
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Security & Risk Analysis
wordpress.org/plugins/foldersCreate unlimited folders with the Folders WordPress plugin, organize & manage your Media Library files, Pages & Posts in folders 📁
Is Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Safe to Use in 2026?
Generally Safe
Score 89/100Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager has a strong security track record. Known vulnerabilities have been patched promptly.
The 'folders' v3.1.6 plugin exhibits a mixed security posture. While it demonstrates several good security practices, such as a high percentage of prepared SQL statements and properly escaped output, significant concerns remain. The static analysis reveals a notable attack surface with 38 AJAX handlers, two of which lack authorization checks, presenting a direct avenue for potential unauthorized actions. The taint analysis, though limited in scope with only 8 flows, identified 3 flows with unsanitized paths, indicating potential risks of insecure handling of user-provided data, even if no critical or high severity vulnerabilities were immediately flagged by this specific analysis.
The plugin's vulnerability history is a more substantial cause for concern. With a total of 6 known CVEs, including 2 high and 4 medium severity vulnerabilities in the past, it suggests a recurring pattern of security weaknesses. The common vulnerability types like Missing Authorization, Incorrect Authorization, Cross-site Scripting, and Unrestricted Upload indicate that the plugin has struggled with fundamental security implementations. Although there are currently no unpatched CVEs, the historical prevalence of these types of vulnerabilities necessitates careful scrutiny.
In conclusion, while the current version of 'folders' v3.1.6 shows improvements in areas like SQL prepared statements and output escaping, the presence of unprotected AJAX endpoints and a history of significant vulnerabilities, particularly those related to authorization and input sanitization, indicate that the plugin still carries a moderate to high risk. Continued vigilance and prompt patching of any future disclosed vulnerabilities are strongly advised.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
- High number of known CVEs (6 total)
- Previous high severity CVEs (2)
- Previous medium severity CVEs (4)
- Common vulnerability types (auth, XSS, upload)
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 - Missing Authorization to Authenticated (Author+) Media Replacement
Folders <= 3.1.5 - Incorrect Authorization to Authenticated (Contributor+) Folder Content Manipulation
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG File Upload
Folders Pro <= 3.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via User First Name and Last Name
Folders <= 2.9.2 - Authenticated (Author+) Arbitrary File Upload in handle_folders_file_upload
Folders <= 2.9.2 - Authenticated (Author+) Arbitrary File Upload
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Attack Surface
AJAX Handlers 38
WordPress Hooks 82
Maintenance & Trust
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Maintenance & Trust
Maintenance Signals
Community Trust
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Alternatives
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
Real Media Library: Media Library Folder & File Manager
real-media-library-lite
Organize uploaded media in folders, collections and galleries: A file manager for WordPress. Media management made easy with Real Media Library! (Alte …
Enhanced Media Library
enhanced-media-library
This plugin would be handy for those who need to manage a lot of media files.
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types
wicked-folders
Organize your pages, posts, and custom post types into folders. Upgrade to pro for media library folders, WooCommerce integration, and more.
Media Library Organizer – WordPress Media Library Folders & File Manager
media-library-organizer
Create unlimited Media Library folders and subfolders to organize your files. Export Media Library folders, set default attributes & more.
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Developer Profile
9 plugins · 651K total installs
How We Detect Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/folders/css/folders.css/wp-content/plugins/folders/css/folders.grid.css/wp-content/plugins/folders/css/folders.styles.css/wp-content/plugins/folders/js/folders.js/wp-content/plugins/folders/js/folders.tree.js/wp-content/plugins/folders/js/folders.media.js/wp-content/plugins/folders/js/folders.posts.js/wp-content/plugins/folders/js/folders.pages.js+3 more/wp-content/plugins/folders/js/folders.js/wp-content/plugins/folders/js/folders.tree.js/wp-content/plugins/folders/js/folders.media.js/wp-content/plugins/folders/js/folders.posts.js/wp-content/plugins/folders/js/folders.pages.js/wp-content/plugins/folders/js/folders.tags.js+2 morefolders/style.css?ver=folders/grid.css?ver=folders/styles.css?ver=folders/folders.js?ver=folders/folders.tree.js?ver=folders/folders.media.js?ver=folders/folders.posts.js?ver=folders/folders.pages.js?ver=folders/folders.tags.js?ver=folders/folders.taxonomies.js?ver=folders/folders.media.replace.js?ver=HTML / DOM Fingerprints
folders-treefolders-tree-branchfolders-tree-leaffolders-tree-selectedfolders-gridfolders-grid-itemfolders-grid-selectedfolders-create-folder+6 more<!-- Folders Tree --><!-- Folders Grid --><!-- Create Folder Form --><!-- Rename Folder Form -->+1 moredata-folder-iddata-parent-iddata-folder-namedata-item-iddata-item-typeWCP_FOLDERS_PLUGIN_URLWCP_FOLDERS_PLUGIN_PATHfolders_tree_objectfolders_media_objectfolders_posts_objectfolders_pages_object+3 more/wp-json/folders/v1/get-folders/wp-json/folders/v1/create-folder/wp-json/folders/v1/rename-folder/wp-json/folders/v1/delete-folder/wp-json/folders/v1/move-item/wp-json/folders/v1/get-items