Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
91 health vs 59 average across 2,206 Media plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
106.1K
now · peak 657.3K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Occasionally updatedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
1
releases in the last 12 months
4mo ago
latest release · v2.4.0
53
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 68% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “1M+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-09-06 · 1,458 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent review vibe
read from the latest 12 reviews to 2026-04-22Reviewers keep calling it simple and easy to use, with just a few asking for taxonomy support or inline SVG pasting and one old complaint about page load slowdown.
Recent reviews
All reviews on wp.org ↗- ★★★★★ jeeni4mo ago
Very helpful plugin, thanks!
Read on wp.org ↗ - ★★★★★ devlin16mo ago
Needed SVG upload support, and this plugin did the job. Very lightweight and easy to use. No issues so far. Some additional settings would be nice, but overall, it’s quite solid.
Read on wp.org ↗ - ★★★★★ Reza Asadi9mo ago
Nice And Easy plugin for using SVG files
Read on wp.org ↗ - ★★★★★ rrvoigt1.2y ago
Would have given a 5 star, but it seems support is missing for the taxonomy / terms section (like in categories) upload for SVG images. Keep getting an error that the upload isn’t supported. Hopefully this will be fixed in a future update. Will update once this is added. Cheers!
Read on wp.org ↗ - ★★★★★ Stefano1.3y ago
Great plugin! very usefull, but please can you add the possibility to add an inline SVG on the block pasting svg code? Thanks!
Read on wp.org ↗ - ★★★★★ bandgamin1.4y ago
Thanks to the plugin developers. The plugin helped me solve my issue.
Read on wp.org ↗ - ★★★★★ Jimmy Lee1.8y ago
Thanks for creating this plugin!
Read on wp.org ↗ - ★★★★★ headfalcon2.1y ago
I didn’t look into it but this plugin caused my homepage in translations to take about 30 seconds to load, instead of 1-2. We use WPML. It was back to normal the moment I deleted the plugin. This topic was modified 1 year, 11 months ago by headfalcon.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2025-09-22 Version 2.4.0 Added: Ability to upload SVGs from more admin locations (props @stormrockwell , @darylldoyle , @wpexplorer , @smerriman , @jeffpaul , @dkotter via #279 ). Changed: Added $attachment_id argument to filters safe_svg_use_wi 2.4.0
- 2025-08-13 Version 2.3.3 Security: Update the enshrined/svg-sanitize package from 0.19.0 to 0.22.0 to fix an issue with case-insensitive attributes slipping through the sanitiser and address PHP 8.4 deprecation warnings (props @darylldoyle , @su 2.3.3
- 2025-07-21 Version 2.3.2 Fixed: Visual parity between the front end and the block editor (props @s3rgiosan , @dkotter via #261 , #266 ). Changed: Bump WordPress “tested up to” version 6.8 (props @godleman , @jeffpaul , @dkotter via #251 , #254 ) 2.3.2
- 2024-12-05 Version 2.3.1 Fixed: Revert changes made to how we determine custom dimensions for SVGs (props @dkotter , @martinpl , @subfighter3 , @smerriman , @gigatyrant , @jeffpaul , @iamdharmesh via #238 ). 2.3.1
- 2024-11-25 Version 2.3.0 Added: New setting that allows large SVG files (roughly 10MB or greater) to be uploaded and sanitized properly (props @kirtangajjar , @faisal-alvi , @darylldoyle , @manojsiddoji , @dkotter via #201 ). Added: New get_svg_ 2.3.0
- 2024-08-28 Version 2.2.6 Changed: Bump WordPress “tested up to” version to 6.6 (props @sudip-md , @ankitguptaindia , @jeffpaul via #212 , #213 ). Changed: Bump WordPress minimum from 5.7 to 6.4 (props @sudip-md , @ankitguptaindia , @jeffpaul via 2.2.6
Known vulnerabilities
via Wordfence Intelligence6 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2024-10-17 CVE-2024-8378 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.5 Patched in 2.2.6
- 2023-03-23 CVE-2023-28426 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.3 Patched in 2.1.0
- High · 7.7 Safe SVG <= 1.9.9 - Content-Type Bypass ↗2022-03-25 CVE-2022-1091 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.9.10 Patched in 1.9.10
- Medium · 5.4 Safe SVG <= 1.9.5 - Cross-Site Scripting ↗2019-11-08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.9.5 Patched in 1.9.6
- Medium · 6.5 Safe SVG <= 1.9.4 - Denial of Service ↗
- Medium · 6.5 Safe SVG <= 1.9.4 - Denial of Service ↗
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 6.8.3
Languages
via translate.wordpress.orgTranslated into 33 languages, 23 at 90% or more
Plus 9 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2024-12-11 900K+ → 1M+ up after 1 days in tier
- 2024-12-10 1M+ → 900K+ down after 6 days in tier
- 2024-12-04 900K+ → 1M+ up after 4 days in tier
- 2024-11-30 1M+ → 900K+ down after 74 days in tier
- 2024-09-17 900K+ → 1M+ up after 241 days in tier
- 2024-01-20 800K+ → 900K+ up after 313 days in tier
- 2023-03-13 700K+ → 800K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
SVG Support 1M+ installs · 4.8★ · 2 shared tags A
- D Disable Real MIME Check 10K+ installs · 4.6★ · 2 shared tags D
-
Wordfence Security – Firewall, Malware Scan, and Login Security 5M+ installs · 4.7★ · 1 shared tag A
-
Hostinger Tools 3M+ installs · 3.6★ · 1 shared tag B
-
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) 3M+ installs · 4.9★ · 1 shared tag A -
Jetpack – WP Security, Backup, Speed, & Growth 3M+ installs · 3.8★ · 1 shared tag A
Embed this report card
Drop a live Pulse card for Safe SVG into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/safe-svg" width="480" height="300" style="border:0" loading="lazy" title="Safe SVG — Plugin Pulse"></iframe> Safe SVG: 1M+ active installs, 4.9★ (79 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/safe-svg