
Files Inspector Security & Risk Analysis
wordpress.org/plugins/files-inspectorCompare files changes within wordpress.
Is Files Inspector Safe to Use in 2026?
Generally Safe
Score 85/100Files Inspector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "files-inspector" v0.1 plugin exhibits significant security concerns primarily due to its unprotected entry points and lack of robust input sanitization. The static analysis reveals three AJAX handlers, all of which lack authentication checks, presenting a direct attack vector. Furthermore, the plugin utilizes the dangerous `unserialize` function and performs all SQL queries without prepared statements, increasing the risk of deserialization vulnerabilities and SQL injection. The taint analysis highlights two flows with unsanitized paths, indicating potential for path traversal or other file system manipulation vulnerabilities. Although the plugin has no recorded vulnerability history, this does not negate the immediate risks identified in the code. The absence of capability checks and nonce verifications on AJAX actions further exacerbates these vulnerabilities, making it highly susceptible to unauthorized actions and potential compromise. While the plugin has a small attack surface and no external HTTP requests, these strengths are overshadowed by the critical security flaws.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function: unserialize
- SQL queries without prepared statements
- Taint flow with unsanitized path (critical)
- Taint flow with unsanitized path (critical)
- Output escaping is poorly implemented
- No nonce checks on AJAX
- No capability checks on AJAX
Files Inspector Security Vulnerabilities
Files Inspector Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Files Inspector Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
Files Inspector Maintenance & Trust
Maintenance Signals
Community Trust
Files Inspector Alternatives
Melapress File Monitor
website-file-changes-monitor
Get email alerts for file and permission changes on your WordPress sites. No false positives!
Lord of the Files: Enhanced Upload Security
blob-mimes
This plugin expands file-related security and sanity around the upload process.
Disable File Editor
disable-file-editor
This plugin will disable file editing tool in your WordPress admin panel.
Guard Dog Security & Site Lock
folder-auditor
Audit your site to keep WordPress clean and secure. Enable our one-of-a-kind SITE LOCK to give your site the ultimate security.
Random File Upload Names
random-file-upload-names
This plugin from WPZA provides your website randomised file names when you upload files into WordPress.
Files Inspector Developer Profile
1 plugin · 10 total installs
How We Detect Files Inspector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/files-inspector/assets/css/bootstrap.min.css/wp-content/plugins/files-inspector/assets/css/style.css/wp-content/plugins/files-inspector/assets/js/bootstrap.min.js/wp-content/plugins/files-inspector/assets/js/script.js/wp-content/plugins/files-inspector/assets/js/script.jsfiles-inspector/assets/css/style.css?ver=files-inspector/assets/js/script.js?ver=HTML / DOM Fingerprints
filesinspector-contentfilesinspector-compare-recordfilesinspector-main-content<!-- Files Inspector Plugin -->data-ajax-urlfilesInspectorSettings