
WP Original Media Path Security & Risk Analysis
wordpress.org/plugins/wp-original-media-pathChange the location for the uploads folder for WordPress
Is WP Original Media Path Safe to Use in 2026?
Generally Safe
Score 100/100WP Original Media Path has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-original-media-path plugin v2.4.2 presents a generally positive security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good security practices with 100% of SQL queries using prepared statements and all identified outputs being properly escaped. The lack of file operations, external HTTP requests, and absence of critical taint flows are also strong indicators of a secure codebase in these areas.
However, a significant concern arises from the plugin's vulnerability history. The presence of one known CVE, even if currently patched and of medium severity, indicates that the plugin has had exploitable vulnerabilities in the past. The common vulnerability type being Cross-site Scripting also suggests that input validation and output sanitization, while appearing to be handled correctly in the current static analysis, may have been areas of weakness in previous versions. The fact that a vulnerability was discovered as recently as April 2023 warrants caution. While the current version appears to have addressed past issues, the history itself introduces a degree of risk that should not be overlooked.
In conclusion, while the static analysis of v2.4.2 shows a robustly coded plugin with minimal direct security flaws, the historical context of known vulnerabilities, particularly XSS, tempers this positive assessment. Users should remain vigilant and ensure they are always running the latest version of the plugin, as past issues could potentially re-emerge or new ones could be introduced.
Key Concerns
- Past vulnerability of medium severity
- Common vulnerability type: XSS
WP Original Media Path Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Original Media Path <= 2.4.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
WP Original Media Path Code Analysis
Output Escaping
WP Original Media Path Attack Surface
WordPress Hooks 8
Maintenance & Trust
WP Original Media Path Maintenance & Trust
Maintenance Signals
Community Trust
WP Original Media Path Alternatives
Upload Url and Path Enabler
upload-url-path-enabler
Get the media upload path and url setting fields back in WP 3.5+.
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
WP Extra File Types
wp-extra-file-types
Plugin to let you extend the list of allowed file types supported by the Wordpress Media Library
Easy SVG Support
easy-svg
This Plugin allows you to upload SVG Files into your Media library.
WP Original Media Path Developer Profile
3 plugins · 7K total installs
How We Detect WP Original Media Path
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-original-media-path/assets/wp-original-media-path.css/wp-content/plugins/wp-original-media-path/assets/wp-original-media-path.js/wp-content/plugins/wp-original-media-path/assets/wp-original-media-path.jswp-original-media-path.css?ver=wp-original-media-path.js?ver=