
Add From Server Reloaded Security & Risk Analysis
wordpress.org/plugins/add-from-server-reloadedBypass WordPress upload limits and import large files or folders directly from anywhere on your server into the WordPress Media Library.
Is Add From Server Reloaded Safe to Use in 2026?
Generally Safe
Score 100/100Add From Server Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The add-from-server-reloaded plugin, version 5.2.0, exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant positive. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries, performing a decent percentage of output escaping, and implementing nonce and capability checks. The fact that there are no known CVEs is also a reassuring indicator of its historical security.
However, the taint analysis reveals a notable concern. Two flows were identified with unsanitized paths, both flagged as high severity. This indicates a potential for path traversal vulnerabilities, where an attacker might be able to manipulate file paths to access or manipulate files outside of the intended scope. While the absence of external HTTP requests and dangerous functions is commendable, these identified taint flows represent the most significant immediate risk.
In conclusion, add-from-server-reloaded 5.2.0 has several strengths, particularly in its limited attack surface and secure data handling for SQL. The lack of historical vulnerabilities is a positive sign. Nevertheless, the presence of high-severity unsanitized path flows in the taint analysis necessitates careful review and remediation to mitigate potential risks.
Key Concerns
- High severity unsanitized path flows found
Add From Server Reloaded Security Vulnerabilities
Add From Server Reloaded Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Add From Server Reloaded Attack Surface
WordPress Hooks 1
Maintenance & Trust
Add From Server Reloaded Maintenance & Trust
Maintenance Signals
Community Trust
Add From Server Reloaded Alternatives
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Bulk Media Register
bulk-media-register
Bulk register files on the server to the Media Library.
Big File Uploads – Increase Maximum File Upload Size
tuxedo-big-file-uploads
Enable large file uploads in the built-in WordPress media uploader via file chunking, and set maximum upload file size to any value based on user role …
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Add From Server Reloaded Developer Profile
1 plugin · 1K total installs
How We Detect Add From Server Reloaded
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-from-server-reloaded/add-from-server.css/wp-content/plugins/add-from-server-reloaded/add-from-server.js/wp-content/plugins/add-from-server-reloaded/add-from-server.jsadd-from-server-reloaded/add-from-server.css?ver=add-from-server-reloaded/add-from-server.js?ver=HTML / DOM Fingerprints
afsrreloaded-maindata-noncedata-ajaxurldata-processingdata-completedata-errorafsrreloadedData