
Filestack Security & Risk Analysis
wordpress.org/plugins/filepicker-media-uploaderUse Filestack to upload files directly from Facebook, Instagram, Google Images and more for your WordPress site, without ever leaving WordPress.
Is Filestack Safe to Use in 2026?
Use With Caution
Score 63/100Filestack has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The static analysis of filepicker-media-uploader v2.0.8 reveals an exceptionally clean codebase, with no identified dangerous functions, SQL injection vulnerabilities, unescaped output, file operations, or external HTTP requests. The absence of any identified taint flows further reinforces this positive picture, indicating that data handled by the plugin is likely processed securely. Furthermore, the plugin boasts zero entry points that lack authentication checks and no shortcodes, cron events, or REST API routes that bypass permission callbacks, which is a strong indicator of good security design.
However, the plugin's vulnerability history presents a significant concern. The presence of one unpatched medium-severity CVE, specifically related to Cross-site Scripting (XSS), overshadows the otherwise robust static analysis. This indicates a potential for attackers to exploit this known flaw to inject malicious scripts, leading to compromised user sessions or data theft. The recency of this last vulnerability further underscores the immediate need for attention.
In conclusion, while filepicker-media-uploader v2.0.8 demonstrates excellent secure coding practices in its static analysis, the existence of an unpatched XSS vulnerability is a critical weakness that poses a real risk to users. The plugin's strengths lie in its secure handling of data and limited attack surface, but the unpatched vulnerability necessitates immediate action to mitigate potential exploitation.
Key Concerns
- Unpatched medium severity CVE
Filestack Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Filestack <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Filestack Code Analysis
Filestack Attack Surface
Maintenance & Trust
Filestack Maintenance & Trust
Maintenance Signals
Community Trust
Filestack Alternatives
No alternatives data available yet.
Filestack Developer Profile
2 plugins · 40 total installs
How We Detect Filestack
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/filepicker-media-uploader/css/style.css/wp-content/plugins/filepicker-media-uploader/css/wp_media.css/wp-content/plugins/filepicker-media-uploader/js/filepicker.js/wp-content/plugins/filepicker-media-uploader/js/filepicker_wp_media.js/wp-content/plugins/filepicker-media-uploader/js/jquery.filepicker.js/wp-content/plugins/filepicker-media-uploader/js/filepicker.js/wp-content/plugins/filepicker-media-uploader/js/filepicker_wp_media.js/wp-content/plugins/filepicker-media-uploader/js/jquery.filepicker.jsfilepicker-media-uploader/css/style.css?ver=filepicker-media-uploader/css/wp_media.css?ver=filepicker-media-uploader/js/filepicker.js?ver=filepicker-media-uploader/js/filepicker_wp_media.js?ver=filepicker-media-uploader/js/jquery.filepicker.js?ver=HTML / DOM Fingerprints
filepicker-upload-buttonfilepicker-media-upload-formfilepicker-media-previewfilepicker-media-inputdata-fp-apikeydata-fp-button-textdata-fp-button-classdata-fp-containerdata-fp-multi-selectdata-fp-modal+16 morewindow.Filepicker/wp-json/filepicker/v1/upload[filepicker]