
WPIDE – File Manager & Code Editor Security & Risk Analysis
wordpress.org/plugins/wpideWPIDE is a powerful file manager and code editor for WordPress with tabs, code completion, and full access to the entire wp-content folder.
Is WPIDE – File Manager & Code Editor Safe to Use in 2026?
Generally Safe
Score 95/100WPIDE – File Manager & Code Editor has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wpide v3.5.3 plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query handling and includes a reasonable number of nonce and capability checks, significant concerns arise from its attack surface and historical vulnerability patterns. The presence of one unprotected AJAX handler is a direct entry point for potential attacks, even without further taint analysis revealing specific malicious flows. This unprotected entry point is particularly worrying given the plugin's history. The plugin has a notable track record of four previously disclosed CVEs, with two high and two medium severity vulnerabilities. These historical issues, including path traversal, unrestricted uploads, and PHP remote file inclusion, indicate a recurring struggle with input validation and access control. Although there are currently no unpatched CVEs, the historical prevalence of critical vulnerability types suggests a potential for future undiscovered or reintroduced vulnerabilities if underlying coding practices are not rigorously improved. The bundled Freemius v1.0 library, while not explicitly flagged as outdated or vulnerable in the provided data, warrants attention as outdated bundled libraries can introduce risks.
Key Concerns
- Unprotected AJAX handler
- Multiple high severity past CVEs
- Multiple medium severity past CVEs
- Vulnerability history (Path Traversal, RFI)
- Moderate percentage of unescaped output
- Bundled library (Freemius v1.0)
WPIDE – File Manager & Code Editor Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WPIDE <= 3.4.9 - Unauthenticated Full Path Dislcosure
WPide <= 2.6 - Authenticated (Administrator+) Arbitrary File Read
WPide <= 2.6 - Authenticated (Administrator+) Arbitrary File Upload
WPIDE – File Manager & Code Editor <= 2.6 - Authenticated (Admininstrator+) Local File Inclusion
WPIDE – File Manager & Code Editor Release Timeline
WPIDE – File Manager & Code Editor Code Analysis
Bundled Libraries
Output Escaping
WPIDE – File Manager & Code Editor Attack Surface
AJAX Handlers 1
WordPress Hooks 36
Maintenance & Trust
WPIDE – File Manager & Code Editor Maintenance & Trust
Maintenance Signals
Community Trust
WPIDE – File Manager & Code Editor Alternatives
WP Editor
wp-editor
WP Editor is a plugin for WordPress that replaces the default plugin and theme editors as well as the page/post editor.
Disable Theme and Plugin Editor
disable-theme-and-plugin-editor
Disable Theme and Plugin Editors from WordPress Admin Panel for security reasons
Enable Theme and Plugin Editor (WPMU)
enable-theme-and-plugin-editor
Allows to enable theme and plugin editor for site administrator in WordPress MU.
File Manager
wp-file-manager
file manager provides you ability to edit, delete, upload, download, copy and paste files and folders.
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
WPIDE – File Manager & Code Editor Developer Profile
6 plugins · 47K total installs
How We Detect WPIDE – File Manager & Code Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpide/app/public/css/styles.css/wp-content/plugins/wpide/app/public/js/vendors.js/wp-content/plugins/wpide/app/public/js/app.js/wp-content/plugins/wpide/app/public/fonts/wpide-icons.css/wp-content/plugins/wpide/app/public/fonts/wpide-icons.woff2/wp-content/plugins/wpide/app/public/img/logo.svg/wp-content/plugins/wpide/app/public/img/favicon.png/wp-content/plugins/wpide/app/public/js/vendors.js/wp-content/plugins/wpide/app/public/js/app.js/wp-content/plugins/wpide/app/public/css/styles.css?ver=/wp-content/plugins/wpide/app/public/js/vendors.js?ver=/wp-content/plugins/wpide/app/public/js/app.js?ver=HTML / DOM Fingerprints
wpide-noticewpide-promos-noticeWPIDE NOTICE STARTWPIDE NOTICE ENDdata-wpidedata-wpide-noncedata-wpide-urldata-wpide-slugdata-wpide-namewpideWPIDE_APP_CONFIG/wp-json/wpide/v1