WP/LR Sync Folders with Real Media Library Security & Risk Analysis

wordpress.org/plugins/wplr-sync-folders

Synchronize your folders and collections in Real Media Library (Media Library Folders for WordPress) with Lightroom (with the help of WP/LR Sync).

100 active installs v1.1.2 PHP 5.4.0+ WP 4.4+ Updated Mar 27, 2020
lightroomlightroom-syncreal-media-librarysynchronizationwp-lr-sync
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP/LR Sync Folders with Real Media Library Safe to Use in 2026?

Generally Safe

Score 85/100

WP/LR Sync Folders with Real Media Library has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "wplr-sync-folders" v1.1.2 presents a moderate security risk primarily due to an unprotected AJAX handler. While the code shows good practices like a high percentage of prepared SQL statements and no identified dangerous functions or file operations, the lack of authentication on an entry point is a significant concern. This means any user, including unauthenticated ones, could potentially trigger this AJAX action, opening the door to various exploits depending on its functionality.

The static analysis reveals a limited attack surface with only one AJAX handler, but the fact that it lacks authentication is a critical flaw. The absence of nonce checks and a low percentage of output escaping further exacerbate this risk, as it suggests potential for cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, which is positive, indicating a lack of past critical issues. However, this should not breed complacency, as the current code analysis points to specific, actionable security weaknesses that need immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • No nonce checks on entry points
  • No output escaping
Vulnerabilities
None known

WP/LR Sync Folders with Real Media Library Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP/LR Sync Folders with Real Media Library Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
12 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

86% prepared14 total queries

Output Escaping

0% escaped8 total outputs
Attack Surface
1 unprotected

WP/LR Sync Folders with Real Media Library Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wplrsync_extensions_initinc\general\Core.class.php:91
WordPress Hooks 29
actionplugins_loadedinc\base\Core.class.php:64
actioninitinc\base\Core.class.php:65
actionplugins_loadedinc\general\Core.class.php:49
actionRML/Activateinc\general\Core.class.php:50
actionRML/Migrationinc\general\Core.class.php:51
actionRML/Creatable/Registerinc\general\Core.class.php:52
actionRML/Scriptsinc\general\Core.class.php:84
actionRML/Options/Registerinc\general\Core.class.php:85
actionrest_api_initinc\general\Core.class.php:92
actionadmin_noticesinc\general\Core.class.php:95
actionRML/Folder/Createdinc\general\Core.class.php:97
actionwplr_resetinc\general\Core.class.php:98
actionwplr_create_folderinc\general\Core.class.php:99
actionwplr_create_collectioninc\general\Core.class.php:100
actionwplr_remove_folderinc\general\Core.class.php:101
actionwplr_remove_collectioninc\general\Core.class.php:102
actionwplr_update_folderinc\general\Core.class.php:103
actionwplr_update_collectioninc\general\Core.class.php:104
actionwplr_move_folderinc\general\Core.class.php:105
actionwplr_move_collectioninc\general\Core.class.php:106
actionwplr_add_media_to_collectioninc\general\Core.class.php:108
actionwplr_remove_media_from_collectioninc\general\Core.class.php:109
filterRPM/Queue/Added/Processinc\general\Core.class.php:111
actionadmin_noticesinc\general\Core.class.php:115
actionadmin_noticesinc\others\fallback-php-version.php:18
actionadmin_noticesinc\others\fallback-rest-api.php:21
actionadmin_noticesinc\others\fallback-rml.php:19
actionadmin_noticesinc\others\fallback-wp-version.php:20
actionadmin_noticesinc\others\fallback-wplr.php:19
Maintenance & Trust

WP/LR Sync Folders with Real Media Library Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMar 27, 2020
PHP min version5.4.0
Downloads6K

Community Trust

Rating86/100
Number of ratings6
Active installs100
Developer Profile

WP/LR Sync Folders with Real Media Library Developer Profile

Matthias Günter

5 plugins · 4K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP/LR Sync Folders with Real Media Library

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wplr-sync-folders/inc/base/Assets.class.php/wp-content/plugins/wplr-sync-folders/inc/others/start.php/wp-content/plugins/wplr-sync-folders/inc/others/phpfallback.php/wp-content/plugins/wplr-sync-folders/inc/others/cachebuster.php/wp-content/plugins/wplr-sync-folders/inc/others/cachebuster-lib.php
Version Parameters
wplr-sync-folders/inc/base/Assets.class.php?ver=wplr-sync-folders/inc/others/start.php?ver=wplr-sync-folders/inc/others/phpfallback.php?ver=wplr-sync-folders/inc/others/cachebuster.php?ver=wplr-sync-folders/inc/others/cachebuster-lib.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP/LR Sync Folders with Real Media Library