| 开发者 | gobbert |
|---|---|
| 更新时间 | 2026年8月10日 20:09 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/wp-content/plugins/ or install it from the Plugins screen.An SVG is XML markup, not a raster picture. XML can contain a script tag, an event handler, or a link that runs when the file is opened. A PNG cannot. WordPress blocks the format rather than trust every uploaded file. This plugin unblocks it and removes that risk by sanitizing each file.
It does not use pattern matching or find and replace on the text, which is easy to trick with obfuscated markup. It parses the file into a document, walks the tree, and rebuilds a fresh file from a strict allow list of safe tags. Anything not on the list is dropped, and the rebuilt file is scanned once more before it is accepted. Document type declarations and entity definitions are refused outright, which rules out entity expansion attacks.
For a normal design file, no. Sanitizing removes things that should not be in a display graphic anyway and keeps every shape, path, gradient, colour and text element. If a file relied on a script to draw itself, that part is removed by design.
Yes. Drop a logo, icon or flat drawing into the studio and it traces the image into an editable vector, then saves it to your media library. Logos, icons and flat art trace best. A detailed photograph will not become a clean vector.
No. Tracing and editing run in your browser, and the finished file is saved to your own media library.
It places the actual SVG markup on the page instead of wrapping the file in an image tag. That is what lets your CSS recolour the graphic, scale it at any size, and animate shapes inside it.
Whichever editor you use. There is an Inline SVG block in the block editor, an Inline SVG widget in Elementor, and an Inline SVG element in WPBakery. For classic themes and anything else there is the shortcode [gobbert_svg id="123"], where 123 is the attachment ID. All of them accept a motion value of off, drift, breathe or sheen, plus an optional width and CSS class, and all of them output the same standard inline SVG.
Under Settings, Gobbert. Every Gobbert plugin adds its own panel to that one screen rather than a menu of its own, so a site running several of them still has a single place to look. The studio itself is under Media, SVG Studio.
No. This plugin sanitizes every upload and lets you restrict which roles can upload. Running it alongside another SVG uploader is redundant and can cause both to handle the same upload, so pick one.
The current release of WordPress 7.0. The Tested up to header above gives the major version only, which is what the directory expects. It also runs on anything from 6.0 upwards.
No. It places only what you place yourself, through the block, the element or the shortcode.
No. It makes no requests to any other server, at any time. There is no account, no key, no sign-up and no tracking. Sanitizing happens on your own server; tracing and editing happen in your own browser. Removing a photographic background is the one job the studio cannot do on its own, so when it would help, the studio offers a link to a free tool on gobbert.com that does it. It is an ordinary link you choose to click, in a new tab. Nothing is sent unless you go there and upload something yourself.
In your own WordPress database, like any other plugin's. The only setting this plugin stores is which roles may upload SVG files, and deleting the plugin removes it.
Tracing is done by VTracer, an open source engine from VisionCortex, compiled to WebAssembly so it runs in your browser rather than on a server. It is included under the MIT or Apache 2.0 licence, at assets/vendor/, together with its licence text and a note describing where the binary comes from and how to rebuild it from source. The Rust source is at https://github.com/visioncortex/vtracer and the published package is https://www.npmjs.com/package/@visioncortex/vtracer.
None of this plugin's own JavaScript is minified or compiled. Every file it ships is the readable source.