
Prevent files / folders access Security & Risk Analysis
wordpress.org/plugins/prevent-file-accessPrevent public access to WordPress files and folders. Protect downloads from public access, Role-based folder access, and User base folder access.
Is Prevent files / folders access Safe to Use in 2026?
Generally Safe
Score 97/100Prevent files / folders access has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'prevent-file-access' plugin v2.6.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage (98%) of output properly escaped. Nonce checks and capability checks are present, indicating an awareness of securing actions. However, concerns arise from the vulnerability history, which shows two known CVEs, one of which was a high-severity 'Path Traversal' vulnerability. Although no CVEs are currently unpatched, the past presence of such critical flaws, particularly in conjunction with two flows with unsanitized paths identified in the taint analysis, warrants caution. The file operations and external HTTP requests also represent potential areas for exploitation if not meticulously handled, even if no direct vulnerabilities were flagged in this analysis.
Key Concerns
- Past high-severity vulnerability (Path Traversal)
- Past medium-severity vulnerability
- Taint flows with unsanitized paths
- Multiple file operations
- Multiple external HTTP requests
Prevent files / folders access Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Prevent files / folders access <= 2.6.0 - Authenticated (Subscriber+) Path Traversal
Prevent files / folders access <= 2.5.1 - Authenticated (Administrator+) Arbitrary File Upload in mo_media_restrict_page
Prevent files / folders access Release Timeline
Prevent files / folders access Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Prevent files / folders access Attack Surface
WordPress Hooks 9
Maintenance & Trust
Prevent files / folders access Maintenance & Trust
Maintenance Signals
Community Trust
Prevent files / folders access Alternatives
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More
content-control
Restrict content based on login status, user roles, device type & more. Monetize your content with a paywall or members-only content.
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
paid-member-subscriptions
Feature-packed membership plugin for creating subscription plans, adding recurring payments & content restriction on your membership site.
Restrict User Access – Ultimate Membership & Content Protection
restrict-user-access
Create Access Levels and restrict any post, page, category, etc. Supports bbPress, BuddyPress, WooCommerce, WPML, and more.
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
s2member
❤️ Excellent membership plugin! Easy, quick, flexible. Monetize your site with memberships and subscriptions. Protect content instantly and securely.
Prevent files / folders access Developer Profile
41 plugins · 83K total installs
How We Detect Prevent files / folders access
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/prevent-file-access/css/admin.css/wp-content/plugins/prevent-file-access/js/admin.jsprevent-file-access/css/admin.css?ver=prevent-file-access/js/admin.js?ver=HTML / DOM Fingerprints
mo_media_restriction_wrapdata-noncewpMediaRestriction