
WebP Conversion Security & Risk Analysis
wordpress.org/plugins/webp-conversionConvert your .png and .jpeg images to WebP format for FREE – with absolutely NO limits or hidden restrictions.
Is WebP Conversion Safe to Use in 2026?
Mostly Safe
Score 78/100WebP Conversion is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'webp-conversion' v2.2 plugin exhibits a mixed security posture. While it demonstrates good practices in database interaction, using prepared statements for all SQL queries and performing a significant amount of output escaping, several critical areas raise concern. The presence of 16 AJAX handlers, with two lacking proper authorization checks, represents a notable attack surface that could be exploited by unauthenticated users. Additionally, the plugin's vulnerability history, including one unpatched medium severity CVE, indicates a recurring issue with authorization, specifically missing authorization checks, which is a significant security flaw. This pattern suggests a need for more robust access control mechanisms. The plugin's overall security is weakened by these unaddressed authorization vulnerabilities and the potential for exploitation of unprotected AJAX endpoints, despite its strengths in other areas.
Key Concerns
- Unprotected AJAX handlers
- Unpatched medium severity CVE
- Vulnerability history: Missing Authorization
- Lack of capability checks
WebP Conversion Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WebP Conversion <= 2.1 - Missing Authorization
WebP Conversion Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WebP Conversion Attack Surface
AJAX Handlers 16
WordPress Hooks 13
Maintenance & Trust
WebP Conversion Maintenance & Trust
Maintenance Signals
Community Trust
WebP Conversion Alternatives
Enable SVG, WebP, and ICO Upload
enable-svg-webp-ico-upload
This plugin will enable uploading SVG, WebP & ICO image files to WordPress sites.
SVG Block
svg-block
Display an SVG image as a block, which can be used for displaying images, icons, dividers, buttons
Simple WebP Converter
simple-webp-converter
Automatically converts uploaded images to WebP format for better performance and smaller file sizes.
WebP Image Optimization
webp-image-optimization
Automatically converts uploaded JPEG and PNG images to WebP (or AVIF) format, resizes them, and allows conversion of existing images directly from the …
Image Ninja – Convert Images to WebP & AVIF on Upload
image-ninja
Automatically convert JPEG and PNG images to WebP and AVIF formats during upload to optimize your WordPress site’s performance.
WebP Conversion Developer Profile
1 plugin · 1K total installs
How We Detect WebP Conversion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webp-conversion/css/webp-conversion-admin.css/wp-content/plugins/webp-conversion/js/webp-conversion-admin.jswebp-conversion/css/webp-conversion-admin.css?ver=webp-conversion/js/webp-conversion-admin.js?ver=HTML / DOM Fingerprints
webp-conversion-formwebpc-bulk-actionswebpc-section-title<!-- WebpC_DB_Replacer::replace_webp_links --><!-- ADD YOUR CUSTOM JS CODE HERE -->data-webpc-convert-buttondata-webpc-restore-buttondata-webpc-remove-original-buttonvar webpc_ajax_objectvar webpc_bulk_objectvar webpc_globals/wp-json/webpc/v1/convert_single/wp-json/webpc/v1/restore_single/wp-json/webpc/v1/remove_single