
Support SVG – Upload svg files in wordpress without hassle Security & Risk Analysis
wordpress.org/plugins/support-svgThis plugin will help you to upload svg format image in WordPress media library regardless of the theme. That is, it works with every theme.
Is Support SVG – Upload svg files in wordpress without hassle Safe to Use in 2026?
Generally Safe
Score 99/100Support SVG – Upload svg files in wordpress without hassle has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "support-svg" plugin v1.1.3 demonstrates a generally strong security posture in its static analysis. It adheres to best practices by utilizing prepared statements for all SQL queries, ensuring proper output escaping, and having no identified critical or high severity taint flows. The absence of a significant attack surface with unprotected entry points is also a positive indicator. However, the plugin's vulnerability history is a significant concern. With two known medium severity CVEs, both related to Cross-Site Scripting (XSS), the plugin has shown a pattern of introducing vulnerabilities that could allow for malicious code injection. The fact that the last vulnerability was relatively recent (November 2024) and is currently unpatched, despite the version number being higher, suggests a potential ongoing issue with code quality or a lack of timely security updates.
While the current static analysis is clean, the historical vulnerability data strongly suggests that this plugin should be treated with caution. The two medium severity XSS vulnerabilities indicate a recurring weakness in input sanitization or output encoding, which could be present in subtle ways not caught by the current static analysis or that have been fixed in this specific version but indicate a higher likelihood of future issues. The absence of capability checks and nonce checks on potential AJAX or REST API endpoints (though none are currently identified) leaves a theoretical gap for future vulnerabilities if these features are added without proper security controls. Therefore, despite the promising static analysis, the plugin's past security record necessitates a degree of skepticism and careful monitoring.
Key Concerns
- Two medium severity XSS vulnerabilities in history
- Historically prone to XSS, lack of recent patch
- No capability checks
- No nonce checks
Support SVG – Upload svg files in wordpress without hassle Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Support SVG – Upload svg files in wordpress without hassle <= 1.1.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG File Upload
Support SVG <= 1.0.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG
Support SVG – Upload svg files in wordpress without hassle Release Timeline
Support SVG – Upload svg files in wordpress without hassle Code Analysis
Support SVG – Upload svg files in wordpress without hassle Attack Surface
WordPress Hooks 6
Maintenance & Trust
Support SVG – Upload svg files in wordpress without hassle Maintenance & Trust
Maintenance Signals
Community Trust
Support SVG – Upload svg files in wordpress without hassle Alternatives
Secure SVG Upload
secure-svg
Safely upload SVG files in WordPress with robust SVG support and automatic sanitization.
Safe SVG
safe-svg
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Lord of the Files: Enhanced Upload Security
blob-mimes
This plugin expands file-related security and sanity around the upload process.
Upload SVG
upload-svg
Safely enable SVG uploads with sanitization and prevent XML/SVG vulnerabilities on your WordPress website. Preview SVG files in your Media Library.
OH MY Svg
oh-my-svg
Add any svg to your website with the superpowers of the block editor. Out-of-the-box security and speed optimization!
Support SVG – Upload svg files in wordpress without hassle Developer Profile
4 plugins · 10K total installs
How We Detect Support SVG – Upload svg files in wordpress without hassle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/support-svg/assets/css/admin.css/wp-content/plugins/support-svg/assets/js/admin.js/wp-content/plugins/support-svg/assets/js/admin.jssupport-svg/assets/css/admin.css?ver=support-svg/assets/js/admin.js?ver=