
Manage Upload Types Security & Risk Analysis
wordpress.org/plugins/manage-upload-typesThis plugin adds a panel to the Settings->Media page, enabling changes to the file types which are permitted to be uploaded to the media library.
Is Manage Upload Types Safe to Use in 2026?
Generally Safe
Score 85/100Manage Upload Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'manage-upload-types' plugin v1.3 exhibits a generally positive security posture with no recorded vulnerabilities or identified taint flows. The static analysis indicates robust practices in several key areas, notably the absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the presence of nonce checks on its two AJAX entry points. This suggests a developer conscious of common attack vectors like SQL injection and cross-site request forgery.
However, a significant concern arises from the complete lack of output escaping. With three identified output points, the absence of proper escaping presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface that originates from user input or external sources, without sanitization, could be exploited. Additionally, the plugin lacks capability checks on its AJAX handlers, meaning any authenticated user, regardless of their role, could potentially trigger these functions, increasing the attack surface if these handlers have sensitive operations.
While the vulnerability history is clean, suggesting a currently secure implementation, the identified code signals point to critical areas that require immediate attention. The combination of unescaped output and the absence of capability checks on entry points represents the most pressing risks. Addressing these would greatly strengthen the plugin's overall security.
Key Concerns
- Output escaping is missing
- AJAX handlers lack capability checks
Manage Upload Types Security Vulnerabilities
Manage Upload Types Code Analysis
Output Escaping
Manage Upload Types Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Manage Upload Types Maintenance & Trust
Maintenance Signals
Community Trust
Manage Upload Types Alternatives
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
WP Extra File Types
wp-extra-file-types
Plugin to let you extend the list of allowed file types supported by the Wordpress Media Library
Easy SVG Support
easy-svg
This Plugin allows you to upload SVG Files into your Media library.
Media Sync
media-sync
Simple plugin to scan "uploads" directory and bring those files into Media Library.
Manage Upload Types Developer Profile
1 plugin · 500 total installs
How We Detect Manage Upload Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/manage-upload-types/css/jm_mut.css/wp-content/plugins/manage-upload-types/js/jm_mut.jsmanage-upload-types/js/jm_mut.js?ver=manage-upload-types/css/jm_mut.css?ver=HTML / DOM Fingerprints
jm_mut_mimetypes_tablejm_mut_mimetype_thtrjm_mut_mimetype_trjm_mut_extension_tdjm_mut_mimetype_tdjm_mut_delete_tdjm_mut_add_extensionjm_mut_add_mimetype+2 moreid="jm_mut_mimetypes_table"id="jm_mut_add_extension"id="jm_mut_add_mimetype"id="jm_mut_add_button"onclickJmMut/wp-json/jm-mut-delete-type/wp-json/jm-mut-add-type