
File Uploader for WooCommerce Security & Risk Analysis
wordpress.org/plugins/file-uploader-for-woocommerceAllows to attach files from different sources to WooCommerce customer orders.
Is File Uploader for WooCommerce Safe to Use in 2026?
Generally Safe
Score 94/100File Uploader for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis for 'file-uploader-for-woocommerce' v1.0.4 presents a mixed security picture. On the positive side, the plugin demonstrates good security practices in several areas. There are no identified dangerous function uses, SQL queries are 100% prepared, and output escaping is at a high 94%. The presence of nonce and capability checks, along with the limited attack surface of 0 entry points, also suggests a deliberate effort towards secure coding. The taint analysis shows no flows with unsanitized paths, indicating no critical or high severity issues were found in the code's handling of data. However, a significant concern arises from the vulnerability history. The plugin has a known critical vulnerability of 'Unrestricted Upload of File with Dangerous Type', and importantly, this vulnerability was last recorded in the future (2025-12-19). While the current version might not have unpatched vulnerabilities listed, the historical pattern and the nature of the past critical vulnerability are serious red flags. The presence of the Guzzle library, if outdated, could also introduce a potential risk, though its current status isn't specified. The single file operation, while not inherently risky, warrants attention in conjunction with the history of upload-related vulnerabilities. In conclusion, while the current code scan shows positive security indicators like strong SQL sanitization and good output escaping, the historical critical vulnerability related to file uploads, coupled with its future date, demands extreme caution. This suggests a potential for recurring or unaddressed critical issues in past versions that could impact users if not meticulously managed and understood.
Key Concerns
- Known critical vulnerability (Unrestricted Upload)
- Future dated vulnerability in history
- Bundled library (Guzzle)
File Uploader for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
File Uploader for WooCommerce <= 1.0.3 - Unauthenticated Arbitrary File Upload via add-image-data
File Uploader for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
File Uploader for WooCommerce Attack Surface
WordPress Hooks 21
Maintenance & Trust
File Uploader for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
File Uploader for WooCommerce Alternatives
Easy Upload Files During Checkout
easy-upload-files-during-checkout
Attach files during checkout process on cart page with ease.
Grab Image From Remote URL
grab-image-from-remote-url
Allows you to download image from Remote URL to save Wordpress Media Gallery.
Web cam Addon for Contact Form 7
webcam-addon-for-contact-form-7
Webcam Addon for Contact Form 7 lets you capture an image from the user’s webcam (or phone camera) directly in your Contact Form 7 form and include th …
web-cam
web-cam
Web-cam is a simple but fantastic plugin that allows you to Click Photo from website and autometically upload in wp_media and return an id of that med …
Image Uploader Widget
easy-image-uploader
This is a search results in slider view with image plugin.
File Uploader for WooCommerce Developer Profile
1 plugin · 100 total installs
How We Detect File Uploader for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/file-uploader-for-woocommerce/dist/js/fileUploaderBlock.min.js/wp-content/plugins/file-uploader-for-woocommerce/dist/js/main.min.js/wp-content/plugins/file-uploader-for-woocommerce/dist/js/fileUploaderBlock.min.js/wp-content/plugins/file-uploader-for-woocommerce/dist/js/main.min.jswcu-free-woocommerce-file-uploader-editor-scriptwcu-free-woocommerce-file-uploader-styleHTML / DOM Fingerprints
wcu-add-to-cart-image-fieldTODO: Add logsdata-product-idwcu[file_uploader_block]