

An image CDN for WordPress: every image reaches the visitor resized and in WebP or AVIF, from our global network — not from your server.
NimboCDN is an image CDN for WordPress and WooCommerce. Every image on your site is resized and converted to WebP or AVIF — the most modern and efficient image formats there are, with no loss in perceived quality — and delivered from our global network, in 335 cities. Your own server stops delivering images and your site gets faster. You do not need to create an account or paste an API key, and there is no bulk compression process to run on your server. We never modify your original files.
You upload a large image and WordPress keeps the file exactly as it came. That is the file your visitor’s browser downloads — whole, even when the image shows up small on a phone. Your visitor waits for weight they never get to see, and that weight leaves from your server: every image, to every visitor, every single time.
NimboCDN takes care of that on its own. Every visitor receives each image in the size their screen needs and the best format their browser accepts. You configure nothing.
srcsetsrc, srcset, <picture> sources, gallery zoom and lightbox links and CSS backgrounds, so they point at our network. Nothing else changes.On a normal WordPress site, serving images is the bulk of the work your server does: on a page with twenty images there are twenty files to find on disk, read and push out, for every visitor, all day. That work competes with what you actually care about — building the page, running the queries, taking the order.
With NimboCDN your server delegates that job. It is asked once per image, ever; after that our network answers. Measured on real traffic: 98.7% of the images visitors received never came out of the site’s own server. What is left is what your server is for — showing your blog, your shop, your pages.
Most plugins that optimize images for WordPress are library compressors: an image optimizer that works on the files you already uploaded. They re-compress what sits on your server and charge you for what you upload — and since WordPress makes six to eight thumbnails per upload, you pay for sizes no visitor will ever request.
NimboCDN works at the other end, on what actually reaches the visitor:
Every image is delivered as AVIF or WebP depending on what the visitor’s browser accepts — no converter to run, no second copy on your server. A client that accepts neither gets your original file, exactly as without the plugin.
A phone does not need a 3000-pixel file. You never have to resize images by hand or regenerate thumbnails again: NimboCDN offers each image at 400, 800 and 1200 pixels wide with a matching sizes attribute and lets the browser pick. No width larger than the one WordPress offered is ever announced, so a page can never get heavier than it was.
This is exactly what PageSpeed Insights asks for when it reports serve images in next-gen formats and properly size images.
Your JPEG and PNG files stay exactly as you uploaded them: not re-compressed, not resized, not moved, not deleted. The plugin only changes the address of the image in your HTML.
The free plan is not a trial and does not expire. It serves every image on your home page in WebP, in three sizes, from the global cache, with up to 50 new home-page images per month — the number is here, before you install, on purpose. The rest of your site keeps being served by WordPress exactly as before, and visits are never counted or charged: ten visitors or ten thousand, it stays free.
Pro is a paid plan of the hosted service — there is no second plugin to install. You switch plans from this same settings screen, and all the plugin’s code is here and works on every plan; the plan only changes what the network serves.
NimboCDN was built for WooCommerce stores and tested on them: product galleries, gallery zoom (data-large_image), lightboxes, category banners and CSS background heroes. A catalogue is where image weight hurts most — one product page can carry five images, a category page forty.
It works just as well on a blog, a portfolio or a company site, and is at its most useful on shared hosting, where delegating image delivery is the cheapest speed there is. WooCommerce is not required.
<picture> block with its own WebP copies, NimboCDN finds the original behind it and serves that.Three independent fallbacks, each ending with the visitor seeing your image:
<img> element falls back to the file WordPress would have served.The plugin makes no network call during a page view, so it cannot become a single point of failure.
No personal data about your visitors is collected — not their IP address, not their browser, not the page they viewed. The service keeps aggregate counts and byte totals per site, so the settings screen can show what your visitors stopped downloading. Everything the plugin sends is listed under External services below. https://nimbocdn.net/privacy
Install NimboCDN, activate it, and open Settings NimboCDN. Your home page is where that weight hurts most — it is the page most visitors see first — so that is the one we weigh, right there, before you decide anything. No account, no card, one click to undo.
This plugin is a connector for NimboCDN, a hosted image delivery service operated by DIO Digital, the plugin author. The plugin does nothing useful without it: every image it rewrites is served by the service. By installing and activating the plugin you register your site with the service, as described here.
Registration — on activation, once. The plugin sends your site’s domain to https://nimbocdn-prd-control.nimbocdn.workers.dev/activate/start, which answers with a random challenge. The plugin exposes that challenge for five minutes at /wp-json/nimbocdn/v1/challenge, at /?nimbocdn-challenge=1, and as a small text file wp-content/uploads/nimbocdn-challenge-<random>.txt with a blank PNG image of the same name next to it (both removed as soon as registration finishes). It then sends the domain, site name, WordPress version, plugin version, site language and the administrator email address to /activate/finish. The service reads the challenge from your site — proof that whoever registers the domain controls it. When a firewall or antibots answers the service with a challenge page of its own, the service checks instead the width and height of that PNG image, fetched through Cloudflare Images, which are derived from the challenge. A domain nobody registered before is registered even when the proof fails, so a firewall never leaves the plugin idle; until the proof succeeds the site stays on the free plan and cannot manage billing. Re-activating the same domain returns the same credentials, so your history survives an uninstall; www. and non-www. spellings of one domain are one site.
Health, account and home-page sync — from the background and from the settings screen. Twice a day by WP-Cron, when you press Measure now (at most once a minute), when you open or return to the settings screen, and when your home page changes, the plugin sends your site identifier to /health, /account and /site/home on the same host. The last one carries the list of image files your home page uses and the HTML of your home page as your own server returns it, so the service can verify them — by visiting your home page, or, when a firewall or antibots blocks that visit, against the HTML the plugin sent — and answer which ones it will serve. The response says whether the service is available, which delivery hostname to use, your plan and allowance, and the delivery statistics shown on the settings screen. No visitor data and nothing about your posts other than your public home page is sent.
Image delivery — when a visitor loads a page. The visitor’s browser requests images from the delivery hostname (currently cdn.nimbocdn.net). That request carries the URL of the original image, the size of the file WordPress would otherwise have served, and the browser’s own Accept header, as any image request does. For each image served, the edge records the delivered size, format and cache state against your site identifier — sampled on busy sites — never the visitor’s IP address, user agent or page. When a request is refused (for example, a signature that does not match), the edge also records the URL of the refused original so the refusal can be investigated; that URL is a file path on your own site. The plugin itself makes no network call during a page view.
Network card — when you open the settings screen. Your browser asks https://<delivery host>/whoami four times: the first request only opens the connection, the next three are timed and the fastest is shown. A failed request is retried once. The answer names the data center that served the request and the approximate city of your own IP address, so the screen can show where your images are delivered from, and in how many milliseconds, for that computer. Nothing is stored.
Billing — only when you click. Get Pro, Manage plan and Switch to annual ask the service for a checkout, portal or invoice URL and send your browser there. Payments are handled by the service’s payment provider on its own pages; the plugin never sees a card number, a price or a currency, and contains no payment logic.
Emails. Two kinds, and they are not the same thing.
What is stored, and how to erase it. The service keeps your domain, the administrator email, your plan and aggregate delivery statistics. We never sell or share your data with third parties; your address is used by us, to write to you, and by nobody else. Uninstalling the plugin removes every option, transient and scheduled task it created on your site. To erase your account and statistics from the service as well, write to [email protected] from the registered address.
The icons in the settings screen — the crown on the Pro badge, the handshake on a plan provided by a partner, and the small line icons beside the “Why NimboCDN” and support text — are from Tabler Icons, MIT licensed.
Copyright (c) 2020-2026 Paweł Kuna — https://tabler.io/icons
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the above copyright notice and this permission notice being included in all copies or substantial portions of the Software.
The SVG paths are inlined in the settings screen rather than shipped as files: there are a handful of them, and an <img> would cost a request per page load for a few hundred bytes of path.