WebP or AVIF Security & Risk Analysis
wordpress.org/plugins/plus-webpGenerate WebP or AVIF.
Is Plus WebP or AVIF Safe to Use in 2026?
Generally Safe
Score 100/100Plus WebP or AVIF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plus-webp v5.11 plugin exhibits a strong static security posture with zero identified entry points, dangerous functions, file operations, or external HTTP requests. The code analysis indicates excellent practices regarding output escaping, with 100% of outputs being properly sanitized, and no critical or high severity taint analysis findings were present, suggesting a low risk of direct code injection or data leakage through untrusted input. Furthermore, the plugin has no recorded vulnerability history, with zero CVEs reported across all severities. This indicates a generally well-maintained and secure plugin.
Despite the strong static analysis, there are potential areas of concern that, while not currently manifesting as identified vulnerabilities, warrant attention. The plugin has zero capability checks and zero nonce checks. While the current attack surface is reported as zero, this could change with future updates or if new entry points are introduced. The complete absence of these security measures means that if any new, unauthenticated entry points were to be introduced in the future, they would be immediately exploitable. The plugin also uses raw SQL queries without prepared statements, which introduces a risk of SQL injection if the data used in these queries is not meticulously sanitized, though no such flows were detected in this analysis.
Key Concerns
- Raw SQL without prepared statements
- Missing capability checks
- Missing nonce checks
Plus WebP or AVIF Security Vulnerabilities
Plus WebP or AVIF Release Timeline
Plus WebP or AVIF Code Analysis
SQL Query Safety
Plus WebP or AVIF Attack Surface
Maintenance & Trust
Plus WebP or AVIF Maintenance & Trust
Maintenance Signals
Community Trust
Plus WebP or AVIF Alternatives
Image Ninja – Convert Images to WebP & AVIF on Upload
image-ninja
Automatically convert JPEG and PNG images to WebP and AVIF formats during upload to optimize your WordPress site’s performance.
Hedef Image Optimizer — WebP & AVIF
hedef-image-optimizer-webp-avif
Converts JPEG and PNG to modern WebP and AVIF formats, with bulk optimization and smart delivery.
Flux Media Optimizer – Image & Video Optimization by Flux Plugins
flux-media-optimizer
Automatically optimize images, compress videos and deliver media via global CDN. Boost Core Web Vitals and SEO with 50-70% smaller file sizes.
ImgSmaller – Optimize Images | Compress Images | Convert WebP & AVIF
imgsmaller
Compress and optimize your WordPress media library images using the ImgSmaller API with automated backups and restore controls.
TIO – The Image Optimizer – Smart Image Compression & Optimization, Built for the Web
nerdcow-the-image-optimizer
Automatically compress and convert your images to modern formats (WebP, AVIF). Get a perfectly optimized image every time and speed up your website.
Plus WebP or AVIF Developer Profile
54 plugins · 56K total installs
How We Detect Plus WebP or AVIF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plus-webp/lib/js/plus-webp.js/wp-content/plugins/plus-webp/css/plus-webp-style.css/wp-content/plugins/plus-webp/lib/js/plus-webp.jsplus-webp/lib/js/plus-webp.js?ver=plus-webp-style.css?ver=HTML / DOM Fingerprints
plus-webp-backgroundplus-webp-imagesPlus WebPdata-plus-webp-srcplus_webp_data