
FileRenameReplace Security & Risk Analysis
wordpress.org/plugins/filerenamereplaceThis plugin let the user renaming or replacing files without breaking links.
Is FileRenameReplace Safe to Use in 2026?
Generally Safe
Score 85/100FileRenameReplace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "filerenamereplace" plugin version 1.0 exhibits a generally good security posture, largely due to the absence of known vulnerabilities and a lack of significant identified risks in static analysis. The plugin does not expose any AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, indicating a minimal attack surface. Furthermore, all SQL queries are properly prepared, and there are no identified taint flows with unsanitized paths or critical/high severities. This suggests a developer mindful of common web application security pitfalls.
However, a notable concern arises from the low percentage of properly escaped output (6%). With 17 total outputs, only about one is properly escaped, leaving a significant portion potentially vulnerable to Cross-Site Scripting (XSS) attacks if any user-supplied data is included in these unescaped outputs. The presence of file operations, while not inherently dangerous, warrants careful consideration given the lack of robust output escaping.
Given the plugin's history of zero recorded CVEs, it indicates a potentially stable and secure code base. Nevertheless, the significant lack of output escaping is a critical weakness that could be exploited. While the plugin appears to be strong in other areas, this specific oversight presents a clear area of risk that needs to be addressed.
Key Concerns
- Low percentage of properly escaped output
FileRenameReplace Security Vulnerabilities
FileRenameReplace Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FileRenameReplace Attack Surface
WordPress Hooks 6
Maintenance & Trust
FileRenameReplace Maintenance & Trust
Maintenance Signals
Community Trust
FileRenameReplace Alternatives
Replace & Rename Media Files
replace-rename-media
Replace existing media files, rename media files, and display file sizes in the WordPress media library.
Replace Image
replace-image
Upload a new version of an image without deleting the old image attachment, so that references to the image remain intact.
404 Image Redirection (Replace Broken Images)
broken-images-redirection
This plugin will help to replace broken images in posts and pages with a default image. Powerful & easy to use :)
PicDefense.io – Your Guard Against Image Copyright Infringement
picdefense-io-image-copyright-risk-checker
Compile list of images on your Wordpress site and submit to PicDefense.io for copyright risk analysis.
File Media Renamer for SEO
file-media-renamer-for-seo
Rename media files with SEO-friendly names, auto-update references, alt/title sync, and 301 redirects — fast and safe.
FileRenameReplace Developer Profile
2 plugins · 30 total installs
How We Detect FileRenameReplace
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/filerenamereplace/js/filerenamereplace-upload.jsHTML / DOM Fingerprints
misc-pub-file-meta-modifierdata-file-iddata-post-datedata-file-pathdata-file-namefileRenameReplaceGlobal