Safe SVG
by 10up 4.9 (79 reviews)

Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Safe SVG ranks #53 among WordPress.org plugins with 1,000,000+ active installations, is #7 of 4,482 in the Security category, a 4.9/5 rating from 79 reviews, and was last updated Sep 6, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v2.5.0 Current Version v2.5.0
Updated 1 week ago Last Update on 06 Sep, 2026
Refreshed 9 hours ago Last Refreshed on
#7 of 4,482 in Security Top 1% by installs Downloads -63.6% this week Actively maintained
View on WordPress.org
Rank
#53
No change
Active Installs
1M+
-26%
KW Avg Position
20
0.6 better
Downloads
12.8M
+10,583 today
Support Resolved
0%
No change
Rating
98%
Review 4.9 out of 5
4.9 (79 reviews)

Next Milestone 2M

Total Progress 38.5%
1M+ 2M+
24
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 615,385 more installs to reach 2M+

Rank Changes

33 43 53 63 73 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
33 43 54 64 74 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Current #53
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10K 20K 30K 40K 50K 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
0 50K 100K 150K 200K 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.9
79 reviews
Overall 98%
5
71 (90%)
4
7 (9%)
3
0 (0%)
2
1 (1%)
1
0 (0%)

Security History

Source: WPVulnerability

10 known vulnerabilities on record · 1 in the last 24 months · checked 1 week ago

  1. Safe SVG [safe-svg] < 2.2.6

    CVE-2024-8378 · Fixed in v2.2.6

  2. Safe SVG [safe-svg] < 2.1.0

    CVE-2023-28426 · Fixed in v2.1.0

  3. Safe SVG [safe-svg] < 1.9.10

    Fixed in v1.9.10

  4. Safe SVG [safe-svg] < 1.9.10

    CVE-2022-1091 · Fixed in v1.9.10

  5. Safe SVG [safe-svg] < 1.9.6

    Fixed in v1.9.6

  6. Safe SVG [safe-svg] < 1.9.6

    Fixed in v1.9.6

  7. Safe SVG [safe-svg] < 1.9.5

    Fixed in v1.9.5

  8. Safe SVG [safe-svg] < 1.9.5

    CVE-2019-18855 · Fixed in v1.9.5

  9. Safe SVG [safe-svg] < 1.9.5

    CVE-2019-18854 · Fixed in v1.9.5

  10. Safe SVG [safe-svg] < 1.9.6

    Fixed in v1.9.6

TL;DR

AI summary of the plugin's readme

Safe SVG is for WordPress site owners and administrators who want to allow SVG file uploads. It sanitizes uploaded SVGs to prevent XML/SVG security vulnerabilities while enabling previews of SVGs in the media library.

  • Sanitizes uploaded SVGs
  • SVGO optimization on upload
  • SVG previews in media library
  • Restrict who can upload SVGs

Frequently Asked Questions

Common questions about Safe SVG

Yes, this can be done using the svg_allowed_attributes and svg_allowed_tags filters. They take one argument that must be returned. See below for examples: add_filter( 'svg_allowed_attributes', function ( $attributes ) { // Do what you want here... // This should return an array so add your attributes to // to the $attributes array before returning it. E.G. $attributes[] = 'target'; // This would allow the target="" attribute. return $attributes; } ); add_filter( 'svg_allowed_tags', function ( $tags ) { // Do what you want here... // This should return an array so add your tags to // to the $tags array before returning it. E.G. $tags[] = 'use'; // This would allow the <use> element. return $tags; } );
Mostly, yes. The Inline SVG block renders an SVG that carries its own <style> element inside a shadow root, because CSS inside an inline SVG is otherwise applied to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow root, so theme CSS such as .entry-content svg { fill: red; } will not apply to those SVGs. Inherited properties still cross the boundary, so setting color on an ancestor and using currentColor inside the SVG works, as do CSS custom properties. SVGs that do not contain a <style> element are rendered without the shadow root and can be styled by theme stylesheets. To turn isolation off, at the cost of allowing an SVG's CSS to affect the rest of the page: add_filter( 'safe_svg_inline_use_shadow_dom', '__return_false' );
Safe SVG only allows SVGs through upload paths it can actively sanitize. While most WordPress uploads use standard functions like wp_handle_upload() (which Safe SVG hooks), plugins and themes can create custom upload paths by calling WordPress's underlying _wp_handle_upload() function with arbitrary action parameters. Globally enabling the image/svg+xml MIME type would allow SVGs through all upload paths—including custom ones Safe SVG cannot intercept and sanitize. This would create security vulnerabilities where unsanitized SVGs containing malicious scripts could be uploaded. This is a deliberate design decision: Safe SVG prioritizes guaranteed sanitization over broad compatibility. SVGs are only allowed when we can ensure they're safe.
Please report security bugs found in the source code of the Safe SVG plugin through the Patchstack Vulnerability Disclosure  Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.

More plugins by 10up

Sign In / Register

You need to sign in or register to use this feature.