
File Manager, Code Editor, and Backup by Managefy Security & Risk Analysis
wordpress.org/plugins/softdiscover-db-file-managerManage your folder and files , backup, user roles and database easily
Is File Manager, Code Editor, and Backup by Managefy Safe to Use in 2026?
Generally Safe
Score 98/100File Manager, Code Editor, and Backup by Managefy has a strong security track record. Known vulnerabilities have been patched promptly.
The softdiscover-db-file-manager plugin v1.6.2 presents a mixed security posture. While it boasts no unprotected AJAX handlers or REST API routes, and includes nonce and capability checks on its entry points, several concerning signals emerge from the static analysis. The presence of the `exec` function is a significant red flag, as it can be exploited for remote code execution if not handled with extreme care. Furthermore, the low percentage of properly escaped output (5%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals a concerning number of flows with unsanitized paths, with three identified as high severity. This, coupled with the plugin's history of two medium-severity CVEs, one being 'Improper Limitation of a Pathname to a Restricted Directory' (Path Traversal), indicates a recurring weakness in path handling that could lead to unauthorized file access or manipulation. Although there are no currently unpatched CVEs, the past vulnerabilities and the identified path-related issues in the taint analysis are substantial risks that require immediate attention. The plugin's strength lies in its controlled entry points, but the inherent risks within its code execution and output handling, along with historical patterns, suggest a need for significant security improvements.
Key Concerns
- Dangerous function 'exec' found
- Low percentage of properly escaped output (5%)
- 3 high severity taint flows with unsanitized paths
- History of 2 medium CVEs (Path Traversal concern)
- File operations (34) without clear sanitization context
File Manager, Code Editor, and Backup by Managefy Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
File Manager, Code editor, backup by Managefy <= 1.6.1 - Unauthenticated Information Exposure
File Manager, Code Editor, and Backup by Managefy <= 1.4.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Download
File Manager, Code Editor, and Backup by Managefy Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
File Manager, Code Editor, and Backup by Managefy Attack Surface
AJAX Handlers 11
WordPress Hooks 24
Maintenance & Trust
File Manager, Code Editor, and Backup by Managefy Maintenance & Trust
Maintenance Signals
Community Trust
File Manager, Code Editor, and Backup by Managefy Alternatives
Lazy Backup
lazy-backup
Lazy Backup is a WordPress plugin for one-click database backups and file access from the admin dashboard.
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
File Manager
wp-file-manager
file manager provides you ability to edit, delete, upload, download, copy and paste files and folders.
Backuply – Backup, Restore, Migrate and Clone
backuply
Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …
File Manager, Code Editor, and Backup by Managefy Developer Profile
4 plugins · 480 total installs
How We Detect File Manager, Code Editor, and Backup by Managefy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/softdiscover-db-file-manager/assets/css/backend.css/wp-content/plugins/softdiscover-db-file-manager/assets/css/frontend.css/wp-content/plugins/softdiscover-db-file-manager/assets/js/backend.js/wp-content/plugins/softdiscover-db-file-manager/assets/js/frontend.js/wp-content/plugins/softdiscover-db-file-manager/assets/js/backend.js/wp-content/plugins/softdiscover-db-file-manager/assets/js/frontend.jssoftdiscover-db-file-manager/assets/css/backend.css?ver=softdiscover-db-file-manager/assets/css/frontend.css?ver=softdiscover-db-file-manager/assets/js/backend.js?ver=softdiscover-db-file-manager/assets/js/frontend.js?ver=HTML / DOM Fingerprints
flmbkp-admin-container<!-- Managefy version -->data-fmanager-urlflmbkp_admin_obj/wp-json/flmbkp/v1/get_settings/wp-json/flmbkp/v1/save_settings/wp-json/flmbkp/v1/get_files_list/wp-json/flmbkp/v1/create_file/wp-json/flmbkp/v1/delete_file/wp-json/flmbkp/v1/create_folder/wp-json/flmbkp/v1/delete_folder/wp-json/flmbkp/v1/upload_file/wp-json/flmbkp/v1/download_file/wp-json/flmbkp/v1/rename_file/wp-json/flmbkp/v1/rename_folder<a href="https://softdiscover.com/?mngfy_v=1.6.2" title="WordPress File Manager" >Managefy </a> version 1.6.2