Title: Safe SVG
Author: 10up
Published: <strong>Gouere 3, 2015</strong>
Last modified: Gwengolo 22, 2026

---

Search plugins

![](https://ps.w.org/safe-svg/assets/banner-772x250.png?rev=2683939)

![](https://ps.w.org/safe-svg/assets/icon.svg?rev=2779013)

# Safe SVG

 By [10up](https://profiles.wordpress.org/10up/)

[Download](https://downloads.wordpress.org/plugin/safe-svg.2.5.1.zip)

[Live Preview](https://bre.wordpress.org/plugins/safe-svg/?preview=1)

 * [Details](https://bre.wordpress.org/plugins/safe-svg/#description)
 * [Reviews](https://bre.wordpress.org/plugins/safe-svg/#reviews)
 *  [Installation](https://bre.wordpress.org/plugins/safe-svg/#installation)
 * [Development](https://bre.wordpress.org/plugins/safe-svg/#developers)

 [Support](https://wordpress.org/support/plugin/safe-svg/)

## Description

Safe SVG is the best way to Allow SVG Uploads in WordPress!

It gives you the ability to allow SVG uploads whilst making sure that they’re sanitized
to stop SVG/XML vulnerabilities affecting your site. It also gives you the ability
to preview your uploaded SVGs in the media library in all views.

#### Current Features

 * **Sanitised SVGs** – Don’t open up security holes in your WordPress site by allowing
   uploads of unsanitised files.
 * **SVGO Optimisation** – Runs your SVGs through the SVGO tool on upload to save
   you space. This feature is disabled by default but can be enabled by adding the
   following code: `add_filter( 'safe_svg_optimizer_enabled', '__return_true' );`
 * **View SVGs in the Media Library** – Gone are the days of guessing which SVG 
   is the correct one, we’ll enable SVG previews in the WordPress media library.
 * **Choose Who Can Upload** – Restrict SVG uploads to certain users on your WordPress
   site or allow anyone to upload.

Initially a proof of concept for [#24251](https://core.trac.wordpress.org/ticket/24251).

SVG Sanitization is done through the following library: [https://github.com/darylldoyle/svg-sanitizer](https://github.com/darylldoyle/svg-sanitizer).

SVG Optimization is done through the following library: [https://github.com/svg/svgo](https://github.com/svg/svgo).

#### Technical: Upload Path Security

WordPress’s `_wp_handle_upload( $file, $action )` function allows any `$action` 
value, which determines the filter hook name: `{$action}_prefilter`. Safe SVG hooks
common actions like `wp_handle_upload` and `wp_handle_sideload`, but cannot hook
arbitrary custom actions defined by third-party code. Since upload actions are unbounded
and MIME allowances are global, we cannot guarantee sanitization coverage across
all possible upload paths.

## Blocks

This plugin provides 1 block.

 *   Safe SVG Display the SVG icon

## Installation

Install through the WordPress directory or download, unzip and upload the files 
to your `/wp-content/plugins/` directory

## FAQ

### Can we change the allowed attributes and tags?

Yes, this can be done using the `svg_allowed_attributes` and `svg_allowed_tags` 
filters.
 They take one argument that must be returned. See below for examples:

    ```
    add_filter( 'svg_allowed_attributes', function ( $attributes ) {

        // Do what you want here...

        // This should return an array so add your attributes to
        // to the $attributes array before returning it. E.G.

        $attributes[] = 'target'; // This would allow the target="" attribute.

        return $attributes;
    } );


    add_filter( 'svg_allowed_tags', function ( $tags ) {

        // Do what you want here...

        // This should return an array so add your tags to
        // to the $tags array before returning it. E.G.

        $tags[] = 'use'; // This would allow the <use> element.

        return $tags;
    } );
    ```

### Can my theme style an inline SVG?

Mostly, yes. The Inline SVG block renders an SVG that carries its own `<style>` 
element inside a shadow root, because CSS inside an inline SVG is otherwise applied
to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow
root, so theme CSS such as `.entry-content svg { fill: red; }` will not apply to
those SVGs.

Inherited properties still cross the boundary, so setting `color` on an ancestor
and using `currentColor` inside the SVG works, as do CSS custom properties. SVGs
that do not contain a `<style>` element are rendered without the shadow root and
can be styled by theme stylesheets.

To turn isolation off, at the cost of allowing an SVG’s CSS to affect the rest of
the page:

    ```
    add_filter( 'safe_svg_inline_use_shadow_dom', '__return_false' );
    ```

### Why doesn’t Safe SVG globally enable SVG uploads?

Safe SVG only allows SVGs through upload paths it can actively sanitize. While most
WordPress uploads use standard functions like `wp_handle_upload()` (which Safe SVG
hooks), plugins and themes can create custom upload paths by calling WordPress’s
underlying `_wp_handle_upload()` function with arbitrary action parameters.

Globally enabling the `image/svg+xml` MIME type would allow SVGs through all upload
paths—including custom ones Safe SVG cannot intercept and sanitize. This would create
security vulnerabilities where unsanitized SVGs containing malicious scripts could
be uploaded.

This is a deliberate design decision: Safe SVG prioritizes guaranteed sanitization
over broad compatibility. SVGs are only allowed when we can ensure they’re safe.

### Where do I report security bugs found in this plugin?

Please report security bugs found in the source code of the Safe SVG plugin through
the [Patchstack Vulnerability Disclosure  Program](https://patchstack.com/database/vdp/9e5fb4ed-587a-4ada-8dc3-a5b7362c0501).
The Patchstack team will assist you with verification, CVE assignment, and notify
the developers of this plugin.

## Reviews

![](https://secure.gravatar.com/avatar/07a20c9f56b2b62f304e1e3820aec06f9bf96bd4fd2533749b0e738042fb6e6c?
s=60&d=retro&r=g)

### 󠀁[Great plugin, updated!](https://wordpress.org/support/topic/great-plugin-updated/)󠁿

 [Karolina Vyskocilova](https://profiles.wordpress.org/vyskoczilova/) Eost 6, 2026
1 reply

Must use plugin, well maintained, installing almost every time and just now I've
realized, that I didn't review it. Keep it up and thanks!

![](https://secure.gravatar.com/avatar/18572aa4a12155a9fbb006511bf21eb7d29567b1d9de15168ad92ae9eb5d6b70?
s=60&d=retro&r=g)

### 󠀁[Very helpful plugin](https://wordpress.org/support/topic/very-helpful-plugin-496/)󠁿

 [jeeni](https://profiles.wordpress.org/jeeni/) Ebrel 22, 2026 1 reply

Very helpful plugin, thanks!

![](https://secure.gravatar.com/avatar/71f6586dbbc3ee4e15425b5c5aacba2f9b65db3566e3dae8ee207c0ea9cb5aa9?
s=60&d=retro&r=g)

### 󠀁[Works Well](https://wordpress.org/support/topic/works-well-3155/)󠁿

 [devlin1](https://profiles.wordpress.org/devlin1/) Meurzh 11, 2026 1 reply

Needed SVG upload support, and this plugin did the job. Very lightweight and easy
to use. No issues so far. Some additional settings would be nice, but overall, it's
quite solid.

![](https://secure.gravatar.com/avatar/dac57dd68e7365677d7dac1e85643c8e914074c6f703a424de5388db05bd6a47?
s=60&d=retro&r=g)

### 󠀁[Nice And Easy](https://wordpress.org/support/topic/nice-and-easy-450/)󠁿

 [Reza Asadi](https://profiles.wordpress.org/asadister/) miz Du 19, 2025 1 reply

Nice And Easy plugin for using SVG files

![](https://secure.gravatar.com/avatar/9def864927160fb7e47804e7cf79694bbbc5a709a915434e221019a8e78f21b2?
s=60&d=retro&r=g)

### 󠀁[Good plugin, but missing …](https://wordpress.org/support/topic/good-plugin-but-missing/)󠁿

 [rrvoigt](https://profiles.wordpress.org/rrvoigt/) Mezheven 21, 2025 1 reply

Would have given a 5 star, but it seems support is missing for the taxonomy / terms
section (like in categories) upload for SVG images. Keep getting an error that the
upload isn't supported. Hopefully this will be fixed in a future update. Will update
once this is added. Cheers!

![](https://secure.gravatar.com/avatar/91db05863fab71aeade0dec63660fe332672727d0f7d5dac4fec60fb76f8547e?
s=60&d=retro&r=g)

### 󠀁[Wonderful + fetaure request](https://wordpress.org/support/topic/wonderful-fetaure-request/)󠁿

 [Stefano](https://profiles.wordpress.org/stefacchio/) Ebrel 30, 2025 1 reply

Great plugin! very usefull, but please can you add the possibility to add an inline
SVG on the block pasting svg code? Thanks!

 [ Read all 79 reviews ](https://wordpress.org/support/plugin/safe-svg/reviews/)

## Contributors & Developers

“Safe SVG” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ 10up ](https://profiles.wordpress.org/10up/)
 *   [ Daryll Doyle ](https://profiles.wordpress.org/enshrined/)
 *   [ Jeffrey Paul ](https://profiles.wordpress.org/jeffpaul/)

“Safe SVG” has been translated into 32 locales. Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/safe-svg/contributors)
for their contributions.

[Translate “Safe SVG” into your language.](https://translate.wordpress.org/projects/wp-plugins/safe-svg)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/safe-svg/), check out
the [SVN repository](https://plugins.svn.wordpress.org/safe-svg/), or subscribe 
to the [development log](https://plugins.trac.wordpress.org/log/safe-svg/) by [RSS](https://plugins.trac.wordpress.org/log/safe-svg/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.5.1 – 2026-09-22

 * **Added:** New REST endpoint, `/safe-svg/v1/svg/ATTACHMENT-ID`, that can be passed
   an attachment ID for an SVG and will return sanitized markup (props [@dkotter](https://github.com/dkotter),
   [@peterwilsoncc](https://github.com/peterwilsoncc) via [GHSA-3hhm-5qc9-q4xf](https://github.com/10up/safe-svg/security/advisories/GHSA-3hhm-5qc9-q4xf)).
 * **Removed:** Remove the `$sanitizer` property from the `safe_svg` class. If you
   directly use the `safe_svg` class in order to access the `$sanitizer` property,
   you’ll need to update your code to instead use the new `Svg_Sanitizer` class (
   props [@dkotter](https://github.com/dkotter), [@peterwilsoncc](https://github.com/peterwilsoncc)
   via [GHSA-3hhm-5qc9-q4xf](https://github.com/10up/safe-svg/security/advisories/GHSA-3hhm-5qc9-q4xf)).
 * **Security:** Resolve GHSA-qq4c-2xh7-x2wf (props [@dhakalananda](https://github.com/dhakalananda),
   [@dkotter](https://github.com/dkotter), [@peterwilsoncc](https://github.com/peterwilsoncc),
   [@darylldoyle](https://github.com/darylldoyle), [@jeffpaul](https://github.com/jeffpaul)
   via [GHSA-qq4c-2xh7-x2wf](https://github.com/10up/safe-svg/security/advisories/GHSA-qq4c-2xh7-x2wf)).
 * **Security:** Resolve GHSA-vcfp-vw5v-gc9c (props [@spectreDeveloper](https://github.com/spectreDeveloper),
   [@dkotter](https://github.com/dkotter), [@peterwilsoncc](https://github.com/peterwilsoncc),
   [@darylldoyle](https://github.com/darylldoyle), [@jeffpaul](https://github.com/jeffpaul)
   via [GHSA-vcfp-vw5v-gc9c](https://github.com/10up/safe-svg/security/advisories/GHSA-vcfp-vw5v-gc9c)).
 * **Security:** Resolve GHSA-3hhm-5qc9-q4xf (props [@dkotter](https://github.com/dkotter),
   [@peterwilsoncc](https://github.com/peterwilsoncc) via [GHSA-3hhm-5qc9-q4xf](https://github.com/10up/safe-svg/security/advisories/GHSA-3hhm-5qc9-q4xf)).

#### 2.5.0 – 2026-09-07

 * **Security:** Prevented direct access of PHP files (props [@mehrazmorshed](https://github.com/mehrazmorshed),
   [@dkotter](https://github.com/dkotter) via [#300](https://github.com/10up/safe-svg/pull/300)).
 * **Security:** The Inline SVG block now renders SVGs that carry their own `<style
   >` element inside a shadow root, so their CSS is scoped to the block instead 
   of applying to the whole page (props [@darylldoyle](https://github.com/darylldoyle),
   [@dkotter](https://github.com/dkotter), [@jeffpaul](https://github.com/jeffpaul),
   [@peterwilsoncc](https://github.com/peterwilsoncc) via [#328](https://github.com/10up/safe-svg/pull/328)).
 * **Security:** Bump `enshrined/svg-sanitize` from `^0.22.0` to `^1.0.0` to pull
   in security fixes (props [@dkotter](https://github.com/dkotter), [@jeffpaul](https://github.com/jeffpaul),
   [@peterwilsoncc](https://github.com/peterwilsoncc) via [#327](https://github.com/10up/safe-svg/pull/327)).
 * **Added:** Link support for the SVG Inline block, including URL input, new tab
   toggle, and nofollow/sponsored rel options (props [@vegetable-bits](https://github.com/vegetable-bits),
   [@mgiannopoulos24](https://github.com/mgiannopoulos24), [@jeffpaul](https://github.com/jeffpaul),
   [@thrijith](https://github.com/thrijith), [@peterwilsoncc](https://github.com/peterwilsoncc),
   [@dkotter](https://github.com/dkotter), [@pbiron](https://github.com/pbiron) 
   via [#315](https://github.com/10up/safe-svg/pull/315)).
 * **Added:** New `safe_svg_inline_use_shadow_dom` filter to control which inline
   SVGs are isolated in a shadow root, and new `safe_svg_inline_shadow_styles` filter
   to adjust the CSS injected alongside them (props [@darylldoyle](https://github.com/darylldoyle),
   [@dkotter](https://github.com/dkotter), [@jeffpaul](https://github.com/jeffpaul),
   [@peterwilsoncc](https://github.com/peterwilsoncc) via [#328](https://github.com/10up/safe-svg/pull/328)).
 * **Added:** New `safe_svg_remove_remote_references` filter to strip remote `url()`,`@
   import` and `image-set()` references, along with remote `href` targets, from 
   uploaded SVGs. Off by default, because legitimate SVGs reference remote fonts
   and images but use this filter to turn it on (props [@darylldoyle](https://github.com/darylldoyle),
   [@dkotter](https://github.com/dkotter), [@jeffpaul](https://github.com/jeffpaul),
   [@peterwilsoncc](https://github.com/peterwilsoncc) via [#328](https://github.com/10up/safe-svg/pull/328)).
 * **Added:** Added support for Enable Media Replace plugin (props [@gthayer](https://github.com/gthayer),
   [@jeffpaul](https://github.com/jeffpaul), [@peterwilsoncc](https://github.com/peterwilsoncc)
   via [#285](https://github.com/10up/safe-svg/pull/285)).
 * **Changed:** Bump WordPress minimum supported version to 6.9 (props [@zamanq](https://github.com/zamanq),
   [@peterwilsoncc](https://github.com/peterwilsoncc) via [#320](https://github.com/10up/safe-svg/pull/320)).
 * **Changed:** Bump “tested up to header” to indicate WordPress 7.1 support (props
   [@navi151](https://github.com/navi151), [@peterwilsoncc](https://github.com/peterwilsoncc),
   [@dkotter](https://github.com/dkotter), [@jeffpaul](https://github.com/jeffpaul),
   [@zamanq](https://github.com/zamanq) via [#290](https://github.com/10up/safe-svg/pull/290),
   [#311](https://github.com/10up/safe-svg/pull/311), [#320](https://github.com/10up/safe-svg/pull/320)).
 * **Changed:** Theme CSS can no longer target an inline SVG that carries its own`
   <style>` element, because stylesheets cannot reach into a shadow root. Style 
   those SVGs from within the SVG itself, or opt out with the `safe_svg_inline_use_shadow_dom`
   filter. Inherited properties, including `color`/`currentColor` and custom properties,
   still apply as before, and SVGs without a `<style>` element are unaffected (props
   [@darylldoyle](https://github.com/darylldoyle), [@dkotter](https://github.com/dkotter),
   [@jeffpaul](https://github.com/jeffpaul), [@peterwilsoncc](https://github.com/peterwilsoncc)
   via [#328](https://github.com/10up/safe-svg/pull/328)).
 * **Changed:** Updated blueprint file for WordPress.org live previews (props [@fellyph](https://github.com/fellyph),
   [@jeffpaul](https://github.com/jeffpaul), [@peterwilsoncc](https://github.com/peterwilsoncc)
   via [#287](https://github.com/10up/safe-svg/pull/287)).
 * **Changed:** Bump `svgo` from 3.2.0 to 3.3.5 (props [@dependabot[bot]](https://github.com/apps/dependabot),
   [@jeffpaul](https://github.com/jeffpaul), [@peterwilsoncc](https://github.com/peterwilsoncc),
   [@dependabot](https://github.com/dependabot) via [#309](https://github.com/10up/safe-svg/pull/309)).

#### 2.4.0 – 2025-09-22

 * **Added:** Ability to upload SVGs from more admin locations (props [@stormrockwell](https://github.com/stormrockwell),
   [@darylldoyle](https://github.com/darylldoyle), [@wpexplorer](https://github.com/wpexplorer),
   [@smerriman](https://github.com/smerriman), [@jeffpaul](https://github.com/jeffpaul),
   [@dkotter](https://github.com/dkotter) via [#279](https://github.com/10up/safe-svg/pull/279)).
 * **Changed:** Added `$attachment_id` argument to filters `safe_svg_use_width_height_attributes`
   and `safe_svg_dimensions` (props [@roborourke](https://github.com/roborourke),
   [@dkotter](https://github.com/dkotter) via [#278](https://github.com/10up/safe-svg/pull/278)).
 * **Fixed:** Inconsistent or incorrect data type for `$svg` argument in the filters`
   safe_svg_use_width_height_attributes` and `safe_svg_dimensions` (props [@roborourke](https://github.com/roborourke),
   [@dkotter](https://github.com/dkotter) via [#278](https://github.com/10up/safe-svg/pull/278)).

[View historical changelog details here](https://github.com/10up/safe-svg/blob/develop/CHANGELOG.md).

## Community plugin

This plugin is developed and supported by a community. [Contribute to this plugin](https://github.com/10up/safe-svg)

## Meta

 *  Version **2.5.1**
 *  Last updated **6 days ago**
 *  Active installations **1+ million**
 *  WordPress version ** 6.9 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Languages
 * [Belarusian](https://bel.wordpress.org/plugins/safe-svg/), [Catalan](https://ca.wordpress.org/plugins/safe-svg/),
   [Chinese (Taiwan)](https://tw.wordpress.org/plugins/safe-svg/), [Czech](https://cs.wordpress.org/plugins/safe-svg/),
   [Dutch](https://nl.wordpress.org/plugins/safe-svg/), [Dutch (Belgium)](https://nl-be.wordpress.org/plugins/safe-svg/),
   [English (Australia)](https://en-au.wordpress.org/plugins/safe-svg/), [English (Canada)](https://en-ca.wordpress.org/plugins/safe-svg/),
   [English (New Zealand)](https://en-nz.wordpress.org/plugins/safe-svg/), [English (UK)](https://en-gb.wordpress.org/plugins/safe-svg/),
   [English (US)](https://wordpress.org/plugins/safe-svg/), [French (France)](https://fr.wordpress.org/plugins/safe-svg/),
   [Galician](https://gl.wordpress.org/plugins/safe-svg/), [German](https://de.wordpress.org/plugins/safe-svg/),
   [Hungarian](https://hu.wordpress.org/plugins/safe-svg/), [Italian](https://it.wordpress.org/plugins/safe-svg/),
   [Japanese](https://ja.wordpress.org/plugins/safe-svg/), [Korean](https://ko.wordpress.org/plugins/safe-svg/),
   [Marathi](https://mr.wordpress.org/plugins/safe-svg/), [Persian](https://fa.wordpress.org/plugins/safe-svg/),
   [Polish](https://pl.wordpress.org/plugins/safe-svg/), [Portuguese (Portugal)](https://pt.wordpress.org/plugins/safe-svg/),
   [Russian](https://ru.wordpress.org/plugins/safe-svg/), [Serbian](https://sr.wordpress.org/plugins/safe-svg/),
   [Spanish (Chile)](https://cl.wordpress.org/plugins/safe-svg/), [Spanish (Colombia)](https://es-co.wordpress.org/plugins/safe-svg/),
   [Spanish (Ecuador)](https://es-ec.wordpress.org/plugins/safe-svg/), [Spanish (Mexico)](https://es-mx.wordpress.org/plugins/safe-svg/),
   [Spanish (Spain)](https://es.wordpress.org/plugins/safe-svg/), [Spanish (Venezuela)](https://ve.wordpress.org/plugins/safe-svg/),
   [Swedish](https://sv.wordpress.org/plugins/safe-svg/), [Turkish](https://tr.wordpress.org/plugins/safe-svg/),
   and [Ukrainian](https://uk.wordpress.org/plugins/safe-svg/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/safe-svg)
 * Tags
 * [media](https://bre.wordpress.org/plugins/tags/media/)[mime](https://bre.wordpress.org/plugins/tags/mime/)
   [security](https://bre.wordpress.org/plugins/tags/security/)[SVG](https://bre.wordpress.org/plugins/tags/svg/)
   [Vector](https://bre.wordpress.org/plugins/tags/vector/)
 *  [Advanced View](https://bre.wordpress.org/plugins/safe-svg/advanced/)

## Ratings

 4.9 out of 5 stars.

 *  [  71 5-star reviews     ](https://wordpress.org/support/plugin/safe-svg/reviews/?filter=5)
 *  [  7 4-star reviews     ](https://wordpress.org/support/plugin/safe-svg/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/safe-svg/reviews/?filter=3)
 *  [  1 2-star review     ](https://wordpress.org/support/plugin/safe-svg/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/safe-svg/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/safe-svg/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/safe-svg/reviews/)

## Contributors

 *   [ 10up ](https://profiles.wordpress.org/10up/)
 *   [ Daryll Doyle ](https://profiles.wordpress.org/enshrined/)
 *   [ Jeffrey Paul ](https://profiles.wordpress.org/jeffpaul/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/safe-svg/)