
Files Addon for Event Espresso 4 Security & Risk Analysis
wordpress.org/plugins/files-addon-for-event-espresso-4Files add on plugin allows to create file upload type question which can be used in event registration form.
Is Files Addon for Event Espresso 4 Safe to Use in 2026?
Generally Safe
Score 85/100Files Addon for Event Espresso 4 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "files-addon-for-event-espresso-4" plugin v1.2.1 presents a significant security risk due to its unprotected attack surface. The plugin exposes two AJAX handlers without any authentication or capability checks. This means any user, including unauthenticated ones, could potentially trigger these handlers, leading to unintended actions or information disclosure depending on their implementation. The lack of any taint analysis results is concerning, as it suggests limited or no testing for flows that could lead to vulnerabilities like cross-site scripting or SQL injection, especially when combined with the fact that all SQL queries lack prepared statements and output is not properly escaped. The complete absence of known CVEs and past vulnerabilities is a positive indicator of past security efforts or perhaps a lack of targeted attacks, but it does not mitigate the immediate risks identified in the code analysis. Given the significant number of unprotected entry points and the absence of fundamental security measures like input validation and proper escaping, this plugin should be considered high-risk.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- Output not properly escaped
- No nonce checks on entry points
- No capability checks on entry points
Files Addon for Event Espresso 4 Security Vulnerabilities
Files Addon for Event Espresso 4 Release Timeline
Files Addon for Event Espresso 4 Code Analysis
SQL Query Safety
Output Escaping
Files Addon for Event Espresso 4 Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Files Addon for Event Espresso 4 Maintenance & Trust
Maintenance Signals
Community Trust
Files Addon for Event Espresso 4 Alternatives
Contact Me – Very Simple Contact Form
contact-me-very-simple-contact-form
Contact Me is a very simple contact form with uploading file option;
FileOrganizer – WordPress File Manager
fileorganizer
FileOrganizer is an intuitive file manager to easily edit, delete, upload, download, and manage all your WordPress files and folders right from the da …
Big File Uploads – Increase Maximum File Upload Size
tuxedo-big-file-uploads
Enable large file uploads in the built-in WordPress media uploader via file chunking, and set maximum upload file size to any value based on user role …
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
Drag and Drop Multiple File Upload for Contact Form 7
drag-and-drop-multiple-file-upload-contact-form-7
This simple plugin create Drag & Drop or choose Multiple File upload in your Confact Form 7 Forms.
Files Addon for Event Espresso 4 Developer Profile
1 plugin · 40 total installs
How We Detect Files Addon for Event Espresso 4
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/files-addon-for-event-espresso-4/css/admin-screen.css/wp-content/plugins/files-addon-for-event-espresso-4/js/admin-js.jsjs/admin-js.jsfiles-addon-for-event-espresso-4/css/admin-screen.css?ver=files-addon-for-event-espresso-4/js/admin-js.js?ver=HTML / DOM Fingerprints
ssa_var_ds