WebP Image Converter & Replacer – Convert to WebP, No Duplicates Security & Risk Analysis

wordpress.org/plugins/webp-image-converter-replacer

Convert images to WebP and replace originals—no duplicates. Save storage and speed up your site. Auto-convert on upload & bulk tools (premium).

100 active installs v1.1.3 PHP 7.4+ WP 5.8+ Updated Oct 27, 2025
convert-to-webpimage-optimizationmedia-librarywebpwebp-converter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WebP Image Converter & Replacer – Convert to WebP, No Duplicates Safe to Use in 2026?

Generally Safe

Score 100/100

WebP Image Converter & Replacer – Convert to WebP, No Duplicates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The webp-image-converter-replacer plugin, version 1.1.3, demonstrates a generally good security posture, with no known CVEs or recent vulnerabilities reported, suggesting a proactive approach to security. The static analysis reveals strong adherence to best practices, particularly concerning output escaping, where 98% of outputs are properly escaped, and robust nonce and capability checks are implemented across its attack surface. The absence of critical or high severity taint analysis findings further reinforces this positive assessment, indicating that data flows within the plugin are likely well-sanitized.

However, a single unsanitized path identified in the taint analysis warrants attention, despite its current low severity rating. While the plugin has no directly exploitable vulnerabilities from this specific flow in its current state, it represents a potential future risk if not addressed. The presence of 24 SQL queries, with only 83% using prepared statements, also indicates a minor concern regarding potential SQL injection vulnerabilities. While not critical, diligent code review and updating the remaining SQL queries to use prepared statements would further strengthen the plugin's security.

Overall, the plugin is in a strong security position due to its lack of historical vulnerabilities and good implementation of security checks. The primary areas for improvement lie in addressing the identified unsanitized path and ensuring all SQL queries are parameterized. These are manageable risks that, when mitigated, will elevate the plugin's security to an excellent level.

Key Concerns

  • Flow with unsanitized path found
  • SQL queries not using prepared statements
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

WebP Image Converter & Replacer – Convert to WebP, No Duplicates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WebP Image Converter & Replacer – Convert to WebP, No Duplicates Release Timeline

v1.1.3Current
v1.1.2
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

WebP Image Converter & Replacer – Convert to WebP, No Duplicates Code Analysis

Dangerous Functions
0
Raw SQL Queries
20
4 prepared
Unescaped Output
1
55 escaped
Nonce Checks
12
Capability Checks
15
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

17% prepared24 total queries

Output Escaping

98% escaped56 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
webpicr_ajax_convert_image_to_webp (webp-image-converter-replacer.php:615)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WebP Image Converter & Replacer – Convert to WebP, No Duplicates Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 9

authwp_ajax_webpicr_convert_image_to_webpwebp-image-converter-replacer.php:1231
authwp_ajax_webpicr_check_conversion_statuswebp-image-converter-replacer.php:1275
authwp_ajax_webpicr_fix_mime_typeswebp-image-converter-replacer.php:1317
authwp_ajax_webpicr_recalculate_savingswebp-image-converter-replacer.php:1664
authwp_ajax_webpicr_install_phoenixwebp-image-converter-replacer.php:2358
authwp_ajax_webpicr_update_phoenixwebp-image-converter-replacer.php:2460
authwp_ajax_webpicr_activate_phoenixwebp-image-converter-replacer.php:2503
authwp_ajax_webpicr_get_bulk_all_idswebp-image-converter-replacer.php:3458
authwp_ajax_webpicr_refresh_statisticswebp-image-converter-replacer.php:3653
WordPress Hooks 14
filtermedia_row_actionswebp-image-converter-replacer.php:606
filterviews_uploadwebp-image-converter-replacer.php:1419
actionadmin_enqueue_scriptswebp-image-converter-replacer.php:1458
actiondelete_postwebp-image-converter-replacer.php:1533
filterbulk_actions-uploadwebp-image-converter-replacer.php:1685
filterhandle_bulk_actions-uploadwebp-image-converter-replacer.php:1687
actionadmin_noticeswebp-image-converter-replacer.php:1839
filterwp_generate_attachment_metadatawebp-image-converter-replacer.php:2564
filterwp_generate_attachment_metadatawebp-image-converter-replacer.php:2581
actionafter_uninstallwebp-image-converter-replacer.php:3473
actionadmin_initwebp-image-converter-replacer.php:3606
actionadmin_headwebp-image-converter-replacer.php:3666
actionadmin_initwebp-image-converter-replacer.php:3668
actiondelete_attachmentwebp-image-converter-replacer.php:3670

Scheduled Events 1

webpicr_cleanup_old_backups
Maintenance & Trust

WebP Image Converter & Replacer – Convert to WebP, No Duplicates Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 27, 2025
PHP min version7.4
Downloads66K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

WebP Image Converter & Replacer – Convert to WebP, No Duplicates Developer Profile

Core Essentials

4 plugins · 170 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WebP Image Converter & Replacer – Convert to WebP, No Duplicates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webp-image-converter-replacer/assets/css/webp-image-converter-replacer.css/wp-content/plugins/webp-image-converter-replacer/assets/js/webp-image-converter-replacer.js
Script Paths
/wp-content/plugins/webp-image-converter-replacer/assets/js/webp-image-converter-replacer.js
Version Parameters
webp-image-converter-replacer/assets/css/webp-image-converter-replacer.css?ver=webp-image-converter-replacer/assets/js/webp-image-converter-replacer.js?ver=

HTML / DOM Fingerprints

JS Globals
webpicr_settings
FAQ

Frequently Asked Questions about WebP Image Converter & Replacer – Convert to WebP, No Duplicates