
內容簡介
Safe SVG 是一個讓您在 WordPress 中安全上傳 SVG 檔案的最佳解決方案。它確保上傳的 SVG 檔案經過清理,避免安全漏洞,同時提供在媒體庫中預覽 SVG 的功能。
【主要功能】
• 安全清理 SVG 檔案,防止安全漏洞
• SVGO 優化,減少檔案大小以節省空間
• 在媒體庫中預覽 SVG 檔案,方便識別
• 設定上傳權限,限制特定用戶上傳
外掛標籤
開發者團隊
📦 歷史版本下載
原文外掛簡介
Safe SVG is the best way to Allow SVG Uploads in WordPress!
It gives you the ability to allow SVG uploads whilst making sure that they’re sanitized to stop SVG/XML vulnerabilities affecting your site. It also gives you the ability to preview your uploaded SVGs in the media library in all views.
Current Features
Sanitised SVGs – Don’t open up security holes in your WordPress site by allowing uploads of unsanitised files.
SVGO Optimisation – Runs your SVGs through the SVGO tool on upload to save you space. This feature is disabled by default but can be enabled by adding the following code: add_filter( 'safe_svg_optimizer_enabled', '__return_true' );
View SVGs in the Media Library – Gone are the days of guessing which SVG is the correct one, we’ll enable SVG previews in the WordPress media library.
Choose Who Can Upload – Restrict SVG uploads to certain users on your WordPress site or allow anyone to upload.
Initially a proof of concept for #24251.
SVG Sanitization is done through the following library: https://github.com/darylldoyle/svg-sanitizer.
SVG Optimization is done through the following library: https://github.com/svg/svgo.
Technical: Upload Path Security
WordPress’s _wp_handle_upload( $file, $action ) function allows any $action value, which determines the filter hook name: {$action}_prefilter. Safe SVG hooks common actions like wp_handle_upload and wp_handle_sideload, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths.
