Safe SVG

Description

Safe SVG est le meilleur moyen d’autoriser les téléversements de SVG dans WordPress !

Il vous permet d’autoriser les téléversements de SVG tout en vous assurant qu’ils soient nettoyés pour éliminer les vulnérabilités SVG/XML qui peuvent affecter votre site.
Il vous donne également la possibilité de prévisualiser dans la médiathèque vos SVG téléversés.

Fonctionnalités actuelles

  • SVG désinfectés – N’ouvrez pas de failles de sécurité de votre site WordPress en autorisant les téléversements de fichiers non contrôlés.
  • Optimisation SVGO – Exécute vos SVG via l’outil SVGO lors du téléversement pour vous faire gagner de la place. Cette fonctionnalité est désactivée par défaut mais peut être activée en ajoutant le code suivant : add_filter( 'safe_svg_optimizer_enabled', '__return_true' );
  • Afficher les SVG dans la médiathèque – Fini le temps où il fallait deviner quel SVG est le bon, nous activerons les aperçus SVG dans la médiathèque de WordPress.
  • Choisissez qui peut téléverser – Limitez les téléversements de SVG à certains utilisateurs de votre site WordPress ou autorisez n’importe qui à en téléverser.

Initialement une preuve de concept pour #24251.

La normalisation SVG est effectuée avec la bibliothèque suivante : https://github.com/darylldoyle/svg-sanitizer.

L’optimisation des SVG est effectuée via la bibliothèque suivante : https://github.com/svg/svgo.

Technical: Upload Path Security

WordPress’s _wp_handle_upload( $file, $action ) function allows any $action value, which determines the filter hook name: {$action}_prefilter. Safe SVG hooks common actions like wp_handle_upload and wp_handle_sideload, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths.

Blocs

Cette extension fournit 1 bloc.

  • Safe SVG Display the SVG icon

Installation

Installez via le répertoire WordPress ou téléchargez, décompressez et téléversez les fichiers dans votre répertoire /wp-content/plugins/

FAQ

Pouvons-nous modifier les attributs et les balises autorisés ?

Oui, cela peut être fait en utilisant les filtres svg_allowed_attributes et svg_allowed_tags.
Ils prennent un argument qui doit être retourné. Voir ci-dessous pour des exemples :

add_filter( 'svg_allowed_attributes', function ( $attributes ) {

    // Do what you want here...

    // This should return an array so add your attributes to
    // to the $attributes array before returning it. E.G.

    $attributes[] = 'target'; // This would allow the target="" attribute.

    return $attributes;
} );


add_filter( 'svg_allowed_tags', function ( $tags ) {

    // Do what you want here...

    // This should return an array so add your tags to
    // to the $tags array before returning it. E.G.

    $tags[] = 'use'; // This would allow the <use> element.

    return $tags;
} );

Can my theme style an inline SVG?

Mostly, yes. The Inline SVG block renders an SVG that carries its own <style> element inside a shadow root, because CSS inside an inline SVG is otherwise applied to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow root, so theme CSS such as .entry-content svg { fill: red; } will not apply to those SVGs.

Inherited properties still cross the boundary, so setting color on an ancestor and using currentColor inside the SVG works, as do CSS custom properties. SVGs that do not contain a <style> element are rendered without the shadow root and can be styled by theme stylesheets.

To turn isolation off, at the cost of allowing an SVG’s CSS to affect the rest of the page:

add_filter( 'safe_svg_inline_use_shadow_dom', '__return_false' );

Why doesn’t Safe SVG globally enable SVG uploads?

Safe SVG only allows SVGs through upload paths it can actively sanitize. While most WordPress uploads use standard functions like wp_handle_upload() (which Safe SVG hooks), plugins and themes can create custom upload paths by calling WordPress’s underlying _wp_handle_upload() function with arbitrary action parameters.

Globally enabling the image/svg+xml MIME type would allow SVGs through all upload paths—including custom ones Safe SVG cannot intercept and sanitize. This would create security vulnerabilities where unsanitized SVGs containing malicious scripts could be uploaded.

This is a deliberate design decision: Safe SVG prioritizes guaranteed sanitization over broad compatibility. SVGs are only allowed when we can ensure they’re safe.

Where do I report security bugs found in this plugin?

Please report security bugs found in the source code of the Safe SVG plugin through the Patchstack Vulnerability Disclosure  Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.

Avis

11 mars 2026 1 réponse
Needed SVG upload support, and this plugin did the job. Very lightweight and easy to use. No issues so far. Some additional settings would be nice, but overall, it's quite solid.
21 juin 2025 1 réponse
Would have given a 5 star, but it seems support is missing for the taxonomy / terms section (like in categories) upload for SVG images. Keep getting an error that the upload isn't supported. Hopefully this will be fixed in a future update. Will update once this is added. Cheers!
30 avril 2025 1 réponse
Great plugin! very usefull, but please can you add the possibility to add an inline SVG on the block pasting svg code? Thanks!
Lire les 79 avis

Contributeurs/contributrices & développeurs/développeuses

« Safe SVG » est un logiciel libre. Les personnes suivantes ont contribué à cette extension.

Contributeurs

“Safe SVG” a été traduit dans 30 locales. Remerciez l’équipe de traduction pour ses contributions.

Traduisez « Safe SVG » dans votre langue.

Le développement vous intéresse ?

Parcourir le code, consulter le SVN dépôt, ou s’inscrire au journal de développement par RSS.

Journal des modifications

2.5.0 – 2026-09-07

2.4.0 – 2025-09-22

2.3.3 – 2025-08-13

2.3.2 – 2025-07-21

2.3.1 – 2024-12-05

2.3.0 – 2024-11-25

2.2.6 – 2024-08-28

Voir le détail de l’historique du journal des modifications ici.