WP Manifestindependent plugin directory
manifest / security / wp-mu-svg

nitida — SVG Uploads

WordPress must-use plugin: allows SVG uploads and sanitizes every one with enshrined/svg-sanitize, so an uploaded SVG cannot run script.

by nitida · github.com/lintmycode/wp-mu-svg

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/lintmycode/wp-mu-svg/archive/refs/heads/main.zip

nitida/wp-mu-svg

WordPress must-use plugin, installed with Composer, that allows SVG uploads and runs every one through an allowlist sanitizer (enshrined/svg-sanitize, the library WordPress VIP and Safe SVG use) before WordPress stores it.

Why not the old svg-upload-support.php

That file (hand-copied to 9 sites from the wp-docker-bedrock starter) refused an SVG only if it contained `