
Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions Security & Risk Analysis
wordpress.org/plugins/soovex-webp-converterAutomatically convert WordPress images to WebP format. Optimize images, boost page speed and SEO with unlimited conversions and smart backups.
Is Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions Safe to Use in 2026?
Generally Safe
Score 100/100Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The soovex-webp-converter plugin v1.0.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates excellent adherence to secure coding practices, with 100% of its identified entry points (AJAX handlers) protected by authentication checks. Furthermore, the extensive use of prepared statements for SQL queries (78%) and proper output escaping (97%) significantly mitigates common web vulnerabilities like SQL injection and cross-site scripting (XSS). The absence of known CVEs and a clean vulnerability history further reinforce its current security.
However, a few areas warrant attention. The analysis reveals two flows with unsanitized paths. While these are not flagged as critical or high severity in the taint analysis, unsanitized paths can potentially lead to directory traversal or other file-related vulnerabilities if exploited. The plugin also performs 27 file operations, which, in combination with unsanitized paths, could represent a risk if not handled with extreme care. The overall attack surface is concentrated within its 24 AJAX handlers, all of which are protected, indicating a good control mechanism for this aspect.
In conclusion, soovex-webp-converter v1.0.2 is a well-developed plugin from a security perspective, with robust authentication and data handling practices. The primary, albeit minor, concern lies with the two identified flows containing unsanitized paths, which should be investigated and remediated to ensure complete security.
Key Concerns
- Flows with unsanitized paths found
Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions Security Vulnerabilities
Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions Attack Surface
AJAX Handlers 24
WordPress Hooks 28
Scheduled Events 10
Maintenance & Trust
Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions Maintenance & Trust
Maintenance Signals
Community Trust
Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions Alternatives
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
quickwebp
QuickWebP is a free WordPress plugin that converts images to WebP, optimizes performance, improves SEO, auto-fills metadata, and resizes images—no API …
IMJOLWP Image Optimizer
imjolwp-image-optimizer
IMJOLWP Image Optimizer automatically converts uploaded images (JPG, PNG, GIF) to WebP format without changing the original image URL, improving page …
Image Squeeze – Optimize WebP, Compress Images, Boost Performance
imagesqueeze
Smart image optimization for WordPress. Compress, convert to WebP, and speed up your site while improving Core Web Vitals and SEO.
GioCompress
giocompress
WordPress plugin for smart image optimization. Auto-converts to WebP, includes smart lazy loading, and generates missing alt text for better SEO.
Media WebP Converter
media-webp-converter
Converts all media images to WebP format with options to overwrite originals, control output image quality, and optionally generate new attachments.
Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions Developer Profile
1 plugin · 80 total installs
How We Detect Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/soovex-webp-converter/assets/css/webp-cp-admin-style.css/wp-content/plugins/soovex-webp-converter/assets/css/webp-cp-dashboard.css/wp-content/plugins/soovex-webp-converter/assets/css/webp-cp-settings.css/wp-content/plugins/soovex-webp-converter/assets/js/webp-cp-admin.js/wp-content/plugins/soovex-webp-converter/assets/js/webp-cp-dashboard.js/wp-content/plugins/soovex-webp-converter/assets/js/webp-cp-settings.js/wp-content/plugins/soovex-webp-converter/assets/js/webp-cp-media-library.jsassets/icon.svgsoovex-webp-converter/assets/css/webp-cp-admin-style.css?ver=soovex-webp-converter/assets/css/webp-cp-dashboard.css?ver=soovex-webp-converter/assets/css/webp-cp-settings.css?ver=soovex-webp-converter/assets/js/webp-cp-admin.js?ver=soovex-webp-converter/assets/js/webp-cp-dashboard.js?ver=soovex-webp-converter/assets/js/webp-cp-settings.js?ver=soovex-webp-converter/assets/js/webp-cp-media-library.js?ver=HTML / DOM Fingerprints
webp-cp-dashboard-pagewebp-cp-activity-log-pagewebp-cp-settings-pagewebp-cp-help-pagewebp-cp-dashboard-wrapperwebp-cp-main-contentwebp-cp-sidebarwebp-cp-dashboard-widget+17 more<!-- Hide default dashicon ::before --><!-- Style the SVG image container - match WordPress menu icon container --><!-- Style the SVG image - proper alignment --><!-- Hover state - brighter -->+3 moredata-webp-cp-actiondata-webp-cp-noncedata-webp-cp-image-iddata-webp-cp-queue-idwebp_cp_admin_ajax_objectwebp_cp_localize_datawebp_cp_dashboard_paramswebp_cp_settings_paramswebp_cp_media_library_params