
WP Encrypted Uploads Security & Risk Analysis
wordpress.org/plugins/wp-encrypted-uploadsShield your sensitive files with unbreakable encryption! 🛡️ Say goodbye to prying eyes and take full control of your private data.
Is WP Encrypted Uploads Safe to Use in 2026?
Generally Safe
Score 100/100WP Encrypted Uploads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-encrypted-uploads' v1.0.2 plugin exhibits a generally good security posture based on the provided static analysis. It utilizes prepared statements for all SQL queries and includes a nonce check for its sole AJAX handler, indicating an awareness of common WordPress security vulnerabilities. The absence of critical or high-severity taint flows and dangerous functions further supports this assessment. The plugin also has no recorded vulnerability history, which is a positive indicator of its historical stability. However, a notable concern is the lack of capability checks on its AJAX handler. While a nonce check provides some protection against CSRF attacks, an attacker could still leverage this entry point if they can bypass the nonce mechanism or if the functionality itself doesn't require specific user permissions. The relatively high number of file operations (19) warrants attention, though without specific details on their nature (e.g., read, write, delete, or path manipulation), it's difficult to assign a concrete risk. The partial output escaping (67%) suggests that a portion of the plugin's output may not be properly sanitized, potentially opening it up to cross-site scripting (XSS) vulnerabilities.
Key Concerns
- Missing capability checks on AJAX handler
- Partial output escaping (33% unescaped)
WP Encrypted Uploads Security Vulnerabilities
WP Encrypted Uploads Release Timeline
WP Encrypted Uploads Code Analysis
Output Escaping
WP Encrypted Uploads Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
WP Encrypted Uploads Maintenance & Trust
Maintenance Signals
Community Trust
WP Encrypted Uploads Alternatives
Prevent files / folders access
prevent-file-access
Prevent public access to WordPress files and folders. Protect downloads from public access, Role-based folder access, and User base folder access.
Bulk Media Register
bulk-media-register
Bulk register files on the server to the Media Library.
Overwrite Uploads
overwrite-uploads
Overwrites files with the same name and folder when uploading, instead of storing multiple copies with unique filenames.
WP Sanitize Accented Uploads
wp-sanitize-accented-uploads
Simple plugin which removes accented characters from uploaded files.
PeproDev CF7 Database
pepro-cf7-database
Reliable Solution to Save CF7 Submissions and Files, Works with CF7 v.5.9+
WP Encrypted Uploads Developer Profile
3 plugins · 30 total installs
How We Detect WP Encrypted Uploads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-encrypted-uploads/public/js/admin.js/wp-content/plugins/wp-encrypted-uploads/public/css/admin.css/wp-content/plugins/wp-encrypted-uploads/public/js/admin.jswp-encrypted-uploads/public/js/admin.js?ver=wp-encrypted-uploads/public/css/admin.css?ver=HTML / DOM Fingerprints
ANCENC