Media Folders Lite Security & Risk Analysis

wordpress.org/plugins/media-folders-lite

Upload files to custom folders in WP Media Library.

200 active installs v1.0.2 PHP + WP 5.0+ Updated May 5, 2024
directoriesdirectoryfoldersmediaupload
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Media Folders Lite Safe to Use in 2026?

Generally Safe

Score 92/100

Media Folders Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, "media-folders-lite" v1.0.2 exhibits a strong security posture regarding typical WordPress plugin vulnerabilities. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, combined with the lack of detected dangerous functions, SQL injection risks, and external HTTP requests, suggests a well-contained plugin. The 100% use of prepared statements for SQL queries and proper output escaping further bolsters confidence in its defense against common attack vectors. Furthermore, the complete lack of known CVEs and recorded vulnerability history indicates a history of secure development or effective patching.

However, there are specific areas that, while not indicating immediate critical risks based on the data, warrant careful consideration for a truly robust security profile. The complete absence of nonce checks and capability checks across all entry points is a significant concern, even with a seemingly limited attack surface. Any future introduction of new entry points or an increase in complexity could expose the plugin to serious authorization and CSRF vulnerabilities. The single file operation, while not explicitly flagged as problematic, should be closely monitored for any potential path traversal or insecure handling, especially if it involves user-supplied input. The lack of taint analysis results is noted; while this may mean no issues were found, a comprehensive taint analysis could uncover deeper vulnerabilities. Overall, the plugin is in a good state, but the oversight in authorization checks is a notable weakness.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Single file operation, potential for insecure handling
Vulnerabilities
None known

Media Folders Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Media Folders Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped18 total outputs
Attack Surface

Media Folders Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionadmin_noticesincludes\build.php:10
filterplugin_row_metaincludes\build.php:16
filteradmin_footer_textincludes\build.php:19
actionadmin_enqueue_scriptsincludes\build.php:22
actionpre-upload-uiincludes\build.php:25
filtermanage_media_columnsincludes\build.php:28
actionmanage_media_custom_columnincludes\build.php:33
actionadmin_initincludes\build.php:41
actionwp_enqueue_mediaincludes\filter.php:10
filterwp_handle_upload_prefilterincludes\folders.php:10
filterupload_dirincludes\folders.php:11
filterwp_handle_uploadincludes\folders.php:16
actionupdate_option_mediafolders_optionincludes\folders.php:22
actioninitincludes\select.php:10
actionenqueue_block_editor_assetsincludes\select.php:13
actionadmin_footerincludes\select.php:16
actioninitincludes\taxonomy.php:10
actionadd_attachmentincludes\taxonomy.php:13
actionadmin_initincludes\taxonomy.php:29
actionadmin_initincludes\taxonomy.php:32
actioninitmedia-folders.php:34
Maintenance & Trust

Media Folders Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 5, 2024
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Media Folders Lite Developer Profile

jbulies

1 plugin · 200 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Media Folders Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/media-folders-lite/assets/css/style.css/wp-content/plugins/media-folders-lite/assets/js/filter.js

HTML / DOM Fingerprints

CSS Classes
mediafolders-select-titlemediafolders-select-jsmediafolders-img-jsmediafolders-rating-link
Data Attributes
mediafolders_option
JS Globals
MediaLibraryTaxonomyFilterData
FAQ

Frequently Asked Questions about Media Folders Lite