
SVG Support Security & Risk Analysis
wordpress.org/plugins/svg-supportSecurely upload SVG files to your media library, with built-in sanitization and advanced features for styling and animation.
Is SVG Support Safe to Use in 2026?
Generally Safe
Score 89/100SVG Support has a strong security track record. Known vulnerabilities have been patched promptly.
The svg-support v2.5.14 plugin exhibits a generally positive security posture with some notable exceptions. The static analysis reveals a small attack surface of only 2 AJAX handlers, both of which are protected by authentication checks, indicating good practice in limiting unauthorized access. The overwhelming majority of output is properly escaped, and nonce and capability checks are present on all identified entry points. File operations and external HTTP requests are also managed, suggesting careful handling of potentially sensitive actions. However, the plugin's history is a significant concern. It has a substantial number of known CVEs, all of which are medium severity and related to Cross-Site Scripting (XSS). While there are currently no unpatched vulnerabilities, the sheer volume of past XSS issues, including a recent one in 2025, suggests a recurring pattern of input sanitization weaknesses that the developers have struggled to fully resolve. Furthermore, the presence of SQL queries not utilizing prepared statements is a potential risk, although the low number of queries and the absence of taint flows are mitigating factors. The lack of any identified taint flows is a positive sign, implying that critical vulnerabilities are not being introduced in current development, but the historical pattern of XSS warrants caution.
Key Concerns
- SQL queries not using prepared statements
- 6 medium severity CVEs historically
SVG Support Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
SVG Support <= 2.5.8 - Stored Cross-Site Scripting via Vulnerability Dependency
SVG Support <= 2.5.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
SVG Support <= 2.5.7 - Authenticated (Author+) Cross-Site Scripting via SVG
SVG Support 2.5 - 2.5.1 - Insecure Plugin Defaults to Cross-Site Scripting
SVG Support <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scripting
SVG Support <= 2.3.19 Admin+ Cross-Site Scripting
SVG Support Code Analysis
SQL Query Safety
Output Escaping
SVG Support Attack Surface
AJAX Handlers 2
WordPress Hooks 35
Maintenance & Trust
SVG Support Maintenance & Trust
Maintenance Signals
Community Trust
SVG Support Alternatives
Safe SVG
safe-svg
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
WP SVG Images
wp-svg-images
Add SVG support to your WP website. Securely upload SVG files, automatic sanitization, Media Library preview.
SVGator
svgator
The easiest way to add SVG animations to your website right from your SVGator account.
OH MY Svg
oh-my-svg
Add any svg to your website with the superpowers of the block editor. Out-of-the-box security and speed optimization!
SVG Editor: Upload & Change Colors
svg-editor
SVG Editor lets you upload SVG files and change their colors directly within the WordPress Media Library.
SVG Support Developer Profile
2 plugins · 1.0M total installs
How We Detect SVG Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/svg-support/css/svgs-admin.css/wp-content/plugins/svg-support/css/svgs-admin-simple-mode.css/wp-content/plugins/svg-support/css/svgs-admin-edit-post.css/wp-content/plugins/svg-support/css/jquery.dropdown-min.css/wp-content/plugins/svg-support/js/min/jquery.dropdown-min.js/wp-content/plugins/svg-support/js/svgs-inline.js/wp-content/plugins/svg-support/js/svgs-admin.jssvg-support/css/svgs-admin.css?ver=svg-support/css/svgs-admin-simple-mode.css?ver=svg-support/css/svgs-admin-edit-post.css?ver=svg-support/css/jquery.dropdown-min.css?ver=svg-support/js/min/jquery.dropdown-min.js?ver=svg-support/js/svgs-inline.js?ver=svg-support/js/svgs-admin.js?ver=HTML / DOM Fingerprints
svg-support-frontend-settings<!-- SVG Support Settings -->bodhi_svgs_optionssvgs_plugin_version