What the SVG policy actually blocks
Plathix offers one SVG policy for the whole site: clean on upload, block outright, or stay out of the way. This test uploads real SVG files — ordinary ones and hostile ones — against each policy, each allowed-role setting, and strict safe mode, and records exactly what got through.
The claim we are testing
“Choose whether Plathix cleans SVG uploads, blocks them, or leaves SVG handling to another tool. You can also choose which WordPress roles may upload SVG files.”
Why this is worth testing
SVG is XML, and XML can carry script. A plugin that says it sanitises has to be judged on what it rejects, not on the fact that it has a sanitiser. "Block site-wide" carries a second promise worth checking: that it also overrides SVG another plugin allowed.
What we check
- Policy "clean on upload": an ordinary SVG uploads and renders.
- Policy "clean on upload": a file carrying script is rejected, not silently stripped and accepted.
- Policy "block": SVG upload fails, including when another plugin has allowed the type.
- Policy "leave it to another tool": Plathix does not touch the upload either way.
- A role outside the allowed list cannot upload SVG even with WordPress upload rights.
- Strict safe mode: a file whose <use> or <image> points at an external resource is rejected.
Test in progress
The scope above is fixed, the run has not happened yet. When it does, this page gets the setup we used, a recording of each check, the numbers, and anything that did not work — including the parts that went against us.
We publish the result either way. That is the point of Lab.
Related
Test it on your own site
Plathix Free installs in a minute and deactivates cleanly. Your library is the only benchmark that counts.