
File Groups Security & Risk Analysis
wordpress.org/plugins/file-groupsAdd "file group" multiple file handling capability.
Is File Groups Safe to Use in 2026?
Generally Safe
Score 100/100File Groups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "file-groups" plugin v1.1.5 exhibits a mixed security posture. On the positive side, the plugin has a very small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, and its vulnerability history is clean. The use of prepared statements for most SQL queries is also a good practice.
However, significant concerns arise from the static analysis. The most critical finding is a high severity taint flow, indicating a potential vulnerability where user input could be manipulated. The low percentage of properly escaped output (9%) is a major red flag, suggesting a high risk of cross-site scripting (XSS) vulnerabilities. The presence of unsanitized paths in taint flows further exacerbates this risk. The single file operation, while not inherently bad, needs careful scrutiny in conjunction with the taint analysis. The absence of nonce checks on any entry points (though the attack surface is zero) and only one capability check means that even if an entry point were discovered, authorization might be weak.
In conclusion, while the plugin has a minimal attack surface and a clean vulnerability history, the static analysis reveals significant weaknesses, particularly in output escaping and taint flow handling. These issues present a considerable risk that outweighs the plugin's limited attack surface. Developers should prioritize addressing the output escaping and taint flow vulnerabilities immediately.
Key Concerns
- High severity taint flow found
- Only 9% of outputs properly escaped
- Unsanitized paths in taint flows
- One file operation present
- No nonce checks found
- Only one capability check found
File Groups Security Vulnerabilities
File Groups Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
File Groups Attack Surface
WordPress Hooks 20
Maintenance & Trust
File Groups Maintenance & Trust
Maintenance Signals
Community Trust
File Groups Alternatives
File Upload Types by WPForms
file-upload-types
Easily allow WordPress to accept and upload any file type extension or MIME type, including custom file types.
Download Attachments
download-attachments
Download Attachments is a new approach to managing downloads in WordPress. It allows you to easily add and display download links in any post or page.
Hotlink File Prevention
hotlink-file-prevention
Simple hotlink protection for individual files in the media library.
m1.DownloadList
m1downloadlist
This plugin easily displays the folders and files from a selected directory. It can be placed by shortcode in any post.
Modify Attachments Meta
modify-attachments-meta
Allows modification of meta data of attachments, such as date fields, menu order... (soon to add more, I guess).
File Groups Developer Profile
13 plugins · 6K total installs
How We Detect File Groups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/file-groups/file-groups.cssfile-groups/style.css?ver=file-groups.css?ver=HTML / DOM Fingerprints
fg_xitfg_list_itemfg_list_item_link