Kontainer File Picker Security & Risk Analysis

wordpress.org/plugins/kontainer-file-picker

File picker for Kontainer Dam and Pim platform

20 active installs v2.0.5 PHP 7.4+ WP 5.2+ Updated Nov 12, 2025
assetsdamkontainermedia
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kontainer File Picker Safe to Use in 2026?

Generally Safe

Score 100/100

Kontainer File Picker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "kontainer-file-picker" plugin v2.0.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and lack of file operations or external HTTP requests are significant strengths. Furthermore, the plugin has no recorded vulnerabilities or CVEs, indicating a history of stable and secure development. The attack surface, while present with AJAX and REST API endpoints, is fully protected by authentication and permission checks, which is a crucial good practice.

However, the static analysis does reveal some areas for improvement. A notable concern is the absence of nonce checks on AJAX handlers. While capability checks are present, nonces are vital for preventing Cross-Site Request Forgery (CSRF) attacks on these endpoints, especially if they perform any action. Additionally, a 30% rate of unescaped output, while not critical in isolation, presents a potential risk for Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is involved in these outputs. The analysis of taint flows shows no critical or high-severity issues, which is positive, but the limited number of flows analyzed (2) means this might not be exhaustive.

In conclusion, "kontainer-file-picker" v2.0.5 is a relatively secure plugin with a clean vulnerability history and a well-protected attack surface. The primary weaknesses lie in the missing nonce checks for AJAX endpoints and the percentage of unescaped output, which should be addressed to further harden the plugin against potential threats.

Key Concerns

  • Missing nonce checks on AJAX handlers
  • Unescaped output (30% of 30 outputs)
Vulnerabilities
None known

Kontainer File Picker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kontainer File Picker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
9
21 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

70% escaped30 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
kontainer_save_settings (includes\kontainer-settings.php:242)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Kontainer File Picker Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_kontainer_generate_tokenincludes\kontainer-settings.php:219
authwp_ajax_kontainer_save_settingsincludes\kontainer-settings.php:240

REST API Routes 1

GET/wp-json/kontainer/file/usagesincludes\kontainer-rest-api.php:11
WordPress Hooks 7
actionrest_api_initincludes\kontainer-rest-api.php:10
actionadmin_menuincludes\kontainer-settings.php:21
actionadmin_initincludes\kontainer-settings.php:137
actionadmin_enqueue_scriptskontainer.php:33
actionadmin_post_custom_action_hookkontainer.php:58
actionadd_meta_boxeskontainer.php:171
filterattachment_fields_to_editkontainer.php:216
Maintenance & Trust

Kontainer File Picker Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Kontainer File Picker Developer Profile

Jesper Sandberg

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kontainer File Picker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kontainer-file-picker/assets/css/admin.css/wp-content/plugins/kontainer-file-picker/assets/js/admin.js
Script Paths
/wp-content/plugins/kontainer-file-picker/assets/js/admin.js
Version Parameters
kontainer-file-picker/assets/css/admin.css?ver=kontainer-file-picker/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
misc-pub-kontainerkontainer__padding-bottomkontainer__edit-link
Data Attributes
data-kontainer-file-iddata-kontainer-folder-iddata-kontainer-edit-url
JS Globals
kontainer_settings
FAQ

Frequently Asked Questions about Kontainer File Picker