Image conversion plugins process uploaded files, write derivatives, update rewrite rules, and may invoke local or remote converters. WebP Express version 0.25.15 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64689, confirming that the review focused on file access, conversion inputs, generated output paths, rewrite behavior, converter configuration, and protection of privileged settings.
| Name of | WebP Express |
| Version | 0.25.15 |
| Active installations | 300,000+ |
| Description | Converts JPEG and PNG images to WebP through local or cloud conversion methods and serves suitable images to compatible browsers. |
| Security | Successfully tested for: SQL Injection (SQLi) Cross-Site Scripting (XSS) – Stored and Reflected Cross-Site Request Forgery (CSRF) Authentication Vulnerabilities Authentication Bypass Exploits Privilege Escalation Buffer Overflow Denial-of-Service (DoS) vectors Data Leakage Vulnerabilities Insecure Dependency Usage Remote Code Execution (RCE) Risks Unauthorized File Access Insufficient Injection Protection Information Disclosure via Misconfigured Endpoints |
| CleanTalk Certification | Proudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards. |
| Additional Information | Use WebP Express with confidence backed by the “Plugin Security Certification” (PSC). Choose conversion methods appropriate for the host, restrict remote converter settings, protect generated files, and verify rewrite rules after server changes. |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Key Features
WebP Express creates WebP alternatives for JPEG and PNG images and serves them to compatible browsers while retaining original formats for other clients. It supports local converters such as Imagick, cwebp, Vips, and GD, along with optional remote conversion methods. Depending on configuration, the plugin can generate images on demand and alter server or HTML delivery behavior.
Security Assurance
The CleanTalk Plugin Security Certification evaluation focused on validation of source images, confinement of generated output paths, authorization for settings, and safe interaction with local or remote converters. The review also considered rewrite rules, on-demand conversion, configuration exposure, file deletion hooks, output integrity, and protection against unauthorized file access.
The plugin has been successfully tested for:
✅ Information Leakage Vulnerabilities
✅ SQL Injection Vulnerabilities
✅ Cross-Site Scripting (XSS) Attacks
✅ Cross-Site Request Forgery (CSRF) Attacks
✅ Authentication and Authentication Bypass Vulnerabilities
✅ Privilege Escalation Vulnerabilities
✅ Buffer Overflow Vulnerabilities
✅ Denial-of-Service (DoS) Vulnerabilities
✅ Data Leakage Vulnerabilities
✅ Insecure Dependencies
✅ Code Execution Vulnerabilities
✅ File Unauthorized Access Vulnerabilities
✅ Insufficient Injection Protection
Conclusion
With PSC-2026-64689, WebP Express version 0.25.15 demonstrates strong baseline security for WebP generation and delivery workflows. The certification addresses conversion inputs, generated files, rewrite behavior, local and remote converter settings, and privileged configuration. Site owners should keep converter components current, verify directory protections, and retest delivery after changes to the web server, CDN, or image storage layout.
Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.
