
FileBird – WordPress Media Library Folders & File Manager Security & Risk Analysis
wordpress.org/plugins/filebirdOrganize thousands of WordPress media files in folders / categories with ease.
Is FileBird – WordPress Media Library Folders & File Manager Safe to Use in 2026?
Generally Safe
Score 89/100FileBird – WordPress Media Library Folders & File Manager has a strong security track record. Known vulnerabilities have been patched promptly.
FileBird v6.5.2 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query preparation (81%) and output escaping (97%), significantly reducing the risk of common web vulnerabilities like SQL injection and XSS. The absence of bundled libraries and external HTTP requests also contributes to a more controlled environment. However, a notable concern is the presence of one unprotected AJAX handler, which represents a direct entry point without proper authentication checks, posing a potential risk for unauthorized actions.
The vulnerability history is a significant red flag. With 10 known CVEs, including one critical and nine medium severity issues, the plugin has a history of security weaknesses. While currently unpatched CVEs are zero, the recurring types of vulnerabilities (Missing/Improper Authorization, XSS, SQL Injection, Authorization Bypass) suggest persistent coding flaws or an inability to fully address certain security concerns. The taint analysis, though limited in scope, did identify one flow with an unsanitized path, which, if exploitable, could lead to security issues. The plugin's total attack surface is moderate, but the single unprotected entry point is a critical weakness.
Key Concerns
- Unprotected AJAX handler
- One flow with unsanitized path
- 1 critical CVE in history
- 9 medium CVEs in history
- Recurring authorization issues
- Recurring XSS issues
- Recurring SQL Injection issues
FileBird – WordPress Media Library Folders & File Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
FileBird – WordPress Media Library Folders & File Manager <= 6.5.1 - Missing Authorization to Authenticated (Author+) Global Folders Tampering
FileBird <= 6.4.9 - Improper Authorization to Authenticated (Author+) Settings Reset
FileBird – WordPress Media Library Folders & File Manager <= 6.4.8 - Authenticated (Author+) SQL Injection
Filebird <= 6.4.2.1 - Authenticated (Author+) Insecure Direct Object Reference
Filebird <= 6.3.2 - Missing Authorization
FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Stored Cross-Site Scripting
FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Insecure Direct Object Reference
FileBird <= 5.6.0 - Authenticated(Administrator+) Stored Cross-Site Scripting via Folder Import
Filebird <= 5.1.4 - Missing Authorization via resAdminPermissionsCheck
Filebird 4.7.3 - Unauthenticated SQL Injection
FileBird – WordPress Media Library Folders & File Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FileBird – WordPress Media Library Folders & File Manager Attack Surface
AJAX Handlers 4
WordPress Hooks 90
Scheduled Events 2
Maintenance & Trust
FileBird – WordPress Media Library Folders & File Manager Maintenance & Trust
Maintenance Signals
Community Trust
FileBird – WordPress Media Library Folders & File Manager Alternatives
Real Media Library: Media Library Folder & File Manager
real-media-library-lite
Organize uploaded media in folders, collections and galleries: A file manager for WordPress. Media management made easy with Real Media Library! (Alte …
Folderly
folderly
Organize your WordPress media library with folders. Drag & drop media files into folders, manage images, videos & documents efficiently.
Enhanced Media Library
enhanced-media-library
This plugin would be handy for those who need to manage a lot of media files.
Document Library Lite
document-library-lite
Create a WordPress document library to manage, search and download files.
WP Media folders
wp-media-folders
WP Media Folders is a media management plugin that: Implement a real folder and media URL structure & Allow WP Media Folder plugin data import
FileBird – WordPress Media Library Folders & File Manager Developer Profile
13 plugins · 496K total installs
How We Detect FileBird – WordPress Media Library Folders & File Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/filebird/assets/css/photoswipe/photoswipe.css/wp-content/plugins/filebird/assets/css/photoswipe/default-skin.css/wp-content/plugins/filebird/assets/js/photoswipe/photoswipe.min.js/wp-content/plugins/filebird/assets/js/photoswipe/photoswipe-ui-default.min.js/wp-content/plugins/filebird/assets/js/photoswipe/fbv-photoswipe.min.js/wp-content/plugins/filebird/blocks/filebird-gallery/init.phpfilebird/assets/css/photoswipe/photoswipe.css?ver=filebird/assets/css/photoswipe/default-skin.css?ver=filebird/assets/js/photoswipe/photoswipe.min.js?ver=filebird/assets/js/photoswipe/photoswipe-ui-default.min.js?ver=filebird/assets/js/photoswipe/fbv-photoswipe.min.js?ver=HTML / DOM Fingerprints
fbv-media-folder-rootnjfb-modal-contentfbv-folder-itemfbv-sidebarFileBird galleryFileBird Media Library FolderFileBird LiteFileBirddata-filebird-modaldata-njfb-modaldata-fbv-foldernjfb_plugin_urlnjfb_versionnjfb_rest_url/wp-json/filebird/v1/wp-json/filebird/public/v1