CodePros SVG Secure Support
Highly secure SVG upload support for WordPress. Validates, sanitizes, and protects SVG files through a multi-layer security pipeline.
Use with caution
CodePros SVG Secure Support works, but test it on a staging site before relying on it in 2026. Was last updated 4 months ago, and scores 49/100 on our health check.
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where CodePros SVG Secure Support stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| sanitize | #59 |
| security | >100 |
| SVG | >100 |
| upload | >100 |
| xss protection | >100 |
About CodePros SVG Secure Support
From the official readme · v1.0.0Description
WordPress does not support SVG uploads natively — and naive SVG plugins are a well-known attack surface. SVG files are XML documents that can carry XSS payloads, XXE attacks, external resource injection, and embedded HTML. CodePros SVG Secure Support adds safe, production-ready SVG uploads through a layered defense pipeline.
Security Pipeline
Every uploaded SVG passes through five sequential checks before it is accepted:
- Extension check — Blocks double-extension filenames (e.g.
payload.php.svg) and enforces.svgonly. - MIME check — Verifies actual file bytes return
image/svg+xmlviafinfo; confirms<svgor<?xmlis present in the header bytes. - Size check — Rejects files exceeding the configured maximum (default 1 MB).
- Node-count check — Parses the XML and counts DOM nodes; rejects files above the threshold (default 5,000 nodes) to prevent node-flood DoS attacks.
- Dimension check — Reads the root
<svg>width/height/viewBox; rejects unreasonably large declared dimensions (default 10,000 px).
After validation, the file is sanitized:
- DOM sanitization via the battle-tested enshrined/svg-sanitize library with custom tag and attribute whitelists.
- Remote reference stripping — all external URLs are removed.
- Final string-level regex scan for
javascript:,<script, inline event handlers (on*=), and CSSexpression()— any match causes the upload to be rejected entirely.
Security Headers
When SVG attachment pages are served, the plugin adds:
Content-Security-Policy(configurable, secure default provided)X-Content-Type-Options: nosniffX-Frame-Options: SAMEORIGIN
Server-Level Hardening (Optional but Recommended)
The plugin’s PHP layer covers every SVG upload that passes through WordPress. But if someone accesses an uploaded file directly — e.g. by visiting https://example.com/wp-content/uploads/2024/01/logo.svg — WordPress is bypassed entirely, so the PHP security headers are never sent.
The plugin ships two ready-to-use server configuration snippets to close that gap:
uploads-htaccess.txt— for Apache / LiteSpeed serversuploads-nginx.conf— for Nginx servers
Each snippet does three things:
- Blocks server-side script execution in
wp-content/uploads/— if an attacker somehow uploads a.phpfile and tries to access it directly, the server returns 403 instead of executing it. - Enforces the correct SVG MIME type (
image/svg+xml) — some server setups serve SVGs astext/plain, which prevents browsers from honouring Content Security Policy rules scoped to that MIME type. - Adds security headers on direct SVG requests — the same
X-Content-Type-Options,X-Frame-Options, andContent-Security-Policyheaders that the PHP layer adds on WordPress attachment pages, so direct file links are equally protected.
Applying these snippets is the difference between WordPress-mediated access being protected and all access (direct URL, CDN pull, hotlink) being protected.
Admin UI
A tabbed settings page under Settings → SVG Secure Support provides:
- Settings tab — Configure allowed upload roles, file size/node/dimension limits, sanitization options, CSP header value, and logging preferences.
- Security Logs tab — Paginated, filterable log viewer showing every security event (blocked upload, removed tag/attribute, suspicious payload). Includes a log purge action.
Key Features
- Role-based upload access — select one or more WordPress roles (default: Administrator) whose members may upload SVG files
- Automatic upload-time sanitization — clean SVG replaces the original tmp file before WordPress moves it
- Security event logging to the WordPress debug log and a dedicated database table
- Configurable log retention with one-click purge
- Bundled
.htaccessand Nginx config snippets for the uploads directory
Installation
Minimum Requirements
- WordPress 6.0 or higher
- PHP 7.4 or higher
- Composer (to install dependencies before activation)
Installation Steps
- Upload the
svg-secure-supportfolder to/wp-content/plugins/. - In the plugin directory, run:
composer install - Activate the plugin through the Plugins screen in WordPress.
- Go to Settings → SVG Secure Support to configure upload capability, limits, and logging.
Important: The plugin will not activate correctly without the Composer dependencies. An admin notice will be displayed if vendor/autoload.php is missing.
Uploading via the WordPress Admin
After activation, simply upload .svg files through the standard WordPress Media Library. Users without the required capability will receive a clear error message.
Frequently asked questions
Who can upload SVG files after activation?
By default, only Administrators. You can grant access to one or more additional roles (Editor, Author, Contributor, Subscriber, or any custom role) under Settings → SVG Secure Support → Roles Allowed to Upload SVGs. If no roles are selected, only Administrators can upload. All role checks are performed at upload time.
Does this plugin make SVG uploads completely safe?
The plugin implements every layer recommended by security researchers: validation → DOM sanitization with a strict tag/attribute whitelist → string-level payload scan → Content Security Policy headers. No sanitization approach can offer an absolute guarantee, but this multi-layer pipeline eliminates all known SVG attack vectors.
What happens to a malicious SVG?
It depends on where the threat is detected: Validation failures (wrong extension, wrong MIME, too large, too many nodes) — upload is blocked entirely with an error message shown to the user. Sanitizable content (disallowed tags or attributes) — the content is stripped and the cleaned SVG is accepted. Unsanitizable payloads (e.g. javascript: survives DOM traversal) — upload is blocked entirely. All outcomes are recorded in the security log.
Will this slow down my site?
The validation and sanitization pipeline runs only during file uploads, not on page loads. There is no frontend performance impact. The security headers are lightweight HTTP headers added on SVG attachment pages only (except X-Content-Type-Options: nosniff, which is sent on all pages).
Do I need to configure Apache or Nginx separately?
It is strongly recommended. Without the server-level snippets, only requests routed through WordPress are protected. A direct URL to an uploaded SVG bypasses all PHP-layer security headers. Apache — applying uploads-htaccess.txt Open (or create) wp-content/uploads/.htaccess on your server. Copy the entire contents of uploads-htaccess.txt (found in the plugin directory) and append them to that file. Save. Apache picks up .htaccess changes immediately — no restart needed. Note: WordPress may overwrite uploads/.htaccess when you save Permalink settings. Re-apply the snippet after that happens…
What is logged?
The following event types are recorded: upload_allowed — SVG passed all checks upload_sanitized — SVG was cleaned before being saved upload_blocked — SVG was rejected tag_removed — A disallowed tag was stripped attribute_removed — A disallowed attribute was stripped suspicious_payload — A javascript: or similar payload was detected
How do I view and manage logs?
Go to Settings → SVG Secure Support and click the Security Logs tab. You can filter by severity (Info / Warning / Critical) and event type, and purge entries older than the configured retention period.
Does the plugin work with Multisite?
The plugin has not been tested on WordPress Multisite. Network-wide activation is not currently supported.
Changelog
Initial release. No upgrade steps required.
1.0.0
- Initial release.
- Role-based upload access with multi-role selection; Administrators allowed by default.
- Five-check SVG validation pipeline (extension, MIME, size, node count, dimensions).
- DOM sanitization via enshrined/svg-sanitize with custom tag/attribute whitelists.
- XML comment stripping and enhanced string-level XSS payload scan as a final defense layer.
- Security event logging to WP debug log and database table.
- CSP, X-Content-Type-Options, and X-Frame-Options headers on SVG attachment pages.
- Tabbed admin UI with settings and security log viewer.
- Bundled Apache and Nginx upload-directory hardening snippets.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best CodePros SVG Secure Support alternatives
All sanitize plugins →FAQ
CodePros SVG Secure Support: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 28, 2026
Is CodePros SVG Secure Support free?
Yes. CodePros SVG Secure Support is free to download and use from the official WordPress.org plugin directory.
Is CodePros SVG Secure Support safe to use in 2026?
CodePros SVG Secure Support works, but test it on a staging site before relying on it in 2026. Was last updated 4 months ago, and scores 49/100 on our health check.
How many websites use CodePros SVG Secure Support?
CodePros SVG Secure Support is active on <10 WordPress websites and has been downloaded 196 times since it launched in June 2026. It was downloaded 51 times in the last 30 days.
Does CodePros SVG Secure Support work with WordPress 7.1?
CodePros SVG Secure Support is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does CodePros SVG Secure Support need?
CodePros SVG Secure Support requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was CodePros SVG Secure Support last updated?
The latest version, 1.0.0, was released on June 15, 2026 (4 months ago).
Who makes CodePros SVG Secure Support?
CodePros SVG Secure Support is developed and maintained by codeprosai.
What are the best alternatives to CodePros SVG Secure Support?
The most popular alternatives to CodePros SVG Secure Support are Clean Image Filenames (30K+ installs), Filenames to latin (9K+ installs) and Clean Filenames (3K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card

