{"repo":"10up/safe-svg","free":true,"listed":false,"github":"https://github.com/10up/safe-svg","clone":"git clone https://github.com/10up/safe-svg.git","description":"Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.","language":"PHP","stars":338,"topics":["wordpress","svg","sanitize","upload","security","svg-upload","image","vector","file","graphic"],"license":"GPL-2.0","category":"security-tools","readme_excerpt":"Safe SVG Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website. Overview Safe SVG is the best way to Allow SVG Uploads in WordPress! It gives you the ability to allow SVG uploads whilst making sure that they're sanitized to stop SVG/XML vulnerabilities affecting your site. It also gives you the ability to preview your uploaded SVGs in the media library in all views. Current Features Sanitised SVGs - Don't open up security holes in your WordPress site by allowing uploads of unsanitised files. SVGO Optimisation - Runs your SVGs through the SVGO tool on upload to save you space. This feature is disabled by default but can be enabled by adding the following code: add filter( 'safe svg optimizer enabled', ' return true' ); View SVGs in the Media Library - Gone are the days of guessing which SVG is the correct one, we'll enable SVG previews in the WordPress media library. Choose Who Can Upload - Restrict SVG uploads to certain users on your WordPress site or allow anyone to upload. Initially a proof of concept for #24251. SVG Sanitization is done through the following library: https://github.com/darylldoyle/svg-sanitizer. SVG Optimization is done through the following library: https://github.com/svg/svgo. Technical: Upload Path Security WordPress’s wp handle upload( $file, $action ) function allows any $action value, which determines the filter hook name: {$action} prefilter . Safe SVG hooks common actions like wp handle upload and wp handle","default_branch":null,"files":null,"tree":[],"storefront":"/r/10up","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/10up/safe-svg/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}