How we test
JPG Smaller publishes tools only when they produce a real file. This page describes the checks we actually run: upload validation, processing, measured bytes, downloads, target ceilings, previews, responsive layout, and security limits.
What this page is
This is the testing method behind the tools, not a score or a “100% tested” badge. Some slugs have a dated verification card because they were in the last measured sample. Other slugs use the same engine and limits, and we say so instead of inventing a PASS row.
Who tests and who publishes
JPG Smaller publishes this site. There is no invented expert biography and no purchased certification. Questions go to [email protected]. Related pages: About and Research.
Upload test
Before pixels are touched, the server checks the upload.
- Supported formats: JPG, JPEG, JFIF, PNG, WebP, GIF, AVIF, BMP.
- MIME type is read from file bytes with PHP
finfo, not from the filename alone. - Files that are not valid images according to
getimagesizeare rejected. - Maximum upload size is 15 MB.
- Maximum edge is 8000 pixels. Maximum pixel count is 40,000,000.
- A browser upload must be a real uploaded file. Local-path processing is used only by our research scripts on the server.
Corrupt files, empty files, and spoofed extensions should produce a short error, not a fake success card.
Processing test
A passing run must create an output raster with the ImageProcessor. The result includes output format, width, height, and byte length of the generated file. We do not hardcode those values in the page. Preview URLs point at the same generated bytes used for download.
File test
After encoding, the server stores a temporary file and measures filesize. The label you see (for example 99 KB) is formatted from those bytes. If the file cannot be written or has zero bytes, the run fails.
Download test
Each successful result includes a download URL with a short-lived token. The downloaded file must exist and match the generated byte count. Temporary files are cleaned after 3600 seconds. They are not kept as a permanent photo library. See the Privacy Policy.
Target-size test
Tools with a kilobyte ceiling compare generated bytes to target_kb × 1024. The UI says the target was met only when that comparison is true. We do not label a 99 KB file as “exactly 100KB”. If the ceiling cannot be reached without severe damage, the tool reports a best-effort file and says so. Measured 100KB runs are published on the 100KB research page.
Visual test
Where a preview is appropriate, the preview image must load. Dimensions on the card must match the generated raster. “Usable” here means the image opens and the subject remains recognizable, not that every pixel is indistinguishable from the source. Lossy JPEG is not described as lossless.
Responsive test
Tool pages are checked at phone, mid-width, and desktop sizes in Cursor Browser / Preview. We look for a usable upload workspace, readable type, working primary actions, and no horizontal overflow on the tool chrome. This is layout QA, not a claim that every article paragraph has been reflow-tested on every device.
Security test
- Invalid, oversized, and unsupported uploads are rejected with generic user errors. PHP warnings and internal paths are not printed to the page.
- Download names are sanitized. Dangerous path characters are stripped.
- MIME spoofing is blocked by signature checks plus image dimension reads.
- URL fetch allows only HTTP or HTTPS, blocks private and loopback IPs, limits redirects, and caps download size. That is the SSRF guard for the fetch field.
- Processing is limited to 30 requests per minute per IP. URL fetches are limited to 15 per minute.
- Result text is escaped in the browser. Errors are plain text, not raw HTML.
- CSRF tokens are required on process and fetch requests.
Representative verification
The table below lists slugs that were processed on 5 October 2026 with alpine.jpg through the live ImageProcessor. Other live tools use the same code path. Absence from this table means “not in this sample”, not “untested marketing copy pretending to be a pass”.
| Tool | Processing | Bytes | Dimensions | Download | Measured sample |
|---|---|---|---|---|---|
| compress-jpg | PASS | VERIFIED | VERIFIED | VERIFIED | 644 KB, 2400×1600 |
| compress-jpg-to-100kb | PASS | VERIFIED | VERIFIED | VERIFIED | 99 KB, 1920×1280 |
| resize-image-to-1080x1080 | PASS | VERIFIED | VERIFIED | VERIFIED | 134 KB, 1080×1080 |
| jpg-to-webp | PASS | VERIFIED | VERIFIED | VERIFIED | 302 KB, 2400×1600 |
| crop-image | PASS | VERIFIED | VERIFIED | VERIFIED | 338 KB, 1600×1600 |
| file-mime-type-checker | PASS | VERIFIED | VERIFIED | VERIFIED | 644 KB, 2400×1600 |
Original research
Beyond smoke checks, we run controlled experiments on a fixed photo set (alpine, coast, forest, city, ceramic, books, flower, watch). Those rows live on the research pages. If a conclusion is weak, the article says so.
What we will not claim
We do not publish fake user counts, fake ratings, or “guaranteed lossless JPEG”. We do not mark a target as exact unless bytes match. We do not list a verification PASS on a tool that was not in the measured sample.