
Live Editor File Manager Security & Risk Analysis
wordpress.org/plugins/live-editor-file-managerBetter media management for WordPress. Upload, embed, and link to your files hosted on Live Editor directly in your WordPress site.
Is Live Editor File Manager Safe to Use in 2026?
Generally Safe
Score 85/100Live Editor File Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'live-editor-file-manager' plugin v0.5.7 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities or CVEs, which suggests a history of responsible development or limited public exposure of past issues. The static analysis also shows a complete absence of SQL queries that are not prepared, and all AJAX handlers have nonce checks, which are good practices for preventing common web attacks.
However, significant concerns arise from the static analysis. A critical finding is that 100% of output escaping is missing across 55 identified output points. This represents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content can be injected into the page without proper sanitization. Additionally, while capability checks are present on AJAX handlers (implied by '4 AJAX handlers (0 without auth checks)' and '4 Nonce checks'), the absence of explicit capability checks directly in the code, if that's what the static analysis implies by 'Capability checks: 0', is a weakness. The presence of file operations and external HTTP requests without detailed context on their handling also warrants caution. Taint analysis showing zero flows, while seemingly positive, could also indicate that the analysis depth was limited or the code structure did not lend itself to triggering the taint analysis engine.
In conclusion, the lack of historical vulnerabilities is a strength, but the pervasive lack of output escaping and potential gaps in robust authorization checks present a clear and present danger of XSS and potentially other injection-style attacks. The plugin needs immediate attention to address the unescaped outputs.
Key Concerns
- Missing output escaping on 100% of outputs
- Lack of explicit capability checks detected
Live Editor File Manager Security Vulnerabilities
Live Editor File Manager Code Analysis
Output Escaping
Live Editor File Manager Attack Surface
AJAX Handlers 4
WordPress Hooks 11
Maintenance & Trust
Live Editor File Manager Maintenance & Trust
Maintenance Signals
Community Trust
Live Editor File Manager Alternatives
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Media Cleaner: Clean your WordPress!
media-cleaner
Clean your WordPress! Eliminate unused and broken media files. For a faster, and better website.
FancyBox for WordPress
fancybox-for-wordpress
Seamlessly integrates FancyBox lightbox into your WordPress blog: Upload, activate, and you're done. Additional configuration optional.
Mixed Media Gallery Blocks
simply-gallery-block
Create mixed media galleries with images, HTML5 video, YouTube, Vimeo, and VideoPress — all in one gallery by Simply Gallery.
Live Editor File Manager Developer Profile
1 plugin · 10 total installs
How We Detect Live Editor File Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-editor-file-manager/stylesheets/styles.css/wp-content/plugins/live-editor-file-manager/javascripts/jquery.ba-postmessage.js/wp-content/plugins/live-editor-file-manager/javascripts/jquery.insertAtCaret.js/wp-content/plugins/live-editor-file-manager/javascripts/live-editor-file-manager-plugin.js/wp-content/plugins/live-editor-file-manager/javascripts/jquery.ba-postmessage.js/wp-content/plugins/live-editor-file-manager/javascripts/jquery.insertAtCaret.js/wp-content/plugins/live-editor-file-manager/javascripts/live-editor-file-manager-plugin.jslive-editor-file-manager/javascripts/jquery.ba-postmessage.js?ver=live-editor-file-manager/javascripts/jquery.insertAtCaret.js?ver=live-editor-file-manager/javascripts/live-editor-file-manager-plugin.js?ver=HTML / DOM Fingerprints
live-editor-activateddata-live-editor-activateddata-live-editor-subdomaindata-live-editor-admin-ajax-urldata-live-editor-post-typedata-live-editor-target-domaindata-live-editor-target-url+1 more/wp-json/live-editor-file-manager/v1/resources/wp-json/live-editor-file-manager/v1/resources/new/wp-json/live-editor-file-manager/v1/resources/imports/wp-json/live-editor-file-manager/v1/editor-code