Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.

Name ofWebP Express
Version0.25.15
Active installations300,000+
DescriptionConverts JPEG and PNG images to WebP through local or cloud conversion methods and serves suitable images to compatible browsers.
SecuritySuccessfully tested for:
SQL Injection (SQLi)
Cross-Site Scripting (XSS) – Stored and Reflected
Cross-Site Request Forgery (CSRF)
Authentication Vulnerabilities
Authentication Bypass Exploits
Privilege Escalation
Buffer Overflow
Denial-of-Service (DoS) vectors
Data Leakage Vulnerabilities
Insecure Dependency Usage
Remote Code Execution (RCE) Risks
Unauthorized File Access
Insufficient Injection Protection
Information Disclosure via Misconfigured Endpoints
CleanTalk CertificationProudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards.
Additional InformationUse WebP Express with confidence backed by the “Plugin Security Certification” (PSC). Choose conversion methods appropriate for the host, restrict remote converter settings, protect generated files, and verify rewrite rules after server changes.
Plugin Security Certification by CleanTalk
Logo of the plugin

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Key Features

WebP Express creates WebP alternatives for JPEG and PNG images and serves them to compatible browsers while retaining original formats for other clients. It supports local converters such as Imagick, cwebp, Vips, and GD, along with optional remote conversion methods. Depending on configuration, the plugin can generate images on demand and alter server or HTML delivery behavior.

Security Assurance

The CleanTalk Plugin Security Certification evaluation focused on validation of source images, confinement of generated output paths, authorization for settings, and safe interaction with local or remote converters. The review also considered rewrite rules, on-demand conversion, configuration exposure, file deletion hooks, output integrity, and protection against unauthorized file access.

The plugin has been successfully tested for:

✅ Information Leakage Vulnerabilities

✅ SQL Injection Vulnerabilities

✅ Cross-Site Scripting (XSS) Attacks

✅ Cross-Site Request Forgery (CSRF) Attacks

✅ Authentication and Authentication Bypass Vulnerabilities

✅ Privilege Escalation Vulnerabilities

✅ Buffer Overflow Vulnerabilities

✅ Denial-of-Service (DoS) Vulnerabilities

✅ Data Leakage Vulnerabilities

✅ Insecure Dependencies

✅ Code Execution Vulnerabilities

✅ File Unauthorized Access Vulnerabilities

✅ Insufficient Injection Protection

Conclusion

With PSC-2026-64689, WebP Express version 0.25.15 demonstrates strong baseline security for WebP generation and delivery workflows. The certification addresses conversion inputs, generated files, rewrite behavior, local and remote converter settings, and privileged configuration. Site owners should keep converter components current, verify directory protections, and retest delivery after changes to the web server, CDN, or image storage layout.

Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.

Plugin Security Certification (PSC-2026-64689): “WebP Express” – Version 0.25.15

Dmitrii I

Pentester with 5 years of hands-on experience securing WordPress and web applications, holding OSWE, OSEP, OSCP, and OSWP certifications. Author of 450 published CVEs, including 35 disclosed within the last month. Specializes in discovering and validating high-impact vulnerabilities in WordPress plugins/themes / Custom WEB applications and delivering actionable remediation guidance to harden production sites.

Visit Author's Website

See all posts by dmitrii-ignatyev

Leave a Reply

Your email address will not be published. Required fields are marked *