
Media from ZIP Security & Risk Analysis
wordpress.org/plugins/media-from-zipExtract from ZIP archive to Media Library.
Is Media from ZIP Safe to Use in 2026?
Generally Safe
Score 100/100Media from ZIP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "media-from-zip" plugin v1.21 exhibits a strong security posture based on the provided static analysis. The absence of identifiable entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows a clean bill of health with no dangerous functions, no file operations, and no external HTTP requests. The presence of 100% properly escaped output is also a positive indicator of secure coding practices.
However, there are a few areas for consideration. The plugin has one SQL query that does not use prepared statements, which, while not a critical vulnerability in isolation, represents a potential risk for SQL injection if that query handles user-supplied data. The complete lack of nonce checks and capability checks across all entry points (even though there are none explicitly listed) is a significant concern. If any functionality were ever to be added that *did* have an entry point, the absence of these fundamental security checks would immediately expose it to various attacks.
The vulnerability history shows a completely clean record, with no known CVEs. This suggests a history of secure development or a lack of targeted exploitation. Despite the minor concern regarding the non-prepared SQL statement and the significant concern about the lack of any authentication/authorization checks on potential future entry points, the overall security assessment is relatively positive due to the limited attack surface and clean vulnerability history.
Key Concerns
- SQL query not using prepared statements
- Missing nonce checks on potential entry points
- Missing capability checks on potential entry points
Media from ZIP Security Vulnerabilities
Media from ZIP Release Timeline
Media from ZIP Code Analysis
SQL Query Safety
Media from ZIP Attack Surface
Maintenance & Trust
Media from ZIP Maintenance & Trust
Maintenance Signals
Community Trust
Media from ZIP Alternatives
ZIP from Media
zip-from-media
Compress from Media Library to ZIP archive.
Zippy
zippy
Incredibly easy solution to archive pages and posts as zip file and unpack them back even on the other website!
Archivarix External Images Importer
archivarix-external-images-importer
Import external images in posts and pages from external sources or Web Archive if original sources are not available anymore.
Export Media as ZIP
export-media-as-zip
Export images from your WordPress media library as a ZIP file — filter by year and image size before downloading.
Upload Media by Zip
upload-media-by-zip
Upload a zip archive and let WP unzip it and attach everything to a page/post (or not).
Media from ZIP Developer Profile
54 plugins · 56K total installs
How We Detect Media from ZIP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-from-zip/css/admin.css/wp-content/plugins/media-from-zip/js/admin.js/wp-content/plugins/media-from-zip/js/admin-bulk.js/wp-content/plugins/media-from-zip/js/media-from-zip.js/wp-content/plugins/media-from-zip/js/admin.js/wp-content/plugins/media-from-zip/js/admin-bulk.js/wp-content/plugins/media-from-zip/js/media-from-zip.jsmedia-from-zip/css/admin.css?ver=media-from-zip/js/admin.js?ver=media-from-zip/js/admin-bulk.js?ver=media-from-zip/js/media-from-zip.js?ver=HTML / DOM Fingerprints
mfz-adminmfz-bulk-importmfz-upload-formdata-mfz-noncedata-mfz-upload-urlmedia_from_zip_params/wp-json/media-from-zip/v1/upload