TR Pixel Engine – Image Optimization | WebP Conversion Security & Risk Analysis

wordpress.org/plugins/tr-pixel-engine

Boost site speed by automatically converting images to WebP. Features a unique visual comparison dashboard and bulk optimizer.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Feb 18, 2026
image-compressionoptimizationperformancespeedwebp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TR Pixel Engine – Image Optimization | WebP Conversion Safe to Use in 2026?

Generally Safe

Score 100/100

TR Pixel Engine – Image Optimization | WebP Conversion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "tr-pixel-engine" v1.0.0 plugin presents a mixed security posture. While it shows strengths in the absence of known CVEs, dangerous functions, file operations, and external HTTP requests, significant concerns arise from its static analysis. The plugin exposes a total of 5 AJAX handlers, with a concerning 2 of these lacking authentication checks, creating a direct attack vector for potential unauthorized actions.

Further analysis reveals that the plugin performs SQL queries without utilizing prepared statements, indicating a risk of SQL injection vulnerabilities. While taint analysis shows no critical or high-severity flows, this is likely due to the limited scope of analysis or the specific nature of the plugin's code. The moderate rate of proper output escaping (49%) also suggests a potential for cross-site scripting (XSS) vulnerabilities if untrusted data is ever processed and displayed without adequate sanitization.

The complete lack of recorded vulnerabilities in its history is a positive sign, suggesting a developer who may be security-conscious or has not yet encountered exploitable flaws. However, the presence of unprotected AJAX endpoints and raw SQL queries are immediate red flags that require attention. In conclusion, the plugin has some good security practices but exhibits critical weaknesses in its handling of AJAX endpoints and SQL queries that significantly elevate its risk profile.

Key Concerns

  • AJAX handlers without authentication
  • SQL queries without prepared statements
  • Low percentage of properly escaped output
Vulnerabilities
None known

TR Pixel Engine – Image Optimization | WebP Conversion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TR Pixel Engine – Image Optimization | WebP Conversion Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
29
28 escaped
Nonce Checks
5
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

49% escaped57 total outputs
Attack Surface
2 unprotected

TR Pixel Engine – Image Optimization | WebP Conversion Attack Surface

Entry Points5
Unprotected2

AJAX Handlers 5

authwp_ajax_awou_statsincludes\class-awou-admin.php:12
authwp_ajax_awou_toggleincludes\class-awou-admin.php:13
authwp_ajax_awou_mime_panelincludes\class-awou-admin.php:14
authwp_ajax_awou_manual_startincludes\class-awou-converter.php:13
authwp_ajax_awou_manual_stepincludes\class-awou-converter.php:14
WordPress Hooks 3
actionadmin_menuincludes\class-awou-admin.php:9
actionadmin_enqueue_scriptsincludes\class-awou-admin.php:10
filterwp_handle_uploadincludes\class-awou-converter.php:11
Maintenance & Trust

TR Pixel Engine – Image Optimization | WebP Conversion Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version7.4
Downloads136

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TR Pixel Engine – Image Optimization | WebP Conversion Developer Profile

Taqadas Ur Rehman

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TR Pixel Engine – Image Optimization | WebP Conversion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tr-pixel-engine/assets/awou-fonts.css
Version Parameters
tr-pixel-engine/assets/awou-fonts.css?ver=tr-pixel-engine/assets/awou-ui.css?ver=

HTML / DOM Fingerprints

CSS Classes
awou-toastis-awou-progress-barawou-progress-textawou-progress-pctawou-skeletonawou-tabis-active+8 more
HTML Comments
Toast Notification SystemWe use this instead of ugly browser alerts to show success/error messages.Progress Bar UpdaterUpdates the width and text labels of the progress bar during bulk conversion.+23 more
Data Attributes
data-tabdata-panel--pos
JS Globals
awou
REST Endpoints
/wp-json/awou/v1/stats/wp-json/awou/v1/toggle/wp-json/awou/v1/mime-panel
FAQ

Frequently Asked Questions about TR Pixel Engine – Image Optimization | WebP Conversion