SVG ایمن

توضیحات

افزونه امنیت vsg بهترین روش برای اجازه آپلود فایل vsg در وردپرس است!

این امکان را به شما می دهد تا آپلودهای SVG را مجاز کنید و در عین حال مطمئن شوید که برای جلوگیری از آسیب پذیری های SVG/XML که سایت شما را تحت تأثیر قرار می دهند، ضد عفونی شده اند.
همچنین به شما این امکان را می دهد که SVG های آپلود شده خود را در کتابخانه رسانه در همه نماها پیش نمایش کنید.

ویژگی های فعلی

  • Sanitised SVGs – Don’t open up security holes in your WordPress site by allowing uploads of unsanitised files.
  • SVGO Optimisation – Runs your SVGs through the SVGO tool on upload to save you space. This feature is disabled by default but can be enabled by adding the following code: add_filter( 'safe_svg_optimizer_enabled', '__return_true' );
  • مشاهده SVG در کتابخانه رسانه – زمان حدس زدن اینکه کدام SVG درست است گذشته است، پیش‌نمایش SVG را در کتابخانه رسانه وردپرس فعال می‌کنیم.
  • انتخاب چه کسی می‌تواند آپلود کند – آپلودهای SVG را به کاربران خاصی در سایت وردپرس خود محدود کنید یا به هر کسی اجازه آپلود دهید.

در ابتدا یک اثبات مفهوم برای #24251

پاکسازی SVG از طریق کتابخانه زیر انجام می‌شود: https://github.com/darylldoyle/svg-sanitizer

SVG Optimization is done through the following library: https://github.com/svg/svgo.

Technical: Upload Path Security

WordPress’s _wp_handle_upload( $file, $action ) function allows any $action value, which determines the filter hook name: {$action}_prefilter. Safe SVG hooks common actions like wp_handle_upload and wp_handle_sideload, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths.

بلوک‌ها

این افزونه 1 بلوک ارائه می‌دهد.

  • Safe SVG Display the SVG icon

نصب

از طریق دایرکتوری وردپرس نصب کنید یا فایل ها را از حالت فشرده خارج کنید و در فهرست /wp-content/plugins/ خود آپلود کنید.

سوالات متداول

آیا می توانیم ویژگی ها و برچسب های مجاز را تغییر دهیم؟

بله، این کار را می توان با استفاده از فیلترهای svg_allowed_attributes و svg_allowed_tags انجام داد.
آنها یک آرگومان می گیرند که باید برگردانده شود. برای نمونه به زیر مراجعه کنید:

add_filter( 'svg_allowed_attributes', function ( $attributes ) {

    // Do what you want here...

    // This should return an array so add your attributes to
    // to the $attributes array before returning it. E.G.

    $attributes[] = 'target'; // This would allow the target="" attribute.

    return $attributes;
} );


add_filter( 'svg_allowed_tags', function ( $tags ) {

    // Do what you want here...

    // This should return an array so add your tags to
    // to the $tags array before returning it. E.G.

    $tags[] = 'use'; // This would allow the <use> element.

    return $tags;
} );

Can my theme style an inline SVG?

Mostly, yes. The Inline SVG block renders an SVG that carries its own <style> element inside a shadow root, because CSS inside an inline SVG is otherwise applied to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow root, so theme CSS such as .entry-content svg { fill: red; } will not apply to those SVGs.

Inherited properties still cross the boundary, so setting color on an ancestor and using currentColor inside the SVG works, as do CSS custom properties. SVGs that do not contain a <style> element are rendered without the shadow root and can be styled by theme stylesheets.

To turn isolation off, at the cost of allowing an SVG’s CSS to affect the rest of the page:

add_filter( 'safe_svg_inline_use_shadow_dom', '__return_false' );

Why doesn’t Safe SVG globally enable SVG uploads?

Safe SVG only allows SVGs through upload paths it can actively sanitize. While most WordPress uploads use standard functions like wp_handle_upload() (which Safe SVG hooks), plugins and themes can create custom upload paths by calling WordPress’s underlying _wp_handle_upload() function with arbitrary action parameters.

Globally enabling the image/svg+xml MIME type would allow SVGs through all upload paths—including custom ones Safe SVG cannot intercept and sanitize. This would create security vulnerabilities where unsanitized SVGs containing malicious scripts could be uploaded.

This is a deliberate design decision: Safe SVG prioritizes guaranteed sanitization over broad compatibility. SVGs are only allowed when we can ensure they’re safe.

Where do I report security bugs found in this plugin?

Please report security bugs found in the source code of the Safe SVG plugin through the Patchstack Vulnerability Disclosure  Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.

نقد و بررسی‌ها

6 آگوست 2026 1 پاسخ
Must use plugin, well maintained, installing almost every time and just now I've realized, that I didn't review it. Keep it up and thanks!
11 مارس 2026 1 پاسخ
Needed SVG upload support, and this plugin did the job. Very lightweight and easy to use. No issues so far. Some additional settings would be nice, but overall, it's quite solid.
21 ژوئن 2025 1 پاسخ
Would have given a 5 star, but it seems support is missing for the taxonomy / terms section (like in categories) upload for SVG images. Keep getting an error that the upload isn't supported. Hopefully this will be fixed in a future update. Will update once this is added. Cheers!
30 آوریل 2025 1 پاسخ
Great plugin! very usefull, but please can you add the possibility to add an inline SVG on the block pasting svg code? Thanks!
خواندن تمامی 79 نقد و بررسی‌

توسعه دهندگان و همکاران

“SVG ایمن” نرم افزار متن باز است. افراد زیر در این افزونه مشارکت کرده‌اند.

مشارکت کنندگان

“SVG ایمن” به 32 زبان ترجمه شده است. با تشکر از مترجمین برای همکاری و کمک‌هایشان.

ترجمه “SVG ایمن” به زبان شما.

علاقه‌ مند به توسعه هستید؟

کد را مرور کنید، مخزن SVN را بررسی کنید، یا از طریق RSS در گزارش توسعه مشترک شوید.

گزارش تغییرات

2.5.1 – 2026-09-22

2.5.0 – 2026-09-07

2.4.0 – 2025-09-22

View historical changelog details here.