
File Un-Attach Security & Risk Analysis
wordpress.org/plugins/file-un-attachThis plugin will allow you to attach a single file to multiple posts, but will also will allow you to detach any file.
Is File Un-Attach Safe to Use in 2026?
Generally Safe
Score 85/100File Un-Attach has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "file-un-attach" plugin v1.1.3 exhibits a generally good security posture with no known historical vulnerabilities. The static analysis reveals a limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. This indicates a deliberate effort to minimize potential entry points for attackers. Furthermore, the majority of SQL queries utilize prepared statements, and a reasonable percentage of outputs are properly escaped, demonstrating adherence to some secure coding practices.
However, the analysis does flag a critical concern with the presence of the `unserialize` function. While the static analysis doesn't explicitly show an unsanitized path leading to this function, the mere use of `unserialize` on potentially untrusted data is a significant risk. It's possible that unsanitized data could be passed to `unserialize`, leading to Remote Code Execution (RCE) or other severe vulnerabilities. The taint analysis also indicates one flow with an unsanitized path, which, while not classified as critical or high, still warrants attention as it represents a potential weakness.
In conclusion, the plugin's lack of historical vulnerabilities and its minimal attack surface are positive signs. Nevertheless, the identified use of `unserialize` and the single unsanitized taint flow represent critical potential weaknesses that could be exploited. Further investigation into how data is passed to `unserialize` is highly recommended to fully assess and mitigate these risks.
Key Concerns
- Use of unserialize function
- Flows with unsanitized paths
- Output escaping is not fully proper (68%)
File Un-Attach Security Vulnerabilities
File Un-Attach Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
File Un-Attach Attack Surface
WordPress Hooks 16
Maintenance & Trust
File Un-Attach Maintenance & Trust
Maintenance Signals
Community Trust
File Un-Attach Alternatives
Auto Delete Unattached Media
auto-delete-unattached-media
Automatically delete unattached/unused media/images/attachments every minute silently in the background.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
Import external attachments
import-external-attachments
Makes local copies of all the linked images and pdfs in a post, adding them as gallery attachments.
PhotoSwipe
photo-swipe
A very light implementation of PhotoSwipe javascript plugin for WordPress
Gallery Widget
gallery-widget
Simple widget to show the latest/random images of the WordPress media library as a Widget, using a shortcode or directly with a php-function.
File Un-Attach Developer Profile
9 plugins · 12K total installs
How We Detect File Un-Attach
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/file-un-attach/css/file-unattach.css/wp-content/plugins/file-un-attach/js/file-unattach.js/wp-content/plugins/file-un-attach/js/file-unattach.min.js/wp-content/plugins/file-un-attach/js/file-unattach.js/wp-content/plugins/file-un-attach/js/file-unattach.min.jsfile-unattach/css/file-unattach.css?ver=file-unattach/js/file-unattach.js?ver=HTML / DOM Fingerprints
fun-attachattached-listfun-unattach-rowfun-find-postsid="attached-list-class="attached-list"id="file-unattch-class="fun-unattach-row"id="fun-find-posts-window.fun_wp_versionwindow.fun_max_upload_size