SVG
An src is treated as SVG when its path ends in .svg (for a URL — the path part, without the query string).
Passthrough (default)
Section titled “Passthrough (default)”SVG is not transformed. It is sanitized (when enabled), stored once and served as image/svg+xml:
imagepreset_url('icons/logo.svg');w,h,q,fit,fmand the other parameters are validated as usual but not applied.- The cache file name is the MD5 of
srconly, so every parameter combination for one SVG shares one file. - The response always has the long-lived
Cache-Control(neverno-store) andContent-Security-Policy: default-src 'none'; style-src 'unsafe-inline'; sandbox, so scripts can’t run even when the file is opened directly.
Sanitization
Section titled “Sanitization”'svg' => [ 'sanitize' => true, 'remove_remote_references' => true, 'rasterize' => false,],With enshrined/svg-sanitize installed the full sanitizer is used:
composer require enshrined/svg-sanitizeremove_remote_references is passed to it. If it rejects the file, the request returns 404.
Without the package a basic regex filter removes <script> blocks, on* event attributes and javascript: URIs. It doesn’t handle remote references or less common vectors — install the sanitizer if SVGs come from users or remote hosts.
sanitize => false stores the file as is — only for trusted sources.
Rasterization
Section titled “Rasterization”'svg' => [ 'rasterize' => true,],SVG is converted to a raster image by Glide when all of these hold:
svg.rasterizeistrue;driverisimagick(with GD the SVG is passed through);- the request (after a preset is applied) has
w,horfm.
The result follows the normal raster rules: fm defaults to format, allowlists apply, the cache key is the query string. Sanitization is not applied on this path — Imagick reads the original file.