
Filr – Secure document library Security & Risk Analysis
wordpress.org/plugins/filr-protectionEasily Create a Secure Document Library with Filr
Is Filr – Secure document library Safe to Use in 2026?
Use With Caution
Score 62/100Filr – Secure document library has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'filr-protection' plugin v1.2.14 presents a mixed security posture. On the positive side, the static analysis indicates good practices with a high percentage of properly escaped output and 100% of SQL queries using prepared statements. Furthermore, all identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) appear to have authorization checks, and there are a reasonable number of nonce and capability checks. However, the presence of 2 flows with unsanitized paths in the taint analysis is a significant concern, even though they are not currently classified as critical or high severity. This suggests a potential for path traversal vulnerabilities if these flows are exploited by malicious input.
The plugin's vulnerability history is deeply concerning. With a total of 6 known CVEs and 1 currently unpatched, this indicates a recurring pattern of security weaknesses. The types of past vulnerabilities, including unrestricted file uploads, path traversal, XSS, code injection, and missing authorization, are all severe. The fact that a vulnerability was recorded as recently as February 2026 suggests a history of active security issues that may not have been fully addressed or a potential for future undisclosed vulnerabilities. While the current version shows improvements in some areas, the historical context elevates the overall risk significantly.
In conclusion, while the current version of 'filr-protection' v1.2.14 has made strides in implementing secure coding practices like prepared statements and output escaping, the persistent history of significant vulnerabilities and the presence of unsanitized path flows in the taint analysis are substantial red flags. The unpatched CVE, in particular, poses an immediate and serious risk. Users should exercise extreme caution and consider the plugin's past performance when evaluating its security.
Key Concerns
- Currently unpatched CVE
- Flows with unsanitized paths found
- Bundled Freemius v1.0 library
- History of 6 CVEs
Filr – Secure document library Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Filr – Secure document library <= 1.2.13 - Authenticated (Contributor+) Arbitrary File Uploads
Filr – Secure document library <= 1.2.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via HTML Upload
Filr <= 1.2.10 - Authenticated (Contributor+) Arbitrary File Deletion
Filr – Secure document library <= 1.2.4 - Authenticated (Editor+) Stored Cross-Site Scripting
Filr – Secure document library <= 1.2.3.5 - Authenticated (Author+) Arbitrary File Upload
Filr – Secure document library <= 1.2.2 - Missing Authorization
Filr – Secure document library Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Filr – Secure document library Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 23
Scheduled Events 1
Maintenance & Trust
Filr – Secure document library Maintenance & Trust
Maintenance Signals
Community Trust
Filr – Secure document library Alternatives
Document Library Lite
document-library-lite
Create a WordPress document library to manage, search and download files.
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
file-manager-advanced
Use Advanced File Manager to manage WordPress files, create archives, and build document libraries—all directly from your WordPress dashboard!
Download Manager Addons for Elementor
wpdm-elementor
Download Manager Addons for Elementor
Document Gallery – Display PDF Gallery from Many Folders
catfolders-document-gallery
Display WordPress PDF gallery and file gallery from folder. Comes with a clean, searchable & sortable list/grid layout.
Filr – Secure document library Developer Profile
29 plugins · 440K total installs
How We Detect Filr – Secure document library
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/filr-protection/assets/filr-admin.css/wp-content/plugins/filr-protection/assets/filr-admin.js/wp-content/plugins/filr-protection/assets/font/font-fileuploader.min.css/wp-content/plugins/filr-protection/assets/jquery.fileuploader.min.css/wp-content/plugins/filr-protection/assets/jquery.fileuploader.min.js/wp-content/plugins/filr-protection/assets/filr-admin.jsver=1.2.14HTML / DOM Fingerprints
filr-container<!-- FILR SHORTCODE START --><!-- FILR SHORTCODE END -->data-filr-iddata-filr-post-iddata-filr-user-iddata-filr-securityfilr_ajax_object[filr_display_files]