TR Pixel Engine – Image Optimization | WebP Conversion Security & Risk Analysis
wordpress.org/plugins/tr-pixel-engineBoost site speed by automatically converting images to WebP. Features a unique visual comparison dashboard and bulk optimizer.
Is TR Pixel Engine – Image Optimization | WebP Conversion Safe to Use in 2026?
Generally Safe
Score 100/100TR Pixel Engine – Image Optimization | WebP Conversion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tr-pixel-engine" v1.0.0 plugin presents a mixed security posture. While it shows strengths in the absence of known CVEs, dangerous functions, file operations, and external HTTP requests, significant concerns arise from its static analysis. The plugin exposes a total of 5 AJAX handlers, with a concerning 2 of these lacking authentication checks, creating a direct attack vector for potential unauthorized actions.
Further analysis reveals that the plugin performs SQL queries without utilizing prepared statements, indicating a risk of SQL injection vulnerabilities. While taint analysis shows no critical or high-severity flows, this is likely due to the limited scope of analysis or the specific nature of the plugin's code. The moderate rate of proper output escaping (49%) also suggests a potential for cross-site scripting (XSS) vulnerabilities if untrusted data is ever processed and displayed without adequate sanitization.
The complete lack of recorded vulnerabilities in its history is a positive sign, suggesting a developer who may be security-conscious or has not yet encountered exploitable flaws. However, the presence of unprotected AJAX endpoints and raw SQL queries are immediate red flags that require attention. In conclusion, the plugin has some good security practices but exhibits critical weaknesses in its handling of AJAX endpoints and SQL queries that significantly elevate its risk profile.
Key Concerns
- AJAX handlers without authentication
- SQL queries without prepared statements
- Low percentage of properly escaped output
TR Pixel Engine – Image Optimization | WebP Conversion Security Vulnerabilities
TR Pixel Engine – Image Optimization | WebP Conversion Code Analysis
SQL Query Safety
Output Escaping
TR Pixel Engine – Image Optimization | WebP Conversion Attack Surface
AJAX Handlers 5
WordPress Hooks 3
Maintenance & Trust
TR Pixel Engine – Image Optimization | WebP Conversion Maintenance & Trust
Maintenance Signals
Community Trust
TR Pixel Engine – Image Optimization | WebP Conversion Alternatives
AHS – Image to WebP Converter
ahs-image-to-webp-converter
Automatically convert uploaded images to modern WebP format to reduce file size and improve website performance.
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
LWS Optimize – All-in-One Speed Booster & Cache Tools
lws-optimize
All-in-one speed optimization: caching, WebP/AVIF, Critical CSS, lazy loading, CDN, and more. Instantly boost Core Web Vitals and site speed!
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
quickwebp
QuickWebP is a free WordPress plugin that converts images to WebP, optimizes performance, improves SEO, auto-fills metadata, and resizes images—no API …
Image to WebP Converter
image-to-webp-converter
Automatically convert uploaded images (PNG, JPG, JPEG) to WebP format to enhance website performance and reduce load times.
TR Pixel Engine – Image Optimization | WebP Conversion Developer Profile
1 plugin · 0 total installs
How We Detect TR Pixel Engine – Image Optimization | WebP Conversion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tr-pixel-engine/assets/awou-fonts.csstr-pixel-engine/assets/awou-fonts.css?ver=tr-pixel-engine/assets/awou-ui.css?ver=HTML / DOM Fingerprints
awou-toastis-awou-progress-barawou-progress-textawou-progress-pctawou-skeletonawou-tabis-active+8 moreToast Notification SystemWe use this instead of ugly browser alerts to show success/error messages.Progress Bar UpdaterUpdates the width and text labels of the progress bar during bulk conversion.+23 moredata-tabdata-panel--posawou/wp-json/awou/v1/stats/wp-json/awou/v1/toggle/wp-json/awou/v1/mime-panel