
WebP Express Plus Security & Risk Analysis
wordpress.org/plugins/webp-express-plusExclusion of necessary images from processing by the "WebP Express" plugin
Is WebP Express Plus Safe to Use in 2026?
Generally Safe
Score 85/100WebP Express Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "webp-express-plus" v0.2.1 plugin presents a mixed security profile. From a static analysis perspective, the plugin exhibits a commendable lack of readily identifiable attack surface points such as unprotected AJAX handlers, REST API routes, or shortcodes. Furthermore, all observed SQL queries utilize prepared statements, which is a strong indicator of secure database interaction. However, a significant concern lies in the low percentage (17%) of properly escaped output, suggesting a high potential for cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on any identified entry points, while seemingly limited by the zero entry points, means that if any entry points are later introduced or discovered, they will lack fundamental security protections.
The vulnerability history for this plugin is clean, with no recorded CVEs. This is a positive indicator and suggests a good track record regarding security vulnerabilities. However, it is important to note that a clean history does not guarantee future security, especially in light of the identified output escaping issues. The lack of taint analysis results is likely due to the limited or non-existent attack surface exposed, making it difficult to trace data flow in this assessment. In conclusion, while the plugin has a good foundation with secure SQL handling and no known vulnerabilities, the prevalent issue of unescaped output represents a substantial risk that needs immediate attention.
Key Concerns
- Low output escaping percentage
- Missing capability checks
- Missing nonce checks
WebP Express Plus Security Vulnerabilities
WebP Express Plus Code Analysis
SQL Query Safety
Output Escaping
WebP Express Plus Attack Surface
WordPress Hooks 5
Maintenance & Trust
WebP Express Plus Maintenance & Trust
Maintenance Signals
Community Trust
WebP Express Plus Alternatives
Simple WebP Optimizer
simple-webp-optimizer
Auto-convert JPG/PNG to WebP. Save up to 80% server space and boost site speed with built-in bulk optimization and real-time savings reports.
Autoptimize
autoptimize
Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.
WebP Express
webp-express
Serve autogenerated WebP images instead of jpeg/png to browsers that supports WebP.
TinyPNG – JPEG, PNG & WebP image compression
tiny-compress-images
Speed up your website. Optimize your JPEG, PNG, and WebP images automatically with TinyPNG.
Modern Image Formats
webp-uploads
Converts images to more modern formats such as WebP or AVIF during upload.
WebP Express Plus Developer Profile
1 plugin · 800 total installs
How We Detect WebP Express Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webp-express-plus/simple_html_dom/simple_html_dom.phpHTML / DOM Fingerprints
webpexpress-processed