
Custom Upload Folder Security & Risk Analysis
wordpress.org/plugins/custom-upload-folderUpload files to custom directory in WordPress Media Library.
Is Custom Upload Folder Safe to Use in 2026?
Generally Safe
Score 85/100Custom Upload Folder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-upload-folder plugin v1.1.2 exhibits a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. However, the lack of nonce checks and capability checks across all entry points, combined with a moderate rate of unescaped output (33% not properly escaped), presents a potential area for concern. While the vulnerability history is clean, indicating a well-maintained plugin so far, the absence of security checks could become a vulnerability if new entry points are added or if existing code is modified without proper security considerations. The plugin's current design is secure by obscurity due to its limited entry points, but it lacks robust authorization and input validation mechanisms for its outputs.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Outputs not properly escaped
Custom Upload Folder Security Vulnerabilities
Custom Upload Folder Code Analysis
Output Escaping
Custom Upload Folder Attack Surface
WordPress Hooks 7
Maintenance & Trust
Custom Upload Folder Maintenance & Trust
Maintenance Signals
Community Trust
Custom Upload Folder Alternatives
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
WP Extra File Types
wp-extra-file-types
Plugin to let you extend the list of allowed file types supported by the Wordpress Media Library
Easy SVG Support
easy-svg
This Plugin allows you to upload SVG Files into your Media library.
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Custom Upload Folder Developer Profile
1 plugin · 400 total installs
How We Detect Custom Upload Folder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
custom-upload-folder/style.css?ver=1.1.2HTML / DOM Fingerprints
js-custom-upload-folderdata-custom-upload-folder