
Add From Server Security & Risk Analysis
wordpress.org/plugins/add-from-serverAdd From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Is Add From Server Safe to Use in 2026?
Mostly Safe
Score 84/100Add From Server is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The 'add-from-server' plugin v3.4.5 demonstrates a generally good security posture concerning its current code. The static analysis reveals a promising lack of identified dangerous functions, all SQL queries utilize prepared statements, and there are no external HTTP requests. The presence of nonce and capability checks, along with proper output escaping for a majority of outputs, indicates an effort towards secure coding practices. The attack surface is reported as zero, which, if accurate, is a significant positive, meaning there are no directly exposed entry points like AJAX handlers, REST API routes, or shortcodes that could be immediately exploited.
However, a critical concern arises from its vulnerability history. The plugin has one known CVE, which was a high-severity Cross-Site Request Forgery (CSRF) vulnerability. While this CVE is reported as patched (0 currently unpatched), the existence of a past high-severity vulnerability, especially of the CSRF type, suggests that the plugin's codebase might have had inherent weaknesses that could reappear or be a target for future attacks. The lack of taint analysis data is also a gap, as it limits the insight into potential data flow vulnerabilities that might not be caught by static function analysis alone.
In conclusion, the current version of 'add-from-server' appears to have addressed immediate code-level threats effectively, with a minimal attack surface and good coding practices in place. The primary weakness stems from its past high-severity CSRF vulnerability, which warrants caution and continuous monitoring. While the current code seems clean, the historical context suggests a potential for issues to arise if development practices lapse or if new attack vectors are discovered.
Key Concerns
- Known high severity CVE
- Limited taint analysis data
- Some output not properly escaped
Add From Server Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Add From Server <= 3.3.1 - Cross-Site Request Forgery
Add From Server Release Timeline
Add From Server Code Analysis
Output Escaping
Add From Server Attack Surface
WordPress Hooks 3
Maintenance & Trust
Add From Server Maintenance & Trust
Maintenance Signals
Community Trust
Add From Server Alternatives
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Reveal IDs
reveal-ids-for-wp-admin-25
What this plugin does is to reveal most removed IDs on admin pages, as it was in versions prior to 2.5.
Bulk Media Register
bulk-media-register
Bulk register files on the server to the Media Library.
Post Export Import with Media
post-export-import-with-media
Easily export and import WP posts, pages, media, widgets, menus, themes, plugins & settings with their media files- secure, fast, and with real-ti …
AWSOM Pixgallery
awsom-pixgallery
AWSOM Pixgallery is an Image Gallery/Archive plugin for Wordpress designed to make it easier for Artists or Webcomic creators to set up a portfolio of …
Add From Server Developer Profile
2 plugins · 100K total installs
How We Detect Add From Server
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-from-server/add-from-server.js/wp-content/plugins/add-from-server/add-from-server.css/wp-content/plugins/add-from-server/add-from-server.jsadd-from-server.js?ver=add-from-server.css?ver=HTML / DOM Fingerprints
wrapdata-capability="upload_files"add_from_server_data