ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Security & Risk Analysis
wordpress.org/plugins/shortpixel-adaptive-imagesStart serving properly sized, smart cropped & optimized images, plus CSS, JS and fonts from our CDN with a click; Automatic AVIF & WebP support.
Is ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Safe to Use in 2026?
Generally Safe
Score 96/100ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization has a strong security track record. Known vulnerabilities have been patched promptly.
The shortpixel-adaptive-images plugin v3.11.1 presents a mixed security posture. While it demonstrates good practices in SQL query handling and avoids bundled libraries, significant concerns arise from its attack surface and output escaping. The plugin exposes a large number of AJAX handlers (15 total) with a concerning 14 of them lacking proper authorization checks, creating a substantial entry point for unauthenticated attackers. Furthermore, only 9% of its extensive output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially when combined with the unprotected AJAX endpoints. The taint analysis confirms this, revealing 3 high-severity flows, potentially exploitable through these unauthenticated routes. Despite having no currently unpatched CVEs, the plugin's history of 8 medium-severity vulnerabilities, including XSS, SSRF, CSRF, and authorization/access control issues, suggests a recurring pattern of security weaknesses. This history, coupled with the present code analysis findings, indicates that while the plugin authors are addressing past issues, fundamental security practices around input validation, authorization, and output escaping need significant improvement to mitigate current and future risks.
Key Concerns
- Large attack surface without auth checks
- High severity taint flows
- Low output escaping rate
- Use of unserialize
- Missing nonce checks on AJAX
- History of medium CVEs (8 total)
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.10.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via API URL
ShortPixel Adaptive Images <= 3.10.0 - Missing Authorization
ShortPixel Adaptive Images <= 3.8.3 - Authenticated (Admin+) Server-Side Request Forgery
ShortPixel Adaptive Images <= 3.8.3 - Cross-Site Request Forgery
ShortPixel Adaptive Images <= 3.8.2 - Missing Authorization in activate_ai_handler and deactivate_ai_handler
ShortPixel Adaptive Images <= 3.7.1 - Cross-Site Request Forgery via shortpixel_ai_handle_page_action
ShortPixel Adaptive Images <= 3.6.1 - Reflected Cross-Site Scripting
ShortPixel Adaptive Images <= 3.3.1 - Subscriber+ Arbitrary Settings Update
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Attack Surface
AJAX Handlers 15
WordPress Hooks 56
Maintenance & Trust
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Maintenance & Trust
Maintenance Signals
Community Trust
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Alternatives
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1-click: compress images, convert to WebP & AVIF, resize, and boost your site with the easiest WordPress image optimization plugin!
Optimole – Optimize Images in Real Time
optimole-wp
Automatically optimize images: bulk compression, lazy loading, WebP/AVIF conversion. With CloudFront image CDN to boost Core Web Vitals & conversions!
Pressidium Performance
pressidium-performance
Speed up your WordPress site, improve Core Web Vitals and enhance user experience with one-click image optimization, CSS & JavaScript minification.
JPrompt's Pixengine – Image Converter & Optimizer
jprompts-pixengine
Automatically convert and optimize images to WebP and AVIF formats with intelligent resizing, lazy loading, and caching. Boost page speed by 40-70% wi …
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization Developer Profile
8 plugins · 1.2M total installs
How We Detect ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortpixel-adaptive-images/assets/css/spai-main.css/wp-content/plugins/shortpixel-adaptive-images/assets/js/spai-main.js/wp-content/plugins/shortpixel-adaptive-images/assets/js/spai-admin.js/wp-content/plugins/shortpixel-adaptive-images/assets/js/spai-main.js/wp-content/plugins/shortpixel-adaptive-images/assets/js/spai-admin.jsshortpixel-adaptive-images/assets/css/spai-main.css?ver=shortpixel-adaptive-images/assets/js/spai-main.js?ver=shortpixel-adaptive-images/assets/js/spai-admin.js?ver=HTML / DOM Fingerprints
spai-maindata-spai-loaddata-spai-srcdata-spai-bgShortPixelAIspai_settings/wp-json/spai/v1/optimize