Plathix Lab / What the SVG policy actually blocks
Test in progress Security test

What the SVG policy actually blocks

Plathix offers one SVG policy for the whole site: clean on upload, block outright, or stay out of the way. This test uploads real SVG files — ordinary ones and hostile ones — against each policy, each allowed-role setting, and strict safe mode, and records exactly what got through.

The claim we are testing

“Choose whether Plathix cleans SVG uploads, blocks them, or leaves SVG handling to another tool. You can also choose which WordPress roles may upload SVG files.”

— Settings feature page

Why this is worth testing

SVG is XML, and XML can carry script. A plugin that says it sanitises has to be judged on what it rejects, not on the fact that it has a sanitiser. "Block site-wide" carries a second promise worth checking: that it also overrides SVG another plugin allowed.

What we check

Test in progress

The scope above is fixed, the run has not happened yet. When it does, this page gets the setup we used, a recording of each check, the numbers, and anything that did not work — including the parts that went against us.

We publish the result either way. That is the point of Lab.

Related

SVG controls Settings feature page

← All Plathix Lab tests

Test it on your own site

Plathix Free installs in a minute and deactivates cleanly. Your library is the only benchmark that counts.

Try Plathix Free All Lab tests