
Your Simple SVG Support Security & Risk Analysis
wordpress.org/plugins/your-simple-svg-supportYour Simple SVG Support plugin for Enabling SVG Uploads in WordPress.
Is Your Simple SVG Support Safe to Use in 2026?
Generally Safe
Score 99/100Your Simple SVG Support has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'your-simple-svg-support' plugin v1.0.3 exhibits a strong security posture based on the static analysis, with no identified dangerous functions, fully prepared SQL statements, and properly escaped output. The complete absence of AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly reduces the attack surface. Furthermore, the taint analysis indicates no flows with unsanitized paths, suggesting robust input handling within the analyzed code segments. The plugin also shows no bundled libraries, negating risks associated with outdated third-party components.
Despite the promising static analysis, a critical concern arises from the vulnerability history. The plugin has one known CVE, although it is currently unpatched and was reported as a medium severity Cross-site Scripting (XSS) vulnerability. While the static analysis for this version shows no XSS vulnerabilities, the historical presence of such issues, even if patched in later versions, warrants careful consideration. This suggests that while the current version appears clean, past vulnerabilities may indicate a recurring pattern or a need for continuous security scrutiny for this plugin.
In conclusion, the current version of 'your-simple-svg-support' demonstrates good security practices in its code, particularly regarding SQL and output sanitization, and a minimal attack surface. However, the past XSS vulnerability, even if resolved in subsequent versions, is a significant drawback that necessitates vigilance. The strength lies in its clean code, while the weakness lies in its historical security track record, indicating a need for ongoing monitoring.
Key Concerns
- Medium severity XSS vulnerability in history
- No Nonce checks found
- No Capability checks found
Your Simple SVG Support Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Your Simple SVG Support <= 1.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Your Simple SVG Support Release Timeline
Your Simple SVG Support Code Analysis
Your Simple SVG Support Attack Surface
WordPress Hooks 4
Maintenance & Trust
Your Simple SVG Support Maintenance & Trust
Maintenance Signals
Community Trust
Your Simple SVG Support Alternatives
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
themeisle-companion
Add modules like share buttons, header & footer scripts, disable comments, reading progress bar, custom fonts, custom login page & more in one plugin.
Easy SVG Support
easy-svg
This Plugin allows you to upload SVG Files into your Media library.
WP SVG Images
wp-svg-images
Add SVG support to your WP website. Securely upload SVG files, automatic sanitization, Media Library preview.
Upload SVG
upload-svg
Safely enable SVG uploads with sanitization and prevent XML/SVG vulnerabilities on your WordPress website. Preview SVG files in your Media Library.
SVG Enabler
svg-enabler
This plugin gives you the ability to allow SVG uploads whilst making sure that they’re sanitized to stop SVG/XML vulnerabilities affecting your site.
Your Simple SVG Support Developer Profile
3 plugins · 90 total installs
How We Detect Your Simple SVG Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/your-simple-svg-support/css/your_simple_svg_support_style.cssyour-simple-svg-support/css/your_simple_svg_support_style.css?ver=