AzDrive – WordPress Media Folders & Organizer Security & Risk Analysis

wordpress.org/plugins/azdrive

Organize your media library with folders and subfolders. Drag & drop files, color folders, sort and import from other plugins.

30 active installs v1.0.3 PHP 7.4+ WP 4.7+ Updated Jun 5, 2025
drag-and-dropmedia-foldersorganize-mediasubfoldersupload-to-folder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AzDrive – WordPress Media Folders & Organizer Safe to Use in 2026?

Generally Safe

Score 100/100

AzDrive – WordPress Media Folders & Organizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "azdrive" v1.0.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, proper output escaping for all outputs, and the presence of nonce and capability checks on all identified code signals are excellent security practices. Furthermore, the lack of file operations and external HTTP requests reduces potential attack vectors. The plugin also boasts a clean vulnerability history with no recorded CVEs, suggesting a history of secure development or diligent maintenance.

However, a notable concern is the 20% of SQL queries that do not utilize prepared statements. While the total number of SQL queries is low, raw SQL can be susceptible to SQL injection vulnerabilities, especially if user-supplied data is directly incorporated into these queries. The taint analysis showing zero flows with unsanitized paths is positive, but this doesn't entirely negate the risk from raw SQL if the input to those queries is not thoroughly validated and sanitized elsewhere. The absence of any identified attack surface points (AJAX, REST API, shortcodes, cron events) is a strength, but it also limits the scope of the static analysis in identifying potential weaknesses in these areas.

In conclusion, the "azdrive" plugin demonstrates good security hygiene in many areas, particularly in output handling and the lack of exploitable entry points. The primary area for improvement lies in ensuring all SQL queries are parameterized to mitigate SQL injection risks. The clean vulnerability history is a significant positive indicator of the plugin's overall security reliability.

Key Concerns

  • SQL queries not using prepared statements
Vulnerabilities
None known

AzDrive – WordPress Media Folders & Organizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AzDrive – WordPress Media Folders & Organizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
1 prepared
Unescaped Output
0
25 escaped
Nonce Checks
2
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

20% prepared5 total queries

Output Escaping

100% escaped25 total outputs
Attack Surface

AzDrive – WordPress Media Folders & Organizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionadmin_initazdrive.php:26
actionadmin_enqueue_scriptsincludes\Admin\Assets.php:20
filterscript_loader_tagincludes\Admin\Assets.php:21
filterazdrive_post_typesincludes\Admin\Attachment.php:25
actionazdrive_admin_loadedincludes\Admin\Attachment.php:27
filterazdrive_post_typeincludes\Admin\Attachment.php:40
filterattachment_fields_to_editincludes\Admin\Attachment.php:42
actionpre-plupload-upload-uiincludes\Admin\Attachment.php:43
filtermedia_view_stringsincludes\Admin\Attachment.php:44
actionadd_attachmentincludes\Admin\Attachment.php:46
actiondelete_attachmentincludes\Admin\Attachment.php:47
filterajax_query_attachments_argsincludes\Admin\Attachment.php:48
actionin_admin_headerincludes\Admin\Dashboard.php:21
filterposts_clausesincludes\Admin\Folder.php:20
actionadmin_menuincludes\Admin\Menu.php:20
filterazdrive_rest_routesincludes\Api\FolderRoute.php:19
filterazdrive_rest_routesincludes\Api\ImportRoute.php:28
filterazdrive_folder_create_beforeincludes\Api\Middleware\Folder.php:22
filterazdrive_folder_update_beforeincludes\Api\Middleware\Folder.php:24
actionrest_api_initincludes\Api\Routes.php:18
filterazdrive_rest_routesincludes\Api\SettingsRoute.php:23
filterazdrive_rest_routesincludes\Api\UserRoute.php:27
actionplugins_loadedincludes\Plugin.php:24
actionadmin_initincludes\Plugin.php:25
actionadmin_noticesviews\notices\plugin-exist.php:6
Maintenance & Trust

AzDrive – WordPress Media Folders & Organizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 5, 2025
PHP min version7.4
Downloads585

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

AzDrive – WordPress Media Folders & Organizer Developer Profile

AzPage

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AzDrive – WordPress Media Folders & Organizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/azdrive/assets/dist/main.js
Script Paths
http://localhost:5173/src/main.js
Version Parameters
azdrive?ver=azdrive-app?ver=

HTML / DOM Fingerprints

Data Attributes
type="module"
JS Globals
azdriveApi
REST Endpoints
/wp-json/azdrive/v1/folder/wp-json/azdrive/v1/settings/wp-json/azdrive/v1/import/wp-json/azdrive/v1/user
FAQ

Frequently Asked Questions about AzDrive – WordPress Media Folders & Organizer