Webp Transformer Security & Risk Analysis

wordpress.org/plugins/webp-transformer

Convert images from library to webp and resize them during upload

200 active installs v1.0.2 PHP 7.4+ WP 6.0+ Updated Nov 11, 2024
converterimageslibraryresizewebp
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Webp Transformer Safe to Use in 2026?

Generally Safe

Score 92/100

Webp Transformer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "webp-transformer" v1.0.2 plugin exhibits a strong security posture based on the provided static analysis results. The absence of any identifiable attack surface points, such as AJAX handlers, REST API routes, or shortcodes, is a significant strength. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. There are no flagged dangerous functions, file operations, or external HTTP requests, which further contributes to its secure design. The zero known CVEs and no recorded vulnerability history indicate a history of security diligence from the developers or a lack of exploitation attempts, which is positive. However, a complete lack of nonce and capability checks across all entry points (which are zero in this case) is a potential concern. While there are no active entry points to exploit, if future versions introduce any, the absence of these fundamental security checks could create vulnerabilities. The zero taint flows analyzed also suggest a very limited scope for complex vulnerabilities, but it's worth noting that this might also be due to the limited functionality or entry points of the plugin.

Key Concerns

  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Webp Transformer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Webp Transformer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

Webp Transformer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menupages\settings.php:25
actionadmin_initpages\settings.php:26
actioninitwebp-transformer.php:38
actionadmin_noticeswebp-transformer.php:42
filterwp_handle_uploadwebp-transformer.php:46
Maintenance & Trust

Webp Transformer Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 11, 2024
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Webp Transformer Developer Profile

Informatiza

1 plugin · 200 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webp Transformer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Webp Transformer