
FileBird Document Library Security & Risk Analysis
wordpress.org/plugins/filebird-document-libraryCreate WordPress document library using FileBird and Gutenberg or any WordPress page builder.
Is FileBird Document Library Safe to Use in 2026?
Generally Safe
Score 99/100FileBird Document Library has a strong security track record. Known vulnerabilities have been patched promptly.
The filebird-document-library v3.0.8 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with only one shortcode and no unprotected entry points. There are no identified dangerous functions, file operations, or external HTTP requests, which are good indicators of secure coding practices in those areas. Furthermore, the plugin has 0 currently unpatched CVEs, which is a strong positive sign. The high percentage of properly escaped output is also commendable.
However, there are several areas of concern. The presence of a single SQL query that is not using prepared statements is a significant risk. While the taint analysis found no critical or high severity flows, the fact that 100% of SQL queries are not prepared means there's a potential for SQL injection vulnerabilities if user input is directly incorporated into this query. The complete absence of nonce checks across all entry points is another critical weakness. While the single shortcode has a capability check, relying solely on capability checks without nonces leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks.
The vulnerability history shows one medium severity CVE for Exposure of Sensitive Information to an Unauthorized Actor, which was recently patched. This indicates a past weakness that, while resolved, highlights the plugin's susceptibility to certain types of attacks. The overall conclusion is that while the plugin has a small attack surface and good output escaping, the lack of prepared statements for SQL and the absence of nonce checks are critical security flaws that significantly increase its risk profile.
Key Concerns
- Raw SQL query without prepared statements
- No nonce checks on entry points
FileBird Document Library Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
FileBird Document Library <= 2.0.6 - Unauthenticated Sensitive Information Exposure
FileBird Document Library Code Analysis
SQL Query Safety
Output Escaping
FileBird Document Library Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
FileBird Document Library Maintenance & Trust
Maintenance Signals
Community Trust
FileBird Document Library Alternatives
Simple File List
simple-file-list
Simple File List gives your WordPress website a list of your files which allows your users to open and download them.
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files
embed-any-document
Embed PDF, DOC, PPT and XLS documents easily on your WordPress website with the help of Google Docs Viewer or Microsoft Office Online.
Download Manager Addons for Elementor
wpdm-elementor
Download Manager Addons for Elementor
Card Elements for Elementor
card-elements-for-elementor
Showcase useful elements with card style for elementor page builder.
Document Gallery – Display PDF Gallery from Many Folders
catfolders-document-gallery
Display WordPress PDF gallery and file gallery from folder. Comes with a clean, searchable & sortable list/grid layout.
FileBird Document Library Developer Profile
13 plugins · 496K total installs
How We Detect FileBird Document Library
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/filebird-document-library/blocks/dist/index.js/wp-content/plugins/filebird-document-library/blocks/dist/index.css/wp-content/plugins/filebird-document-library/blocks/dist/frontend.js/wp-content/plugins/filebird-document-library/blocks/dist/index.js/wp-content/plugins/filebird-document-library/blocks/dist/frontend.jsfilebird-document-library/blocks/dist/index.js?ver=filebird-document-library/blocks/dist/frontend.js?ver=filebird-document-library/blocks/dist/index.css?ver=HTML / DOM Fingerprints
njt-fbdldata-jsonfbdl/wp-json/njfb/v1/get-attachments<div id="filebird-document-library"><div class="njt-fbdl" data-json=