Popis
Safe SVG je nejlepší způsob, jak povolit nahrávání souborů SVG ve WordPressu!
Umožňuje vám povolit nahrávání souborů SVG a zároveň zajistit jejich očištění, aby se zabránilo zranitelnostem SVG/XML, které by mohly ohrozit váš web. Dále vám umožňuje zobrazit náhled nahraných souborů SVG v knihovně médií ve všech zobrazeních.
Aktuální funkce
- Očištěné soubory SVG – Nevytvářejte na svém webu WordPress bezpečnostní mezery tím, že povolíte nahrávání neočištěných souborů.
- Optimalizace SVGO – Při nahrání soubory SVG zpracovává nástroj SVGO, čímž vám ušetří místo. Tato funkce je ve výchozím nastavení vypnutá, lze ji však zapnout přidáním následujícího kódu:
add_filter( 'safe_svg_optimizer_enabled', '__return_true' ); - Zobrazení souborů SVG v knihovně médií – Už nemusíte hádat, který soubor SVG je ten správný – v knihovně médií WordPressu zpřístupníme náhledy souborů SVG.
- Vyberte, kdo může nahrávat soubory – Omezte nahrávání souborů SVG na určité uživatele vašeho webu WordPress nebo povolte nahrávání komukoli.
Původně se jednalo o ověření koncepce pro #24251.
Očištění SVG se provádí pomocí následujících knihoven: https://github.com/darylldoyle/svg-sanitizer.
Optimalizace SVG se provádí pomocí následujících knihoven: https://github.com/svg/svgo.
Technical: Upload Path Security
WordPress’s _wp_handle_upload( $file, $action ) function allows any $action value, which determines the filter hook name: {$action}_prefilter. Safe SVG hooks common actions like wp_handle_upload and wp_handle_sideload, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths.
Bloky
Tento plugin poskytuje 1 blok.
- Safe SVG Display the SVG icon
Instalace
Nainstalujte plugin prostřednictvím adresáře WordPressu, nebo si soubory stáhněte, rozbalte a nahrajte do adresáře /wp-content/plugins/
Nejčastější dotazy
-
Ano, to lze provést pomocí filtrů
svg_allowed_attributesasvg_allowed_tags.
Tyto filtry přijímají jeden argument, který musí být vrácen. Příklady najdete níže:add_filter( 'svg_allowed_attributes', function ( $attributes ) { // Do what you want here... // This should return an array so add your attributes to // to the $attributes array before returning it. E.G. $attributes[] = 'target'; // This would allow the target="" attribute. return $attributes; } ); add_filter( 'svg_allowed_tags', function ( $tags ) { // Do what you want here... // This should return an array so add your tags to // to the $tags array before returning it. E.G. $tags[] = 'use'; // This would allow the <use> element. return $tags; } ); -
Can my theme style an inline SVG?
-
Mostly, yes. The Inline SVG block renders an SVG that carries its own
<style>element inside a shadow root, because CSS inside an inline SVG is otherwise applied to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow root, so theme CSS such as.entry-content svg { fill: red; }will not apply to those SVGs.Inherited properties still cross the boundary, so setting
coloron an ancestor and usingcurrentColorinside the SVG works, as do CSS custom properties. SVGs that do not contain a<style>element are rendered without the shadow root and can be styled by theme stylesheets.To turn isolation off, at the cost of allowing an SVG’s CSS to affect the rest of the page:
add_filter( 'safe_svg_inline_use_shadow_dom', '__return_false' ); -
Why doesn’t Safe SVG globally enable SVG uploads?
-
Safe SVG only allows SVGs through upload paths it can actively sanitize. While most WordPress uploads use standard functions like
wp_handle_upload()(which Safe SVG hooks), plugins and themes can create custom upload paths by calling WordPress’s underlying_wp_handle_upload()function with arbitrary action parameters.Globally enabling the
image/svg+xmlMIME type would allow SVGs through all upload paths—including custom ones Safe SVG cannot intercept and sanitize. This would create security vulnerabilities where unsanitized SVGs containing malicious scripts could be uploaded.This is a deliberate design decision: Safe SVG prioritizes guaranteed sanitization over broad compatibility. SVGs are only allowed when we can ensure they’re safe.
-
Where do I report security bugs found in this plugin?
-
Please report security bugs found in the source code of the Safe SVG plugin through the Patchstack Vulnerability Disclosure Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.
Recenze
Autoři
Safe SVG je otevřený software. Následující lidé přispěli k vývoji tohoto pluginu.
SpolupracovníciPlugin „Safe SVG“ byl přeložen do 32 jazyků. Děkujeme všem překladatelům za jejich pomoc.
Přeložte “Safe SVG” do svého jazyka.
Zajímá vás vývoj?
Prohledejte kód, podívejte se do SVN repozitáře, nebo se přihlaste k odběru protokolu vývoje pomocí RSS.
Přehled změn
2.5.1 – 2026-09-22
- Added: New REST endpoint,
/safe-svg/v1/svg/ATTACHMENT-ID, that can be passed an attachment ID for an SVG and will return sanitized markup (props @dkotter, @peterwilsoncc via GHSA-3hhm-5qc9-q4xf). - Removed: Remove the
$sanitizerproperty from thesafe_svgclass. If you directly use thesafe_svgclass in order to access the$sanitizerproperty, you’ll need to update your code to instead use the newSvg_Sanitizerclass (props @dkotter, @peterwilsoncc via GHSA-3hhm-5qc9-q4xf). - Security: Resolve GHSA-qq4c-2xh7-x2wf (props @dhakalananda, @dkotter, @peterwilsoncc, @darylldoyle, @jeffpaul via GHSA-qq4c-2xh7-x2wf).
- Security: Resolve GHSA-vcfp-vw5v-gc9c (props @spectreDeveloper, @dkotter, @peterwilsoncc, @darylldoyle, @jeffpaul via GHSA-vcfp-vw5v-gc9c).
- Security: Resolve GHSA-3hhm-5qc9-q4xf (props @dkotter, @peterwilsoncc via GHSA-3hhm-5qc9-q4xf).
2.5.0 – 2026-09-07
- Security: Prevented direct access of PHP files (props @mehrazmorshed, @dkotter via #300).
- Security: The Inline SVG block now renders SVGs that carry their own
<style>element inside a shadow root, so their CSS is scoped to the block instead of applying to the whole page (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Security: Bump
enshrined/svg-sanitizefrom^0.22.0to^1.0.0to pull in security fixes (props @dkotter, @jeffpaul, @peterwilsoncc via #327). - Added: Link support for the SVG Inline block, including URL input, new tab toggle, and nofollow/sponsored rel options (props @vegetable-bits, @mgiannopoulos24, @jeffpaul, @thrijith, @peterwilsoncc, @dkotter, @pbiron via #315).
- Added: New
safe_svg_inline_use_shadow_domfilter to control which inline SVGs are isolated in a shadow root, and newsafe_svg_inline_shadow_stylesfilter to adjust the CSS injected alongside them (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Added: New
safe_svg_remove_remote_referencesfilter to strip remoteurl(),@importandimage-set()references, along with remotehreftargets, from uploaded SVGs. Off by default, because legitimate SVGs reference remote fonts and images but use this filter to turn it on (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Added: Added support for Enable Media Replace plugin (props @gthayer, @jeffpaul, @peterwilsoncc via #285).
- Changed: Bump WordPress minimum supported version to 6.9 (props @zamanq, @peterwilsoncc via #320).
- Changed: Bump „tested up to header“ to indicate WordPress 7.1 support (props @navi151, @peterwilsoncc, @dkotter, @jeffpaul, @zamanq via #290, #311, #320).
- Changed: Theme CSS can no longer target an inline SVG that carries its own
<style>element, because stylesheets cannot reach into a shadow root. Style those SVGs from within the SVG itself, or opt out with thesafe_svg_inline_use_shadow_domfilter. Inherited properties, includingcolor/currentColorand custom properties, still apply as before, and SVGs without a<style>element are unaffected (props @darylldoyle, @dkotter, @jeffpaul, @peterwilsoncc via #328). - Changed: Updated blueprint file for WordPress.org live previews (props @fellyph, @jeffpaul, @peterwilsoncc via #287).
- Changed: Bump
svgofrom 3.2.0 to 3.3.5 (props @dependabot[bot], @jeffpaul, @peterwilsoncc, @dependabot via #309).
2.4.0 – 22. září 2025
- Přidáno: Možnost nahrávat soubory SVG z více míst v administraci (díky @stormrockwell, @darylldoyle, @wpexplorer, @smerriman, @jeffpaul, @dkotter prostřednictvím #279).
- Změna: Do filtrů
safe_svg_use_width_height_attributesasafe_svg_dimensionsbyl přidán argument$attachment_id< (poděkování @roborourke, @dkotter prostřednictvím #278). - Opraveno: Nesouladný nebo nesprávný datový typ argumentu
$svgve filtrechsafe_svg_use_width_height_attributesasafe_svg_dimensions(poděkování @roborourke, @dkotter prostřednictvím #278).
Podrobnosti o historických změnách si můžete prohlédnout zde.
