89 Quality Score
Active Installs
27/30

With 1,000,000+ active installs, Safe SVG is widely adopted and clearly the default choice in its niche.

Update Freshness
25/25

The plugin was last updated on 2026-04-14, is tested with WordPress 7.0, and requires WordPress 6.6 and PHP 7.4, which signals an actively maintained codebase on current versions.

User Rating
15/15

A 98/100 rating from 78 reviews is excellent and indicates strong user satisfaction among those who took the time to rate it.

Support Health
8/15

Support health sits at 50/15 with 0 of 0 support threads, which is neutral; there is no negative signal but also no trackable public support activity to score.

WP Compatibility
15/15

Compatibility scores a perfect 100/15, reflecting tested support for the latest WordPress and PHP requirements with no known conflicts.

Scores higher than 99% of indexed plugins

About

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Active Installs 1M+
Rating ★★★★½ 4.9/5
Last Updated 2026-09-22 3:29pm GMT
Requires WordPress 6.9+
Tested Up To 7.1.2
Requires PHP 7.4+

Security History

6 known vulnerabilities, all patched
2 High 4 Medium

Most recent: October 17, 2024

View details ▸

Powered by Wordfence Intelligence

What It Does

Safe SVG lets you upload SVG files to the WordPress media library by adding SVG to the allowed mime types, then runs each file through an XML/SVG sanitizer before it is stored. This strips malicious scripts, external references, and other payloads that a raw SVG could carry, which is important because SVGs are XML documents and can execute JavaScript in the browser. In practice you get native SVG support in the block editor, Media Library, and featured image fields without exposing the well-known SVG XSS attack surface.

Who It's For

This plugin is a good fit for design-heavy WordPress sites that regularly upload custom SVG assets, including design agencies, illustration portfolios, marketing teams, and tech startups that need vector logos, icons, or inline graphics in posts and pages. It is also useful for educational and publishing sites where multiple contributors upload SVGs and you want a baseline sanitization layer enforced at upload time. If you have ever been frustrated by the default 'Sorry, you are not allowed to upload this file type' error on SVG uploads, this solves that exact problem.

Who Should Skip It

If your site never accepts SVG uploads, or if you already use a security suite that sanitizes SVGs at the WAF or proxy layer, this plugin adds no real value. Developers comfortable handling SVG sanitization in their build pipeline (e.g., via SVGO before deployment) also do not need it in production.

The Bottom Line

Safe SVG is a focused, well-maintained plugin that does one thing and does it well: it lets you upload SVGs safely. With 1M+ installs, a 98/100 rating, and a perfect maintenance and compatibility profile, it is a low-risk choice for any site that handles SVG assets. Just be aware that it does not replace a full security stack, and the support thread count is too low to draw any meaningful conclusion about responsiveness.

Tags

media mime security SVG Vector