
WebP Image Converter & Replacer – Convert to WebP, No Duplicates Security & Risk Analysis
wordpress.org/plugins/webp-image-converter-replacerConvert images to WebP and replace originals—no duplicates. Save storage and speed up your site. Auto-convert on upload & bulk tools (premium).
Is WebP Image Converter & Replacer – Convert to WebP, No Duplicates Safe to Use in 2026?
Generally Safe
Score 100/100WebP Image Converter & Replacer – Convert to WebP, No Duplicates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The webp-image-converter-replacer plugin, version 1.1.3, demonstrates a generally good security posture, with no known CVEs or recent vulnerabilities reported, suggesting a proactive approach to security. The static analysis reveals strong adherence to best practices, particularly concerning output escaping, where 98% of outputs are properly escaped, and robust nonce and capability checks are implemented across its attack surface. The absence of critical or high severity taint analysis findings further reinforces this positive assessment, indicating that data flows within the plugin are likely well-sanitized.
However, a single unsanitized path identified in the taint analysis warrants attention, despite its current low severity rating. While the plugin has no directly exploitable vulnerabilities from this specific flow in its current state, it represents a potential future risk if not addressed. The presence of 24 SQL queries, with only 83% using prepared statements, also indicates a minor concern regarding potential SQL injection vulnerabilities. While not critical, diligent code review and updating the remaining SQL queries to use prepared statements would further strengthen the plugin's security.
Overall, the plugin is in a strong security position due to its lack of historical vulnerabilities and good implementation of security checks. The primary areas for improvement lie in addressing the identified unsanitized path and ensuring all SQL queries are parameterized. These are manageable risks that, when mitigated, will elevate the plugin's security to an excellent level.
Key Concerns
- Flow with unsanitized path found
- SQL queries not using prepared statements
- Bundled Freemius v1.0 library
WebP Image Converter & Replacer – Convert to WebP, No Duplicates Security Vulnerabilities
WebP Image Converter & Replacer – Convert to WebP, No Duplicates Release Timeline
WebP Image Converter & Replacer – Convert to WebP, No Duplicates Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WebP Image Converter & Replacer – Convert to WebP, No Duplicates Attack Surface
AJAX Handlers 9
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
WebP Image Converter & Replacer – Convert to WebP, No Duplicates Maintenance & Trust
Maintenance Signals
Community Trust
WebP Image Converter & Replacer – Convert to WebP, No Duplicates Alternatives
Robin Image Optimizer – Unlimited Image Optimization & WebP Converter
robin-image-optimizer
Unlimited automatic image optimization for WordPress. Compress images, convert to WebP, and improve site speed without losing image quality.
Magnet Media Optimizer – AI powered image enhancement, Missing Alt Text & Convert to WebP
magnet-media-optimizer
AI-powered image enhancement: automatic ALT text, captions, and descriptions for images, plus WebP conversion for faster performance and improved SEO.
RW WebP Converter Lite
rw-webp-converter-lite
A lightweight WordPress plugin that converts JPG and PNG images to WebP format in bulk and automatically converts newly uploaded images.
WebPioneer
webpioneer
Compatibility-first WebP conversion for WordPress with upload-time conversion, bulk tools, delivery safety, and local processing.
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
WebP Image Converter & Replacer – Convert to WebP, No Duplicates Developer Profile
4 plugins · 170 total installs
How We Detect WebP Image Converter & Replacer – Convert to WebP, No Duplicates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webp-image-converter-replacer/assets/css/webp-image-converter-replacer.css/wp-content/plugins/webp-image-converter-replacer/assets/js/webp-image-converter-replacer.js/wp-content/plugins/webp-image-converter-replacer/assets/js/webp-image-converter-replacer.jswebp-image-converter-replacer/assets/css/webp-image-converter-replacer.css?ver=webp-image-converter-replacer/assets/js/webp-image-converter-replacer.js?ver=HTML / DOM Fingerprints
webpicr_settings