外掛說明
使用 Safe SVG 外掛是在 WordPress 網站上開放 SVG 檔案上傳的最佳方式。
這個外掛能開放 WordPress 網站上傳 SVG 檔案的功能,並確保 SVG 檔案經過必要的處理,以避免觸發 SVG/XML 漏洞影響網站,同時也能讓使用者在媒體庫的各種檢視模式中預覽已上傳的 SVG 檔案。
目前功能
- 處理 SVG 檔案:不會允許未經處理的 SVG 檔案上傳,以避免觸發 WordPress 網站的安全性漏洞。
- SVGO 最佳化:在上傳 SVG 檔案時使用 SVGO 工具最佳化以節省網站儲存空間。這項功能預設為停用,但可以使用所列程式碼加以啟用:
add_filter( 'safe_svg_optimizer_enabled', '__return_true' ); - 在媒體庫中檢視 SVG 檔案:不需要去回想哪個 SVG 檔案是哪天上傳的,這個外掛提供在 WordPress 媒體庫中預覽 SVG 檔案的功能。
- 設定可上傳 SVG 檔案的使用者:設定指定使用者才能上傳 SVG 檔案,或開放全部使用者均可上傳。
開發這個外掛的想法源自 #24251 這個功能需求。
SVG 檔案的處理使用 https://github.com/darylldoyle/svg-sanitizer 所提供的函式庫。
已透過所列函式庫完成 SVG 最佳化功能:https://github.com/svg/svgo。
Technical: Upload Path Security
WordPress’s _wp_handle_upload( $file, $action ) function allows any $action value, which determines the filter hook name: {$action}_prefilter. Safe SVG hooks common actions like wp_handle_upload and wp_handle_sideload, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths.
適用於區塊編輯器
這個外掛提供 1 個可供區塊編輯器使用的區塊。
- Safe SVG Display the SVG icon
安裝方式
透過 WordPress 外掛目錄安裝,或下載安裝檔案後解壓縮,上傳解壓縮所得的資料夾及其全部檔案至 /wp-content/plugins/ 目錄。
常見問題集
-
可以,這可以透過
svg_allowed_attributes及svg_allowed_tags篩選器完成。
這 2 個篩選器分別使用一個必須回傳值的引數。以下是範例程式碼:add_filter( 'svg_allowed_attributes', function ( $attributes ) { // Do what you want here... // This should return an array so add your attributes to // to the $attributes array before returning it. E.G. $attributes[] = 'target'; // This would allow the target="" attribute. return $attributes; } ); add_filter( 'svg_allowed_tags', function ( $tags ) { // Do what you want here... // This should return an array so add your tags to // to the $tags array before returning it. E.G. $tags[] = 'use'; // This would allow the <use> element. return $tags; } ); -
Can my theme style an inline SVG?
-
Mostly, yes. The Inline SVG block renders an SVG that carries its own
<style>element inside a shadow root, because CSS inside an inline SVG is otherwise applied to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow root, so theme CSS such as.entry-content svg { fill: red; }will not apply to those SVGs.Inherited properties still cross the boundary, so setting
coloron an ancestor and usingcurrentColorinside the SVG works, as do CSS custom properties. SVGs that do not contain a<style>element are rendered without the shadow root and can be styled by theme stylesheets.To turn isolation off, at the cost of allowing an SVG’s CSS to affect the rest of the page:
add_filter( 'safe_svg_inline_use_shadow_dom', '__return_false' ); -
Why doesn’t Safe SVG globally enable SVG uploads?
-
Safe SVG only allows SVGs through upload paths it can actively sanitize. While most WordPress uploads use standard functions like
wp_handle_upload()(which Safe SVG hooks), plugins and themes can create custom upload paths by calling WordPress’s underlying_wp_handle_upload()function with arbitrary action parameters.Globally enabling the
image/svg+xmlMIME type would allow SVGs through all upload paths—including custom ones Safe SVG cannot intercept and sanitize. This would create security vulnerabilities where unsanitized SVGs containing malicious scripts could be uploaded.This is a deliberate design decision: Safe SVG prioritizes guaranteed sanitization over broad compatibility. SVGs are only allowed when we can ensure they’re safe.
-
Where do I report security bugs found in this plugin?
-
Please report security bugs found in the source code of the Safe SVG plugin through the Patchstack Vulnerability Disclosure Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.
使用者評論
參與者及開發者
變更記錄
2.5.0 – 2026-09-07
- Security: Prevented direct access of PHP files (props @mehrazmorshed, @dkotter via #300).
- Security: The Inline SVG block now renders SVGs that carry their own
<style>element inside a shadow root, so their CSS is scoped to the block instead of applying to the whole page (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Security: Bump
enshrined/svg-sanitizefrom^0.22.0to^1.0.0to pull in security fixes (props @dkotter, @jeffpaul, @peterwilsoncc via #327). - Added: Link support for the SVG Inline block, including URL input, new tab toggle, and nofollow/sponsored rel options (props @vegetable-bits, @mgiannopoulos24, @jeffpaul, @thrijith, @peterwilsoncc, @dkotter, @pbiron via #315).
- Added: New
safe_svg_inline_use_shadow_domfilter to control which inline SVGs are isolated in a shadow root, and newsafe_svg_inline_shadow_stylesfilter to adjust the CSS injected alongside them (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Added: New
safe_svg_remove_remote_referencesfilter to strip remoteurl(),@importandimage-set()references, along with remotehreftargets, from uploaded SVGs. Off by default, because legitimate SVGs reference remote fonts and images but use this filter to turn it on (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Added: Added support for Enable Media Replace plugin (props @gthayer, @jeffpaul, @peterwilsoncc via #285).
- Changed: Bump WordPress minimum supported version to 6.9 (props @zamanq, @peterwilsoncc via #320).
- Changed: Bump “tested up to header” to indicate WordPress 7.1 support (props @navi151, @peterwilsoncc, @dkotter, @jeffpaul, @zamanq via #290, #311, #320).
- Changed: Theme CSS can no longer target an inline SVG that carries its own
<style>element, because stylesheets cannot reach into a shadow root. Style those SVGs from within the SVG itself, or opt out with thesafe_svg_inline_use_shadow_domfilter. Inherited properties, includingcolor/currentColorand custom properties, still apply as before, and SVGs without a<style>element are unaffected (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Changed: Updated blueprint file for WordPress.org live previews (props @fellyph, @jeffpaul, @peterwilsoncc via #287).
- Changed: Bump
svgofrom 3.2.0 to 3.3.5 (props @dependabot[bot], @jeffpaul, @peterwilsoncc, @dependabot via #309).
2.4.0 – 2025-09-22
- Added: Ability to upload SVGs from more admin locations (props @stormrockwell, @darylldoyle, @wpexplorer, @smerriman, @jeffpaul, @dkotter via #279).
- Changed: Added
$attachment_idargument to filterssafe_svg_use_width_height_attributesandsafe_svg_dimensions(props @roborourke, @dkotter via #278). - Fixed: Inconsistent or incorrect data type for
$svgargument in the filterssafe_svg_use_width_height_attributesandsafe_svg_dimensions(props @roborourke, @dkotter via #278).
2.3.3 – 2025-08-13
- Security: Update the
enshrined/svg-sanitizepackage from0.19.0to0.22.0to fix an issue with case-insensitive attributes slipping through the sanitiser and address PHP 8.4 deprecation warnings (props @darylldoyle, @sudar, @georgestephanis, @dkotter, @realazizk via #268, #272). - Security: Bump
form-datafrom 4.0.0 to 4.0.4 (props @dependabot, @faisal-alvi via #270). - Security: Bump
tmpfrom 0.2.3 to 0.2.5 and@inquirer/editorfrom 4.2.9 to 4.2.16 (props @dependabot, @dkotter via #271).
2.3.2 – 2025-07-21
- Fixed: Visual parity between the front end and the block editor (props @s3rgiosan, @dkotter via #261, #266).
- Changed: Bump WordPress “tested up to” version 6.8 (props @godleman, @jeffpaul, @dkotter via #251, #254).
- Changed: Bump WordPress minimum supported version to 6.6 (props @godleman, @jeffpaul, @dkotter via #254).
- Security: Bump
wsfrom 7.5.10 to 8.18.0,@wordpress/scriptsfrom 27.9.0 to 30.6.0,nanoidfrom 3.3.7 to 3.3.8 andmochafrom 10.2.0 to 11.0.1 (props @dependabot, @peterwilsoncc via #245). - Security: Bump
@babel/runtimefrom 7.23.9 to 7.27.0,axiosfrom 1.7.4 to 1.8.4,cookiefrom 0.4.2 to 0.7.1,expressfrom 4.21.0 to 4.21.2 and@wordpress/e2e-test-utils-playwrightfrom 0.26.0 to 1.20.0 (props @dependabot, @dkotter via #250). - Security: Bump
http-proxy-middlewarefrom 2.0.6 to 2.0.9 (props @dependabot, @iamdharmesh via #253). - Security: Bump
tar-fsfrom 3.0.8 to 3.0.9 (props @dependabot, @dkotter via #258). - Security: Bump
bytesfrom 3.0.0 to 3.1.2 andcompressionfrom 1.7.4 to 1.8.1 (props @dependabot, @dkotter via #265).
2.3.1 – 2024-12-05
- Fixed: Revert changes made to how we determine custom dimensions for SVGs (props @dkotter, @martinpl, @subfighter3, @smerriman, @gigatyrant, @jeffpaul, @iamdharmesh via #238).
2.3.0 – 2024-11-25
- Added: New setting that allows large SVG files (roughly 10MB or greater) to be uploaded and sanitized properly (props @kirtangajjar, @faisal-alvi, @darylldoyle, @manojsiddoji, @dkotter via #201).
- Added: New
get_svg_dimensionsfunction in order to reduce code duplication (props @gabriel-glo, @jeremymoore, @darylldoyle, @iamdharmesh, @dkotter via #216). - Changed: Updated the
enshrined/svg-sanitizepackage from 0.16.0 to 0.19.0 to fix a PHP 8.3 compatibility issue (props @sksaju, @TylerB24890, @darylldoyle, @rolf-yoast, @faisal-alvi via #214). - Changed: Update how image dimensions are passed in
get_image_tag_overrideandone_pixel_fixmethods (props @gabriel-glo, @jeremymoore, @darylldoyle, @iamdharmesh, @dkotter via #216). - Changed: Bump WordPress “tested up to” version to 6.7 (props @colinswinney, @jeffpaul via #232, #233).
- Changed: Bump WordPress minimum from 6.4 to 6.5 (props @colinswinney, @jeffpaul via #232, #233).
- Changed: Remove composer dev dependencies from archived project (props @TylerB24890, @szepeviktor, @peterwilsoncc via #220).
- Fixed: Use proper block category for the Safe SVG Icon block (props @kirtangajjar, @fabiankaegy via #226).
- Security: Only allow SVG file types to be uploaded if our sanitizer is able to run on those files (props @darylldoyle, @xknown, @dkotter via #228).
- Security: Bump
webpackfrom 5.90.1 to 5.94.0 (props @dependabot, @peterwilsoncc via #222). - Security: Bump
wsfrom 7.5.10 to 8.18.0,serve-staticfrom 1.15.0 to 1.16.2 andexpressfrom 4.19.2 to 4.21.0 (props @dependabot, @Sidsector9, @faisal-alvi via #227, #230, #234).
2.2.6 – 2024-08-28
- Changed: Bump WordPress “tested up to” version to 6.6 (props @sudip-md, @ankitguptaindia, @jeffpaul via #212, #213).
- Changed: Bump WordPress minimum from 5.7 to 6.4 (props @sudip-md, @ankitguptaindia, @jeffpaul via #212, #213).
- Security: Add svg sanitization on the
wp_handle_sideload_prefilterfilter (props @dkotter, @xknown, @iamdharmesh via GHSA-3vr7-86pg-hf4g). - Security: Bump
bracesfrom 3.0.2 to 3.0.3,pac-resolverfrom 7.0.0 to 7.0.1,socksfrom 2.7.1 to 2.8.3,wsfrom 7.5.9 to 7.5.10 and removeip(props @dependabot, @Sidsector9 via #206). - Security: Bump
axiosfrom 1.6.7 to 1.7.4 (props @dependabot, @faisal-alvi via #218).
