
Categorify – WordPress Media Library Category & File Manager Security & Risk Analysis
wordpress.org/plugins/categorifyOrganize your WordPress media files in categories via drag and drop.
Is Categorify – WordPress Media Library Category & File Manager Safe to Use in 2026?
Use With Caution
Score 59/100Categorify – WordPress Media Library Category & File Manager has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'categorify' plugin v1.0.7.5 presents a mixed security posture. While it demonstrates good practices in output escaping and utilizes prepared statements for most SQL queries, significant concerns arise from its attack surface and past vulnerability history. The presence of an unprotected AJAX handler is a direct security risk, as it can be triggered by unauthenticated users, potentially leading to unauthorized actions. Furthermore, the taint analysis reveals three flows with unsanitized paths, two of which are rated as high severity, indicating potential for data manipulation or injection vulnerabilities. The plugin's history of 11 known CVEs, with one still unpatched, and a prevalence of Cross-Site Request Forgery and Missing Authorization issues, strongly suggests a pattern of recurring security weaknesses. While the plugin has strengths in output handling and SQL query safety, these are overshadowed by the direct risks from unprotected entry points, taint flow issues, and a history of unaddressed vulnerabilities.
Key Concerns
- Unprotected AJAX handler
- High severity taint flows
- Unpatched CVE
- History of CSRF and Missing Authorization
- Bundled Freemius library (potential for outdatedness)
Categorify – WordPress Media Library Category & File Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Categorify <= 1.0.7.5 - Missing Authorization
Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxDeleteCategory
Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxAddCategory
Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxUpdateFolderPosition
Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxRenameCategory
Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxUpdateFolderPosition
Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxAddCategory
Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxClearCategory
Categorify <= 1.0.7.4 - Cross-Site Request Forgery via categorifyAjaxClearCategory
Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxDeleteCategory
Categorify <= 1.0.7.4 - Missing Authorization in categorifyAjaxRenameCategory
Categorify – WordPress Media Library Category & File Manager Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Categorify – WordPress Media Library Category & File Manager Attack Surface
AJAX Handlers 12
WordPress Hooks 16
Maintenance & Trust
Categorify – WordPress Media Library Category & File Manager Maintenance & Trust
Maintenance Signals
Community Trust
Categorify – WordPress Media Library Category & File Manager Alternatives
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types
wicked-folders
Organize your pages, posts, and custom post types into folders. Upgrade to pro for media library folders, WooCommerce integration, and more.
iFolders – Ultimate Folder Organizer for Media Library, Pages, Posts and Users
ifolders
Take control of your media library, posts, pages, and other content with our folder manager. Organize your WordPress data into specific categories.
MediaCommander – Bring Folders to Media, Posts, and Pages
mediacommander
Take control of your data with our folder manager - organize your WordPress media library, posts, and pages into specific categories with ease.
Real Media Library: Media Library Folder & File Manager
real-media-library-lite
Organize uploaded media in folders, collections and galleries: A file manager for WordPress. Media management made easy with Real Media Library! (Alte …
Categorify – WordPress Media Library Category & File Manager Developer Profile
2 plugins · 1K total installs
How We Detect Categorify – WordPress Media Library Category & File Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/categorify/inc/settings/assets/css/magnific-popup.css/wp-content/plugins/categorify/inc/settings/assets/css/style.css/wp-content/plugins/categorify/inc/settings/assets/js/magnific-popup.js/wp-content/plugins/categorify/inc/settings/assets/js/init.jsinc/settings/assets/js/magnific-popup.jsinc/settings/assets/js/init.jscategorify/1.0.7.5categorify/inc/settings/assets/css/magnific-popup.css?ver=categorify/inc/settings/assets/css/style.css?ver=categorify/inc/settings/assets/js/magnific-popup.js?ver=categorify/inc/settings/assets/js/init.js?ver=HTML / DOM Fingerprints
categorify-attachment-sidebar DO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE `function_exists` CALL ABOVE TO PROPERLY WORK.include main plugin fileregister CATEGORIFY taxonomyget interface+14 moredata-iddata-namedata-positioncategorify_params/wp-json/categorify/v1/categories/wp-json/categorify/v1/media