
Custom Upload Folders Security & Risk Analysis
wordpress.org/plugins/custom-upload-foldersOrganize your uploaded files in custom folders. Available options: by Year-Month-Day, File Type, Post ID or Author Display Name.
Is Custom Upload Folders Safe to Use in 2026?
Generally Safe
Score 85/100Custom Upload Folders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-upload-folders v1.2 plugin exhibits a generally good security posture based on the provided static analysis. The plugin has a minimal attack surface with no detected AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, none of these are unprotected. The absence of dangerous functions, file operations, and external HTTP requests is also a positive sign. SQL queries are all handled with prepared statements, indicating a strong defense against SQL injection. However, a significant concern arises from the output escaping. With 100% of detected outputs not being properly escaped, this opens the door to potential Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress admin area or user-facing content.
The vulnerability history of this plugin is clean, with no known CVEs recorded. This, combined with the lack of critical or high-severity taint flows, suggests that the developers have historically been diligent in producing secure code. The absence of bundled libraries further simplifies the security audit by reducing potential attack vectors from outdated third-party components. Despite the positive history and clean taint analysis, the unescaped output remains a critical weakness that needs immediate attention. The plugin's strengths lie in its limited attack surface and secure data handling for SQL, but the lack of output escaping represents a substantial, direct risk.
Key Concerns
- Outputs not properly escaped
Custom Upload Folders Security Vulnerabilities
Custom Upload Folders Code Analysis
Output Escaping
Custom Upload Folders Attack Surface
WordPress Hooks 6
Maintenance & Trust
Custom Upload Folders Maintenance & Trust
Maintenance Signals
Community Trust
Custom Upload Folders Alternatives
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Bulk Media Register
bulk-media-register
Bulk register files on the server to the Media Library.
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
WP Extra File Types
wp-extra-file-types
Plugin to let you extend the list of allowed file types supported by the Wordpress Media Library
Custom Upload Folders Developer Profile
3 plugins · 1K total installs
How We Detect Custom Upload Folders
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-upload-folders/css/styles.css/wp-content/plugins/custom-upload-folders/js/custom-upload-folders.js/wp-content/plugins/custom-upload-folders/js/custom-upload-folders.jscustom-upload-folders/css/styles.css?ver=custom-upload-folders/js/custom-upload-folders.js?ver=HTML / DOM Fingerprints
hiddenname="custom_upload_folders"id="custom_upload_folders"id="alert-structure"custom_upload_foldersalert_structure