Safe SVG
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Safe pick
Yes — Safe SVG is a safe, well-maintained plugin to use in 2026. It runs on 1M+ sites, is rated 4.9/5 and was last updated 5 days ago, and scores 94/100 on our health check.
- One of the most-used plugins on the web — 1M+ active sites
- Loved by users — 4.9/5 from 79 reviews
- Actively developed — last update 5 days ago
- Tested with the latest WordPress (7.1)
- Momentum — downloads up 624.8% vs the previous 30 days
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Safe SVG stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| media | >100 |
| mime | #4 |
| security | #81 |
| SVG | #1 |
| Vector | #2 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 4.9 from 79 reviews
About Safe SVG
From the official readme · v2.5.1Description
Safe SVG is the best way to Allow SVG Uploads in WordPress!
It gives you the ability to allow SVG uploads whilst making sure that they’re sanitized to stop SVG/XML vulnerabilities affecting your site. It also gives you the ability to preview your uploaded SVGs in the media library in all views.
Current Features
- Sanitised SVGs – Don’t open up security holes in your WordPress site by allowing uploads of unsanitised files.
- SVGO Optimisation – Runs your SVGs through the SVGO tool on upload to save you space. This feature is disabled by default but can be enabled by adding the following code:
add_filter( 'safe_svg_optimizer_enabled', '__return_true' ); - View SVGs in the Media Library – Gone are the days of guessing which SVG is the correct one, we’ll enable SVG previews in the WordPress media library.
- Choose Who Can Upload – Restrict SVG uploads to certain users on your WordPress site or allow anyone to upload.
Initially a proof of concept for #24251.
SVG Sanitization is done through the following library: https://github.com/darylldoyle/svg-sanitizer.
SVG Optimization is done through the following library: https://github.com/svg/svgo.
Technical: Upload Path Security
WordPress’s _wp_handle_upload( $file, $action ) function allows any $action value, which determines the filter hook name: {$action}_prefilter. Safe SVG hooks common actions like wp_handle_upload and wp_handle_sideload, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths.
Installation
Install through the WordPress directory or download, unzip and upload the files to your /wp-content/plugins/ directory
Frequently asked questions
Can we change the allowed attributes and tags?
Yes, this can be done using the svg_allowed_attributes and svg_allowed_tags filters. They take one argument that must be returned. See below for examples: add_filter( 'svg_allowed_attributes', function ( $attributes ) { // Do what you want here... // This should return an array so add your attributes to // to the $attributes array before returning it. E.G. $attributes[] = 'target'; // This would allow the target="" attribute. return $attributes; } ); add_filter( 'svg_allowed_tags', function ( $tags ) { // Do what you want here... // This should return an array so add your tags to // to the…
Can my theme style an inline SVG?
Mostly, yes. The Inline SVG block renders an SVG that carries its own element inside a shadow root, because CSS inside an inline SVG is otherwise applied to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow root, so theme CSS such as .entry-content svg { fill: red; } will not apply to those SVGs. Inherited properties still cross the boundary, so setting color on an ancestor and using currentColor inside the SVG works, as do CSS custom properties. SVGs that do not contain a element are rendered without the shadow root and can be styled by theme stylesheets. To…
Why doesn’t Safe SVG globally enable SVG uploads?
Safe SVG only allows SVGs through upload paths it can actively sanitize. While most WordPress uploads use standard functions like wp_handle_upload() (which Safe SVG hooks), plugins and themes can create custom upload paths by calling WordPress’s underlying _wp_handle_upload() function with arbitrary action parameters. Globally enabling the image/svg+xml MIME type would allow SVGs through all upload paths—including custom ones Safe SVG cannot intercept and sanitize. This would create security vulnerabilities where unsanitized SVGs containing malicious scripts could be uploaded. This is a…
Where do I report security bugs found in this plugin?
Please report security bugs found in the source code of the Safe SVG plugin through the Patchstack Vulnerability Disclosure Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.
Changelog
This is a security release, it is recommended to upgrade immediately.
2.5.1 – 2026-09-22
- Added: New REST endpoint,
/safe-svg/v1/svg/ATTACHMENT-ID, that can be passed an attachment ID for an SVG and will return sanitized markup (props @dkotter, @peterwilsoncc via GHSA-3hhm-5qc9-q4xf). - Removed: Remove the
$sanitizerproperty from thesafe_svgclass. If you directly use thesafe_svgclass in order to access the$sanitizerproperty, you’ll need to update your code to instead use the newSvg_Sanitizerclass (props @dkotter, @peterwilsoncc via GHSA-3hhm-5qc9-q4xf). - Security: Resolve GHSA-qq4c-2xh7-x2wf (props @dhakalananda, @dkotter, @peterwilsoncc, @darylldoyle, @jeffpaul via GHSA-qq4c-2xh7-x2wf).
- Security: Resolve GHSA-vcfp-vw5v-gc9c (props @spectreDeveloper, @dkotter, @peterwilsoncc, @darylldoyle, @jeffpaul via GHSA-vcfp-vw5v-gc9c).
- Security: Resolve GHSA-3hhm-5qc9-q4xf (props @dkotter, @peterwilsoncc via GHSA-3hhm-5qc9-q4xf).
2.5.0 – 2026-09-07
- Security: Prevented direct access of PHP files (props @mehrazmorshed, @dkotter via #300).
- Security: The Inline SVG block now renders SVGs that carry their own
<style>element inside a shadow root, so their CSS is scoped to the block instead of applying to the whole page (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Security: Bump
enshrined/svg-sanitizefrom^0.22.0to^1.0.0to pull in security fixes (props @dkotter, @jeffpaul, @peterwilsoncc via #327). - Added: Link support for the SVG Inline block, including URL input, new tab toggle, and nofollow/sponsored rel options (props @vegetable-bits, @mgiannopoulos24, @jeffpaul, @thrijith, @peterwilsoncc, @dkotter, @pbiron via #315).
- Added: New
safe_svg_inline_use_shadow_domfilter to control which inline SVGs are isolated in a shadow root, and newsafe_svg_inline_shadow_stylesfilter to adjust the CSS injected alongside them (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Added: New
safe_svg_remove_remote_referencesfilter to strip remoteurl(),@importandimage-set()references, along with remotehreftargets, from uploaded SVGs. Off by default, because legitimate SVGs reference remote fonts and images but use this filter to turn it on (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Added: Added support for Enable Media Replace plugin (props @gthayer, @jeffpaul, @peterwilsoncc via #285).
- Changed: Bump WordPress minimum supported version to 6.9 (props @zamanq, @peterwilsoncc via #320).
- Changed: Bump “tested up to header” to indicate WordPress 7.1 support (props @navi151, @peterwilsoncc, @dkotter, @jeffpaul, @zamanq via #290, #311, #320).
- Changed: Theme CSS can no longer target an inline SVG that carries its own
<style>element, because stylesheets cannot reach into a shadow root. Style those SVGs from within the SVG itself, or opt out with thesafe_svg_inline_use_shadow_domfilter. Inherited properties, includingcolor/currentColorand custom properties, still apply as before, and SVGs without a<style>element are unaffected (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Changed: Updated blueprint file for WordPress.org live previews (props @fellyph, @jeffpaul, @peterwilsoncc via #287).
- Changed: Bump
svgofrom 3.2.0 to 3.3.5 (props @dependabot[bot], @jeffpaul, @peterwilsoncc, @dependabot via #309).
2.4.0 – 2025-09-22
- Added: Ability to upload SVGs from more admin locations (props @stormrockwell, @darylldoyle, @wpexplorer, @smerriman, @jeffpaul, @dkotter via #279).
- Changed: Added
$attachment_idargument to filterssafe_svg_use_width_height_attributesandsafe_svg_dimensions(props @roborourke, @dkotter via #278). - Fixed: Inconsistent or incorrect data type for
$svgargument in the filterssafe_svg_use_width_height_attributesandsafe_svg_dimensions(props @roborourke, @dkotter via #278).
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Safe SVG alternatives
All media plugins →FAQ
Safe SVG: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 28, 2026
Is Safe SVG free?
Yes. Safe SVG is free to download and use from the official WordPress.org plugin directory.
Is Safe SVG safe to use in 2026?
Yes — Safe SVG is a safe, well-maintained plugin to use in 2026. It runs on 1M+ sites, is rated 4.9/5 and was last updated 5 days ago, and scores 94/100 on our health check.
How many websites use Safe SVG?
Safe SVG is active on 1M+ WordPress websites and has been downloaded 14,121,637 times since it launched in July 2015. It was downloaded 798,576 times in the last 30 days.
Does Safe SVG work with WordPress 7.1?
Yes. The developer has tested Safe SVG up to WordPress 7.1.2, the latest release. It requires WordPress 6.9 or newer.
What PHP version does Safe SVG need?
Safe SVG requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Safe SVG last updated?
The latest version, 2.5.1, was released on September 22, 2026 (5 days ago).
Who makes Safe SVG?
Safe SVG is developed and maintained by 10up.
What are the best alternatives to Safe SVG?
The most popular alternatives to Safe SVG are FileBird (200K+ installs), Media Cleaner: Clean your W… (90K+ installs) and Media Library Assistant (70K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card