Central Media Manager for Multisite Security & Risk Analysis

wordpress.org/plugins/central-media-library-for-network-websites

Centralize your WordPress media uploads across all sites in a multisite network with this lightweight and easy-to-use plugin.

0 active installs v1.1.8 PHP 7.0+ WP 4.7+ Updated Feb 1, 2026
central-mediamedia-filesmedia-librarymultisiteshared-media
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Central Media Manager for Multisite Safe to Use in 2026?

Generally Safe

Score 100/100

Central Media Manager for Multisite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "central-media-library-for-network-websites" version 1.1.8 exhibits a significant security concern due to its large number of unprotected AJAX handlers. With 6 AJAX handlers identified, all of which lack proper authentication checks, this presents a substantial attack surface. While the plugin demonstrates good practices in other areas, such as 100% proper output escaping and the absence of dangerous functions, the unprotected AJAX endpoints are a critical weakness. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting potential good development practices in the past or a lack of targeted attacks. However, the current state of unprotected AJAX handlers overrides this positive historical data and demands immediate attention. A balanced conclusion highlights the strengths in output handling and the absence of dangerous code, but the critical weakness in AJAX security overshadows these positives.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Central Media Manager for Multisite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Central Media Manager for Multisite Release Timeline

v1.1.8Current
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
Code Analysis
Analyzed Apr 16, 2026

Central Media Manager for Multisite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
5
Capability Checks
12
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Attack Surface
6 unprotected

Central Media Manager for Multisite Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_query-attachmentscentral-media-library-for-network-sites.php:23
authwp_ajax_get-attachmentcentral-media-library-for-network-sites.php:27
authwp_ajax_save-attachmentcentral-media-library-for-network-sites.php:31
authwp_ajax_set-post-thumbnailcentral-media-library-for-network-sites.php:35
authwp_ajax_delete-attachmentcentral-media-library-for-network-sites.php:39
authwp_ajax_upload-attachmentcentral-media-library-for-network-sites.php:43
WordPress Hooks 39
filterrest_request_before_callbackscentral-media-library-for-network-sites.php:46
filterrest_request_after_callbackscentral-media-library-for-network-sites.php:47
filterrest_dispatch_requestcentral-media-library-for-network-sites.php:48
filterrest_pre_insert_postcentral-media-library-for-network-sites.php:50
filterrest_pre_insert_pagecentral-media-library-for-network-sites.php:51
actionrest_after_insert_postcentral-media-library-for-network-sites.php:52
actionrest_after_insert_pagecentral-media-library-for-network-sites.php:53
filterrest_post_dispatchcentral-media-library-for-network-sites.php:55
filterrest_request_before_callbackscentral-media-library-for-network-sites.php:57
actionadd_post_metacentral-media-library-for-network-sites.php:60
actionupdate_post_metacentral-media-library-for-network-sites.php:61
filterupdate_post_metadatacentral-media-library-for-network-sites.php:62
filteradd_post_metadatacentral-media-library-for-network-sites.php:63
filterupload_dircentral-media-library-for-network-sites.php:66
filterimage_downsizecentral-media-library-for-network-sites.php:67
filterwp_get_attachment_urlcentral-media-library-for-network-sites.php:68
filterwp_get_attachment_image_srccentral-media-library-for-network-sites.php:69
filterget_postcentral-media-library-for-network-sites.php:70
filterplupload_default_settingscentral-media-library-for-network-sites.php:71
filteruser_has_capcentral-media-library-for-network-sites.php:72
filterwp_insert_attachment_datacentral-media-library-for-network-sites.php:75
actionattachment_updatedcentral-media-library-for-network-sites.php:76
actionadd_attachmentcentral-media-library-for-network-sites.php:77
actionedit_attachmentcentral-media-library-for-network-sites.php:78
actionset_auth_cookiecentral-media-library-for-network-sites.php:81
filtermedia_send_to_editorcentral-media-library-for-network-sites.php:86
filteradmin_post_thumbnail_htmlcentral-media-library-for-network-sites.php:88
actionsave_postcentral-media-library-for-network-sites.php:90
filteruser_has_capinc/cmlfnw-ajax-actions.php:165
filteruser_has_capinc/cmlfnw-ajax-actions.php:252
filteruser_has_capinc/cmlfnw-ajax-actions.php:312
filterimage_downsizeinc/cmlfnw-namespace.php:334
filterimage_downsizeinc/cmlfnw-namespace.php:349
filterwp_get_attachment_urlinc/cmlfnw-namespace.php:384
filterwp_get_attachment_image_srcinc/cmlfnw-namespace.php:428
filterget_postinc/cmlfnw-namespace.php:491
actionpre_get_postsinc/cmlfnw-namespace.php:935
filterposts_resultsinc/cmlfnw-namespace.php:978
actionadmin_footerinc/cmlfnw-namespace.php:1043
Maintenance & Trust

Central Media Manager for Multisite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings4
Active installs0
Developer Profile

Central Media Manager for Multisite Developer Profile

Kirtikumar Solanki

16 plugins · 150 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Central Media Manager for Multisite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/central-media-library-for-network-websites/css/cmlfnw-admin.css/wp-content/plugins/central-media-library-for-network-websites/js/cmlfnw-admin.js/wp-content/plugins/central-media-library-for-network-websites/css/cmlfnw-public.css/wp-content/plugins/central-media-library-for-network-websites/js/cmlfnw-public.js
Script Paths
/wp-content/plugins/central-media-library-for-network-websites/js/cmlfnw-admin.js/wp-content/plugins/central-media-library-for-network-websites/js/cmlfnw-public.js
Version Parameters
central-media-library-for-network-websites/css/cmlfnw-admin.css?ver=central-media-library-for-network-websites/js/cmlfnw-admin.js?ver=central-media-library-for-network-websites/css/cmlfnw-public.css?ver=central-media-library-for-network-websites/js/cmlfnw-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
cmlfnw-admin-wrapcmlfnw-bulk-upload-wrapcmlfnw-edit-media-wrapcmlfnw-featured-image-wrapcmlfnw-gallery-wrapcmlfnw-media-framecmlfnw-media-librarycmlfnw-modal-content+6 more
HTML Comments
<!-- Main Media Library Link --><!-- End Main Media Library Link --><!-- Central Media Manager for Multisite - Start --><!-- Central Media Manager for Multisite - End -->+9 more
Data Attributes
data-cmlfnw-iddata-cmlfnw-media-iddata-cmlfnw-post-iddata-cmlfnw-sourcedata-cmlfnw-action
JS Globals
cmlfnw_admincmlfnw_publiccmlfnwAjaxUrl
REST Endpoints
/wp-json/cmlfnw/v1/media/wp-json/cmlfnw/v1/attachments/wp-json/cmlfnw/v1/upload
FAQ

Frequently Asked Questions about Central Media Manager for Multisite