Safesprite Icons
Safesprite Icons lets you manage brand icons in a dedicated plugin library (collections/folders), sanitize every upload, and render icons with a lightweight <use> reference plus a single footer spritesheet.
by Kian Babaabady · github.com/kianbabai/safesprite-icons · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/kianbabai/safesprite-icons/archive/refs/heads/main.zipSecure icon library with footer SVG spritesheets. Does not enable Media Library SVG uploads.
Description
Safesprite Icons lets you manage brand icons in a dedicated plugin library (collections/folders), sanitize every upload, and render icons with a lightweight <use> reference plus a single footer spritesheet.
Security first
- SVG uploads are accepted only through the plugin Icon Library
- This plugin does not enable SVG uploads in the WordPress Media Library
- Uploads are sanitized with the vendored
enshrined/svg-sanitizelibrary (GPL-2.0-or-later), shipped inside the plugin - Front-end output uses sanitized
<symbol>sprites +<use>— not raw uploaded files as<img src>
Features
- Collections (one collection per icon)
- Rename icon titles and collection names (slugs stay stable)
- Trash / restore / permanent delete
- Shortcode:
[sfsi_icon slug="my-icon"] - PHP helper:
sfsi_icon( 'my-icon' ) - Gutenberg block
- TinyMCE button
- Elementor widget (loads only when Elementor is active)
- Nav menu item icons
Installation
- Upload the
safesprite-iconsfolder to/wp-content/plugins/ - Activate the plugin through the Plugins menu
- Open Safesprite in wp-admin, create a collection, upload SVGs
- Insert icons via block, shortcode, TinyMCE, menus, or Elementor
Frequently Asked Questions
Does this allow SVG in the Media Library?
No. Icons are managed only in the plugin library.
Where are files stored?
Sanitized SVG files live under wp-content/uploads/safesprite-icons/ with opaque filenames. Metadata is stored in plugin custom tables (not as custom post types).
What happens on uninstall?
By default, data is kept. Enable “Delete all plugin data on uninstall” under Safesprite -> Settings if you want tables and files removed.
What PHP extensions are required?
PHP 7.4+ with the dom and libxml extensions (used by the SVG sanitizer).
Screenshots
- Collections screen — create and manage icon folders
- Icons library — upload, search, rename, and copy shortcodes
- Icon picker in the block editor
- Settings — upload size limit and uninstall data option
- Trash — restore items or permanently delete icons and collections
Changelog
1.0.0
- First wordpress.org release candidate
- Secure Icon Library with sanitized uploads and footer spritesheets
- Gutenberg, Elementor, TinyMCE, Nav Menus, shortcode, and PHP helper
- Hardened SVG sanitization (no Media Library SVG enablement)
0.2.15
- Security: strip SVG `