Hi db0, if I could make an additional suggestion.
Add detection of additional content appended or attached to media files. Pict-rs does not reprocess all media types on upload and it’s not hard to attach an entire .zip file or other media within an image (https://wiki.linuxquestions.org/wiki/Embed_a_zip_file_into_an_image)
As @[email protected] stated. They’re still valid image files, they just have extra data.