An SVG can look like a self-contained image while referencing external images, styles, fonts, or documents. Search its source for href and URL references, remove or package what is necessary, and reopen the approved copy without network access.
SVG → PNG
Treat SVG as a document, not only a picture
SVG is an XML-based document format. In addition to paths, shapes, and text, it can reference resources that are not stored in the file. SVG 2 identifies structurally external elements that use href, including image, use, script, iframe, audio, and video. CSS declarations can also use URL values or imported stylesheets to retrieve images, fonts, filters, and related material. A graphic that looks complete on the creator's computer may therefore depend on a local folder, a company server, or a public website that the recipient cannot access.
Actual behavior varies by browser, editor, security policy, network state, and cross-origin rules. One program may load a resource while another blocks it or substitutes nothing. A remote file may later change even though the SVG itself remains unchanged. Begin by defining the delivery requirement: editable artwork, a web asset, a print source, an archival record, or a view-only preview. Then determine whether external connections are expected, forbidden, or simply unreliable in the environment where the recipient will open the file.
- Handle SVG as XML with possible external references
- Consider images, documents, styles, fonts, and scripts
- Define whether the receiving environment permits network access
A resource that is visible now is not necessarily embedded in the SVG file.
Recognize privacy and reproducibility risks
If an SVG viewer requests an external resource, the remote service may receive the normal information associated with a web request, such as time, network address, and client details. The URL text itself may contain a project name, account identifier, internal hostname, temporary access token, or other information that should not leave the organization. Even if the request is blocked, that sensitive string can remain readable in the SVG source. A privacy review must therefore include the document text rather than only the pixels shown on screen.
External dependencies also weaken reproducibility. A reference to a creator's local drive, authenticated workspace, or private intranet may fail immediately for the recipient. A public asset can disappear or be replaced, causing an old SVG to render differently in the future. For contractual delivery or long-term storage, identify every required asset and its license, freeze an approved version, and confirm that the document can reproduce the intended appearance without relying on a changing network location. Record any reference that must intentionally remain external.
- Look for sensitive text inside URLs
- Remove creator-only local and intranet paths
- Check whether the artwork remains reproducible offline
Search the source systematically
Work on a copy and open it in a trusted text editor. Search for href, xlink:href, the CSS URL function, @import, http, https, file schemes, and relative paths. Inspect image and use elements as well as style blocks, inline style attributes, filter definitions, masks, and font declarations. Removing visible hyperlink text is not enough if the attribute value remains. Search case variations where appropriate and examine encoded or escaped values that an export tool may have generated. Keep the original unchanged while classifying each match.
Do not delete every match blindly because some references may be essential to rendering. Separate navigation links from images, fonts, styles, scripts, and unused editor metadata. Unknown active content should be inspected in an isolated environment rather than executed merely to discover its purpose. For a complex document, save a diff between the original and the sharing copy and note which resources were embedded, replaced, or removed. This record makes it possible to troubleshoot a missing element without reintroducing every external dependency.
- Search href, xlink:href, URL functions, and imports
- Check remote schemes, local paths, and relative paths
- Classify each reference before changing it
Package dependencies or create a rendered copy
When the recipient needs editable vectors, embed permitted images where practical or deliver a controlled asset package with verified relative paths. Confirm that image and font licenses allow the chosen distribution method. Remove unneeded scripts and references, and document the destination of links that must remain. Reinspect the file after saving because design applications can recreate links to their own working directories or external libraries. Increased file size may be an acceptable tradeoff for a self-contained deliverable, but it should be a deliberate decision.
If the recipient only needs to view the artwork, a PNG rendering can be a simpler sharing copy. Rasterization fixes the currently rendered pixels and does not carry the SVG's external reference structure into the PNG. It can still fail silently if remote content was blocked or unavailable during conversion, leaving missing images or fallback fonts in the raster result. Before converting, confirm that all intended elements are visible, then choose the required dimensions, background, and transparency. Keep the SVG master separately because the PNG no longer provides the original editable vectors.
- Embed or package only licensed required assets
- Consider PNG for view-only delivery
- Check for missing resources before rasterizing
Verify offline and in the receiving application
Open the revised SVG in a test environment with network access disabled or external requests blocked. Compare logos, images, icons, fonts, filters, and masks with a trusted reference. Then test the same file in both a browser and the application the recipient will actually use. Programs differ in font substitution, external-reference policy, CSS support, and script handling, so passing in one editor is not enough. If the workflow allows it, monitor requests during the test to confirm that the approved copy does not contact unexpected locations.
Search the final source again for newly introduced URLs and local paths. Review the filename and document metadata for personal or project information as well. If a PNG companion is included, inspect its dimensions, background, transparency, and edge quality in the publishing destination. Store the untouched master, cleaned SVG, and rendered derivative under clearly distinct names, and mark which version is approved for external sharing. This final separation reduces the chance that a working master with private references is sent by mistake.
- Reopen the file with network access disabled
- Test both browser and receiving editor
- Search the final source again before sending
The final sharing check must cover both rendered appearance and document source.
Key takeaways
- SVG elements and CSS can reference resources outside the file through URLs.
- External references can produce network requests, expose sensitive URL text, fail offline, or render differently across applications.
- Inspect the SVG source for href, xlink:href, URL functions, imports, remote schemes, and local paths.
- Create an approved sharing copy, test it offline and in the receiving application, and keep the untouched source separately.
Frequently asked questions
Can opening an SVG trigger an external request?
Yes, when the file contains external references and the viewing application and its security policy allow those resources to be fetched.
Is an SVG safe if no clickable link is visible?
Not necessarily. Hidden elements, style rules, href attributes, and local paths can still contain external references.
Should I delete every URL from an SVG?
No. First identify whether it is a navigation link or a rendering dependency, then embed, replace, document, or remove it appropriately.
Does converting the SVG to PNG solve the issue?
It removes the SVG reference structure from the delivered raster, but missing or blocked resources can still produce an incomplete PNG.
What is the simplest final check?
Search the final source for URLs and local paths, then reopen it offline and in the recipient's actual application.