
Shoot My File Security & Risk Analysis
wordpress.org/plugins/shoot-my-fileA private file transfer. Share files with users, collaborators or clients, directly from your WordPress site with a unique, time-limited link
Is Shoot My File Safe to Use in 2026?
Generally Safe
Score 100/100Shoot My File has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'shoot-my-file' plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and 99% of output properly escaped. The absence of known vulnerabilities and CVEs in its history further suggests a relatively stable and secure development past. The plugin also correctly implements nonce checks and capability checks on its entry points.
However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks. This creates a substantial attack surface that is exposed to unauthenticated users. While the taint analysis shows no critical or high severity flows, the lack of authorization on these AJAX endpoints is a serious weakness that could be exploited by attackers to trigger unintended functionality or access sensitive data if further vulnerabilities exist within those handlers. The plugin's attack surface is small, but the unprotected nature of its entry points is a notable risk.
In conclusion, while the plugin benefits from good internal coding practices and a clean vulnerability history, the unprotected AJAX endpoints represent a critical security flaw that needs immediate attention. This weakness overshadows the plugin's strengths and requires remediation to ensure a secure environment. Until these endpoints are properly secured, the plugin carries a considerable risk.
Key Concerns
- AJAX handlers without auth checks
- Unprotected AJAX endpoints
Shoot My File Security Vulnerabilities
Shoot My File Release Timeline
Shoot My File Code Analysis
SQL Query Safety
Output Escaping
Shoot My File Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Maintenance & Trust
Shoot My File Maintenance & Trust
Maintenance Signals
Community Trust
Shoot My File Alternatives
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
File Upload Types by WPForms
file-upload-types
Easily allow WordPress to accept and upload any file type extension or MIME type, including custom file types.
MultiLine Files for Contact Form 7
multiline-files-for-contact-form-7
Upload unlimited files to Contact Form 7 with an intuitive interface, file management, and automatic ZIP compression for email delivery.
File Uploads Addon for WooCommerce
woo-addon-uploads
Let customers upload files directly on your WooCommerce product page — no more chasing emails for artwork, logos, prescriptions, or documents.
Shared Files – File Upload & Download Manager
shared-files
File management plugin featuring file upload, download manager, statistics and download log.
Shoot My File Developer Profile
1 plugin · 0 total installs
How We Detect Shoot My File
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shoot-my-file/images/logo.png/wp-content/plugins/shoot-my-file/images/icon-16.png/wp-content/plugins/shoot-my-file/js/front.js/wp-content/plugins/shoot-my-file/js/back.jsshoot-my-file/css/front.css?ver=shoot-my-file/js/front.js?ver=shoot-my-file/css/back.css?ver=shoot-my-file/js/back.js?ver=HTML / DOM Fingerprints
shootmyfile_mainshootmyfile-titleshootmyfile-logoshootmyfileshootmyfile_back