MediaCommander – Bring Folders to Media, Posts, and Pages Security & Risk Analysis

wordpress.org/plugins/mediacommander

Take control of your data with our folder manager - organize your WordPress media library, posts, and pages into specific categories with ease.

40 active installs v2.4.1 PHP 7.4+ WP 6.0+ Updated Jan 26, 2026
file-managermedia-foldermedia-librarymedia-library-categoriesmedia-library-folders
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 12, 2025
Safety Verdict

Is MediaCommander – Bring Folders to Media, Posts, and Pages Safe to Use in 2026?

Generally Safe

Score 99/100

MediaCommander – Bring Folders to Media, Posts, and Pages has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 12, 2025Updated 2mo ago
Risk Assessment

The `mediacommander` plugin v2.4.1 exhibits a generally strong security posture with several good practices in place. The plugin demonstrates a high adherence to using prepared statements for SQL queries and properly escaping output, which significantly mitigates common web vulnerabilities. The static analysis shows no critical or high-severity taint flows, and the absence of a large attack surface with unprotected entry points is commendable.

However, there are notable areas of concern. The complete lack of nonce checks across all entry points is a significant security gap, especially considering the plugin has a history of vulnerabilities. The presence of a medium-severity CVE in its history, even if currently patched, coupled with the absence of nonce checks, suggests a potential for authorization bypass or similar issues. Furthermore, the inclusion of a bundled library, Freemius v1.0, without explicit versioning information in the provided data, raises a mild concern about potential outdated dependencies, which can sometimes carry their own vulnerabilities.

In conclusion, while `mediacommander` has made strides in secure coding practices regarding SQL and output handling, the oversight in implementing nonce checks and its past vulnerability history necessitate caution. The plugin's strengths lie in its core data handling, but its attack surface, though currently appearing small, could be more robustly protected against potential exploitation, particularly given its historical security events.

Key Concerns

  • No nonce checks found
  • Medium severity CVE in history
  • Bundled Freemius v1.0 library
Vulnerabilities
1

MediaCommander – Bring Folders to Media, Posts, and Pages Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-14508medium · 6.5Missing Authorization

MediaCommander – Bring Folders to Media, Posts, and Pages <= 2.3.1 - Missing Authorization to Authenticated (Author+) Media Folder Deletion

Dec 12, 2025 Patched in 2.4.0 (1d)
Code Analysis
Analyzed Mar 16, 2026

MediaCommander – Bring Folders to Media, Posts, and Pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
128 prepared
Unescaped Output
1
65 escaped
Nonce Checks
0
Capability Checks
12
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

98% prepared131 total queries

Output Escaping

98% escaped66 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
addAttachment (includes\System\Folders.php:230)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MediaCommander – Bring Folders to Media, Posts, and Pages Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 28
actioninitincludes\Blocks\GalleryBlock.php:10
actionadmin_noticesincludes\Fallbacks\plugin-exist.php:5
actionplugins_loadedincludes\Plugin.php:8
actionrest_api_initincludes\Rest\Routes.php:8
actioninitincludes\System\Folders.php:15
filtermedia_library_infinite_scrollingincludes\System\Folders.php:21
actionedit_attachmentincludes\System\Folders.php:25
filterattachment_fields_to_editincludes\System\Folders.php:26
filterwp_prepare_attachment_for_jsincludes\System\Folders.php:30
actionadmin_enqueue_scriptsincludes\System\Folders.php:33
actionfusion_enqueue_live_scriptsincludes\System\Folders.php:35
actionelementor/editor/before_enqueue_scriptsincludes\System\Folders.php:37
actionbrizy_editor_enqueue_scriptsincludes\System\Folders.php:39
actionwp_enqueue_scriptsincludes\System\Folders.php:41
actiondelete_postincludes\System\Folders.php:44
actionadd_attachmentincludes\System\Folders.php:45
filterposts_clausesincludes\System\Folders.php:46
filterpre_user_queryincludes\System\Folders.php:47
actionadmin_headincludes\System\Folders.php:71
actioninitincludes\System\Notice.php:8
actionadmin_noticesincludes\System\Notice.php:12
actionadmin_enqueue_scriptsincludes\System\Notice.php:13
actioninitincludes\System\Settings.php:13
actionadmin_menuincludes\System\Settings.php:17
actionin_admin_headerincludes\System\Settings.php:18
actionadmin_initmediacommander.php:21
filterpricing/show_annual_in_monthlymediacommander.php:72
filterplugin_iconmediacommander.php:73
Maintenance & Trust

MediaCommander – Bring Folders to Media, Posts, and Pages Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

MediaCommander – Bring Folders to Media, Posts, and Pages Developer Profile

Yalogica

11 plugins · 110 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect MediaCommander – Bring Folders to Media, Posts, and Pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mediacommander/assets/vendor/cookie/cookie.js/wp-content/plugins/mediacommander/assets/vendor/url/url.js/wp-content/plugins/mediacommander/assets/vendor/overlayscrollbars/overlayscrollbars.css/wp-content/plugins/mediacommander/assets/vendor/overlayscrollbars/overlayscrollbars.js/wp-content/plugins/mediacommander/assets/css/colorpicker.css
Version Parameters
mediacommander-cookiemediacommander-urlmediacommander-overlayscrollbarsmediacommander-colorpicker

HTML / DOM Fingerprints

CSS Classes
mediacommander-replace-media
Data Attributes
data-attachment-id
JS Globals
MEDIACOMMANDER.APP.fn.replacemedia.open
REST Endpoints
mediacommander/v1
FAQ

Frequently Asked Questions about MediaCommander – Bring Folders to Media, Posts, and Pages