
Converter for Media – Optimize images | Convert WebP & AVIF Security & Risk Analysis
wordpress.org/plugins/webp-converter-for-mediaSpeed up your website by using our WebP & AVIF Converter. Optimize images and serve WebP and AVIF images instead of standard formats!
Is Converter for Media – Optimize images | Convert WebP & AVIF Safe to Use in 2026?
Generally Safe
Score 93/100Converter for Media – Optimize images | Convert WebP & AVIF has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the 'webp-converter-for-media' plugin v6.5.4 reveals a generally strong security posture. The plugin exhibits a low attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication checks. Furthermore, it demonstrates good coding practices with 100% of SQL queries using prepared statements and a high percentage (95%) of output properly escaped. The absence of dangerous functions and critical or high-severity taint flows is also a positive indicator.
Key Concerns
- Known High Severity Vulnerability
- Medium Severity Vulnerabilities
- Potential for URL Redirection
- Potential for Cross-Site Request Forgery
- Potential for SSRF
- Missing Authorization vulnerabilities
- Nonce checks present but limited
- Capability checks present but limited
- 32 File operations
- 7 External HTTP requests
Converter for Media – Optimize images | Convert WebP & AVIF Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Converter for Media – Optimize images | Convert WebP & AVIF <= 6.5.1 - Unauthenticated Server-Side Request Forgery via src
Converter for Media <= 6.3.2 - Missing Authorization to Authenticated (Subscriber+) Optimized Image Deletion via regenerate-attachment REST Endpoint
WebP Converter for Media <= 4.0.2 - Unauthenticated Open Redirect
WebP Converter for Media – Convert WebP and AVIF & Optimize Images <= 1.0.2 - Cross-Site Request Forgery
Converter for Media – Optimize images | Convert WebP & AVIF Code Analysis
Output Escaping
Data Flow Analysis
Converter for Media – Optimize images | Convert WebP & AVIF Attack Surface
WordPress Hooks 64
Maintenance & Trust
Converter for Media – Optimize images | Convert WebP & AVIF Maintenance & Trust
Maintenance Signals
Community Trust
Converter for Media – Optimize images | Convert WebP & AVIF Alternatives
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1-click: compress images, convert to WebP & AVIF, resize, and boost your site with the easiest WordPress image optimization plugin!
Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN
wp-smushit
Optimize and compress images with lossless and lossy compression, lazy load, WebP & AVIF conversion, and global image CDN.
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
shortpixel-image-optimiser
Optimize images & PDFs smartly. Create and compress next-gen WebP and AVIF formats. Smart crop and resize.
Squeeze – Image Optimization & Compression, WEBP Conversion
squeeze
Unlimited. Private. Instant. Squeeze compresses and converts your images directly in your browser — no external servers and no upload limits.
DropAvif Image Optimizer – Convert WebP & AVIF | Compress Images
dropavif-media-optimizer
The Ultimate Image Optimization Suite for WordPress. WebP & AVIF conversion, Smart Format Selection, Watermarking, and Lazy Load. Zero server load.
Converter for Media – Optimize images | Convert WebP & AVIF Developer Profile
3 plugins · 541K total installs
How We Detect Converter for Media – Optimize images | Convert WebP & AVIF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webp-converter-for-media/assets/build/css/styles.css/wp-content/plugins/webp-converter-for-media/assets/build/js/scripts.jsassets/build/js/scripts.jswebp-converter-for-media/assets/build/css/styles.css?ver=webp-converter-for-media/assets/build/js/scripts.js?ver=HTML / DOM Fingerprints
/wp-json/webp-converter/v1