BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
CodePros SVG Secure Support icon
Maintained Tested up to 7.0.6 #18 in sanitize

CodePros SVG Secure Support

Highly secure SVG upload support for WordPress. Validates, sanitizes, and protects SVG files through a multi-layer security pipeline.

Active installs<10New
Downloads · 30d51▲ +15.9% vs prev. 30d
Rating—0 reviews
Health score49/100Fair
All-time downloads196Since Jun 2026
Support resolved—No recent threads
RequiresWP 6.0PHP 7.4+
Downloads · 7d11▼ -26.7% week over week
Our verdict

Use with caution

CodePros SVG Secure Support works, but test it on a staging site before relying on it in 2026. Was last updated 4 months ago, and scores 49/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

123Jun 30Aug 13Sep 27
Yesterday1
Daily average (1y)2
Peak day41Jun 15, 2026
Last 12 months200

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where CodePros SVG Secure Support stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
sanitize #59 1,431 Best sanitize plugins →
security >100 10,000 Best security plugins →
SVG >100 2,538 Best SVG plugins →
upload >100 10,000 Best upload plugins →
xss protection >100 595 Best xss protection plugins →

About CodePros SVG Secure Support

From the official readme · v1.0.0

Description

WordPress does not support SVG uploads natively — and naive SVG plugins are a well-known attack surface. SVG files are XML documents that can carry XSS payloads, XXE attacks, external resource injection, and embedded HTML. CodePros SVG Secure Support adds safe, production-ready SVG uploads through a layered defense pipeline.

Security Pipeline

Every uploaded SVG passes through five sequential checks before it is accepted:

  1. Extension check — Blocks double-extension filenames (e.g. payload.php.svg) and enforces .svg only.
  2. MIME check — Verifies actual file bytes return image/svg+xml via finfo; confirms <svg or <?xml is present in the header bytes.
  3. Size check — Rejects files exceeding the configured maximum (default 1 MB).
  4. Node-count check — Parses the XML and counts DOM nodes; rejects files above the threshold (default 5,000 nodes) to prevent node-flood DoS attacks.
  5. Dimension check — Reads the root <svg> width/height/viewBox; rejects unreasonably large declared dimensions (default 10,000 px).

After validation, the file is sanitized:

  • DOM sanitization via the battle-tested enshrined/svg-sanitize library with custom tag and attribute whitelists.
  • Remote reference stripping — all external URLs are removed.
  • Final string-level regex scan for javascript:, <script, inline event handlers (on*=), and CSS expression() — any match causes the upload to be rejected entirely.

Security Headers

When SVG attachment pages are served, the plugin adds:

  • Content-Security-Policy (configurable, secure default provided)
  • X-Content-Type-Options: nosniff
  • X-Frame-Options: SAMEORIGIN

Server-Level Hardening (Optional but Recommended)

The plugin’s PHP layer covers every SVG upload that passes through WordPress. But if someone accesses an uploaded file directly — e.g. by visiting https://example.com/wp-content/uploads/2024/01/logo.svg — WordPress is bypassed entirely, so the PHP security headers are never sent.

The plugin ships two ready-to-use server configuration snippets to close that gap:

  • uploads-htaccess.txt — for Apache / LiteSpeed servers
  • uploads-nginx.conf — for Nginx servers

Each snippet does three things:

  1. Blocks server-side script execution in wp-content/uploads/ — if an attacker somehow uploads a .php file and tries to access it directly, the server returns 403 instead of executing it.
  2. Enforces the correct SVG MIME type (image/svg+xml) — some server setups serve SVGs as text/plain, which prevents browsers from honouring Content Security Policy rules scoped to that MIME type.
  3. Adds security headers on direct SVG requests — the same X-Content-Type-Options, X-Frame-Options, and Content-Security-Policy headers that the PHP layer adds on WordPress attachment pages, so direct file links are equally protected.

Applying these snippets is the difference between WordPress-mediated access being protected and all access (direct URL, CDN pull, hotlink) being protected.

Admin UI

A tabbed settings page under Settings → SVG Secure Support provides:

  • Settings tab — Configure allowed upload roles, file size/node/dimension limits, sanitization options, CSP header value, and logging preferences.
  • Security Logs tab — Paginated, filterable log viewer showing every security event (blocked upload, removed tag/attribute, suspicious payload). Includes a log purge action.

Key Features

  • Role-based upload access — select one or more WordPress roles (default: Administrator) whose members may upload SVG files
  • Automatic upload-time sanitization — clean SVG replaces the original tmp file before WordPress moves it
  • Security event logging to the WordPress debug log and a dedicated database table
  • Configurable log retention with one-click purge
  • Bundled .htaccess and Nginx config snippets for the uploads directory

Installation

Minimum Requirements

  • WordPress 6.0 or higher
  • PHP 7.4 or higher
  • Composer (to install dependencies before activation)

Installation Steps

  1. Upload the svg-secure-support folder to /wp-content/plugins/.
  2. In the plugin directory, run:
    composer install
  3. Activate the plugin through the Plugins screen in WordPress.
  4. Go to Settings → SVG Secure Support to configure upload capability, limits, and logging.

Important: The plugin will not activate correctly without the Composer dependencies. An admin notice will be displayed if vendor/autoload.php is missing.

Uploading via the WordPress Admin

After activation, simply upload .svg files through the standard WordPress Media Library. Users without the required capability will receive a clear error message.

Frequently asked questions

Who can upload SVG files after activation?

By default, only Administrators. You can grant access to one or more additional roles (Editor, Author, Contributor, Subscriber, or any custom role) under Settings → SVG Secure Support → Roles Allowed to Upload SVGs. If no roles are selected, only Administrators can upload. All role checks are performed at upload time.

Does this plugin make SVG uploads completely safe?

The plugin implements every layer recommended by security researchers: validation → DOM sanitization with a strict tag/attribute whitelist → string-level payload scan → Content Security Policy headers. No sanitization approach can offer an absolute guarantee, but this multi-layer pipeline eliminates all known SVG attack vectors.

What happens to a malicious SVG?

It depends on where the threat is detected: Validation failures (wrong extension, wrong MIME, too large, too many nodes) — upload is blocked entirely with an error message shown to the user. Sanitizable content (disallowed tags or attributes) — the content is stripped and the cleaned SVG is accepted. Unsanitizable payloads (e.g. javascript: survives DOM traversal) — upload is blocked entirely. All outcomes are recorded in the security log.

Will this slow down my site?

The validation and sanitization pipeline runs only during file uploads, not on page loads. There is no frontend performance impact. The security headers are lightweight HTTP headers added on SVG attachment pages only (except X-Content-Type-Options: nosniff, which is sent on all pages).

Do I need to configure Apache or Nginx separately?

It is strongly recommended. Without the server-level snippets, only requests routed through WordPress are protected. A direct URL to an uploaded SVG bypasses all PHP-layer security headers. Apache — applying uploads-htaccess.txt Open (or create) wp-content/uploads/.htaccess on your server. Copy the entire contents of uploads-htaccess.txt (found in the plugin directory) and append them to that file. Save. Apache picks up .htaccess changes immediately — no restart needed. Note: WordPress may overwrite uploads/.htaccess when you save Permalink settings. Re-apply the snippet after that happens…

What is logged?

The following event types are recorded: upload_allowed — SVG passed all checks upload_sanitized — SVG was cleaned before being saved upload_blocked — SVG was rejected tag_removed — A disallowed tag was stripped attribute_removed — A disallowed attribute was stripped suspicious_payload — A javascript: or similar payload was detected

How do I view and manage logs?

Go to Settings → SVG Secure Support and click the Security Logs tab. You can filter by severity (Info / Warning / Critical) and event type, and purge entries older than the configured retention period.

Does the plugin work with Multisite?

The plugin has not been tested on WordPress Multisite. Network-wide activation is not currently supported.

Changelog

Initial release. No upgrade steps required.

1.0.0

  • Initial release.
  • Role-based upload access with multi-role selection; Administrators allowed by default.
  • Five-check SVG validation pipeline (extension, MIME, size, node count, dimensions).
  • DOM sanitization via enshrined/svg-sanitize with custom tag/attribute whitelists.
  • XML comment stripping and enhanced string-level XSS payload scan as a final defense layer.
  • Security event logging to WP debug log and database table.
  • CSP, X-Content-Type-Options, and X-Frame-Options headers on SVG attachment pages.
  • Tabbed admin UI with settings and security log viewer.
  • Bundled Apache and Nginx upload-directory hardening snippets.

Full changelog on WordPress.org →

Screenshots

Settings tab — Upload restrictions, sanitization options, CSP header, and logging configuration.
Settings tab — Upload restrictions, sanitization options, CSP header, and logging…
Security Logs tab — Paginated log viewer with severity and event-type filters.
Security Logs tab — Paginated log viewer with severity and event-type filters.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best CodePros SVG Secure Support alternatives

All sanitize plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Clean Image Filenames Clean Image Filenames This plugin automatically converts language accent characters to non-accent characters in… by Upperdog 30K+ ★★★★★★★★★★ 4.6 (21) 9 months ago 61
2 Filenames to latin Filenames to latin Sanitize filenames to latin during upload. by webvitalii 9K+ ★★★★★★★★★★ 4.9 (14) 6 years ago 41
3 Clean Filenames Clean Filenames Removes or replace international or special characters that can make your filenames not… by Samuel Aguilera 3K+ ★★★★★★★★★★ 4.6 (8) 1 year ago 41
4 BEA – Sanitize Filename BEA – Sanitize Filename Remove all punctuation and accents from the filename of uploaded files. by BE API 1K+ ★★★★★★★★★★ 5 (4) 6 months ago 62
5 WP Sanitize Accented Uploads WP Sanitize Accented Uploads Simple plugin which removes accented characters from uploaded files. by Onni Hakala 800+ ★★★★★★★★★★ 5 (2) 10 years ago 34
6 MD5 Media Renamer MD5 Media Renamer Sanitize and rename automatically media files during upload using PHP time() as prefix and… by neoslab 400+ ★★★★★★★★★★ 5 (3) 13 years ago 34
7 Healthy filename Healthy filename Automatically clean the filenames. by Kantari Samy 100+ ★★★★★★★★★★ No reviews 5 years ago 25
8 Space Remover Space Remover Space Remover removes any leading or trailing spaces from your post and page content… by mgwe 100+ ★★★★★★★★★★ 4.7 (3) 10 years ago 31
9 LS Sanitize Greek Filename LS Sanitize Greek Filename Automatically replaces Greek characters in filename with their corresponding Latin… by lenasterg 80+ ★★★★★★★★★★ No reviews 2 years ago 34
10 Aucor URL Sanitizer Aucor URL Sanitizer Converts Cyrillic, Georgian, Arabic and Chinese characters in post, term slugs and media… by Generaxion 60+ ★★★★★★★★★★ No reviews 7 years ago 25

FAQ

CodePros SVG Secure Support: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 28, 2026

Is CodePros SVG Secure Support free?

Yes. CodePros SVG Secure Support is free to download and use from the official WordPress.org plugin directory.

Is CodePros SVG Secure Support safe to use in 2026?

CodePros SVG Secure Support works, but test it on a staging site before relying on it in 2026. Was last updated 4 months ago, and scores 49/100 on our health check.

How many websites use CodePros SVG Secure Support?

CodePros SVG Secure Support is active on <10 WordPress websites and has been downloaded 196 times since it launched in June 2026. It was downloaded 51 times in the last 30 days.

Does CodePros SVG Secure Support work with WordPress 7.1?

CodePros SVG Secure Support is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does CodePros SVG Secure Support need?

CodePros SVG Secure Support requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was CodePros SVG Secure Support last updated?

The latest version, 1.0.0, was released on June 15, 2026 (4 months ago).

Who makes CodePros SVG Secure Support?

CodePros SVG Secure Support is developed and maintained by codeprosai.

What are the best alternatives to CodePros SVG Secure Support?

The most popular alternatives to CodePros SVG Secure Support are Clean Image Filenames (30K+ installs), Filenames to latin (9K+ installs) and Clean Filenames (3K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.