
Kontainer File Picker Security & Risk Analysis
wordpress.org/plugins/kontainer-file-pickerFile picker for Kontainer Dam and Pim platform
Is Kontainer File Picker Safe to Use in 2026?
Generally Safe
Score 100/100Kontainer File Picker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kontainer-file-picker" plugin v2.0.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and lack of file operations or external HTTP requests are significant strengths. Furthermore, the plugin has no recorded vulnerabilities or CVEs, indicating a history of stable and secure development. The attack surface, while present with AJAX and REST API endpoints, is fully protected by authentication and permission checks, which is a crucial good practice.
However, the static analysis does reveal some areas for improvement. A notable concern is the absence of nonce checks on AJAX handlers. While capability checks are present, nonces are vital for preventing Cross-Site Request Forgery (CSRF) attacks on these endpoints, especially if they perform any action. Additionally, a 30% rate of unescaped output, while not critical in isolation, presents a potential risk for Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is involved in these outputs. The analysis of taint flows shows no critical or high-severity issues, which is positive, but the limited number of flows analyzed (2) means this might not be exhaustive.
In conclusion, "kontainer-file-picker" v2.0.5 is a relatively secure plugin with a clean vulnerability history and a well-protected attack surface. The primary weaknesses lie in the missing nonce checks for AJAX endpoints and the percentage of unescaped output, which should be addressed to further harden the plugin against potential threats.
Key Concerns
- Missing nonce checks on AJAX handlers
- Unescaped output (30% of 30 outputs)
Kontainer File Picker Security Vulnerabilities
Kontainer File Picker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Kontainer File Picker Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 7
Maintenance & Trust
Kontainer File Picker Maintenance & Trust
Maintenance Signals
Community Trust
Kontainer File Picker Alternatives
Custom Upload Folder
custom-upload-folder
Upload files to custom directory in WordPress Media Library.
IntelligenceBank Connector
intelligencebank-connector
The IntelligenceBank Connector for WordPress.
B2 Private Files
b2-private-files
Serve token-protected files hosted in Backblaze B2 in your WordPress Site
Imageshop DAM Connector
imageshop-dam-connector
Cloud based DAM Solution
Phraseanet WordPress Client
phraseanet-client
This plugin creates the possibility to get and add assets from Phraseanet server into your Wordpress website.
Kontainer File Picker Developer Profile
1 plugin · 20 total installs
How We Detect Kontainer File Picker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kontainer-file-picker/assets/css/admin.css/wp-content/plugins/kontainer-file-picker/assets/js/admin.js/wp-content/plugins/kontainer-file-picker/assets/js/admin.jskontainer-file-picker/assets/css/admin.css?ver=kontainer-file-picker/assets/js/admin.js?ver=HTML / DOM Fingerprints
misc-pub-kontainerkontainer__padding-bottomkontainer__edit-linkdata-kontainer-file-iddata-kontainer-folder-iddata-kontainer-edit-urlkontainer_settings