Your Simple SVG Support Security & Risk Analysis

wordpress.org/plugins/your-simple-svg-support

Your Simple SVG Support plugin for Enabling SVG Uploads in WordPress.

20 active installs v1.0.3 PHP + WP 5.5+ Updated Dec 7, 2025
supportsvg
99
A · Safe
CVEs total1
Unpatched0
Last CVEMar 24, 2025
Download
Safety Verdict

Is Your Simple SVG Support Safe to Use in 2026?

Generally Safe

Score 99/100

Your Simple SVG Support has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Mar 24, 2025Updated 5mo ago
Risk Assessment

The 'your-simple-svg-support' plugin v1.0.3 exhibits a strong security posture based on the static analysis, with no identified dangerous functions, fully prepared SQL statements, and properly escaped output. The complete absence of AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly reduces the attack surface. Furthermore, the taint analysis indicates no flows with unsanitized paths, suggesting robust input handling within the analyzed code segments. The plugin also shows no bundled libraries, negating risks associated with outdated third-party components.

Despite the promising static analysis, a critical concern arises from the vulnerability history. The plugin has one known CVE, although it is currently unpatched and was reported as a medium severity Cross-site Scripting (XSS) vulnerability. While the static analysis for this version shows no XSS vulnerabilities, the historical presence of such issues, even if patched in later versions, warrants careful consideration. This suggests that while the current version appears clean, past vulnerabilities may indicate a recurring pattern or a need for continuous security scrutiny for this plugin.

In conclusion, the current version of 'your-simple-svg-support' demonstrates good security practices in its code, particularly regarding SQL and output sanitization, and a minimal attack surface. However, the past XSS vulnerability, even if resolved in subsequent versions, is a significant drawback that necessitates vigilance. The strength lies in its clean code, while the weakness lies in its historical security track record, indicating a need for ongoing monitoring.

Key Concerns

  • Medium severity XSS vulnerability in history
  • No Nonce checks found
  • No Capability checks found
Vulnerabilities
1 published

Your Simple SVG Support Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-2542medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Your Simple SVG Support <= 1.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

Mar 24, 2025 Patched in 1.0.2 (1d)
Version History

Your Simple SVG Support Release Timeline

v1.0.3Current
v1.0.2
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Your Simple SVG Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0
Attack Surface

Your Simple SVG Support Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwp_check_filetype_and_extyour-simple-svg-support.php:50
filterwp_handle_upload_prefilteryour-simple-svg-support.php:66
filterupload_mimesyour-simple-svg-support.php:74
actionadmin_enqueue_scriptsyour-simple-svg-support.php:79
Maintenance & Trust

Your Simple SVG Support Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version
Downloads717

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Your Simple SVG Support Developer Profile

Vladyslav Lykhenko

3 plugins · 90 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Your Simple SVG Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/your-simple-svg-support/css/your_simple_svg_support_style.css
Version Parameters
your-simple-svg-support/css/your_simple_svg_support_style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Your Simple SVG Support