
ZIP from Media Security & Risk Analysis
wordpress.org/plugins/zip-from-mediaCompress from Media Library to ZIP archive.
Is ZIP from Media Safe to Use in 2026?
Generally Safe
Score 100/100ZIP from Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zip-from-media plugin version 1.08 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface points such as AJAX handlers, REST API routes, shortcodes, or cron events, especially those without authentication checks, is a significant strength. The code also appears to handle output correctly with 100% proper escaping and avoids dangerous functions and file operations, further contributing to a secure foundation. The complete lack of any recorded vulnerabilities, including CVEs, across all severity levels and common types is also a very positive indicator. This suggests a development team that is either highly diligent in their security practices or has not yet encountered exploitable flaws.
However, a notable concern arises from the presence of a single SQL query that is not using prepared statements. While the volume is low (1 total query), the fact that it's not prepared introduces a potential risk of SQL injection. The lack of nonce checks and capability checks, while not directly tied to an identified attack vector in this analysis, can be a concern in broader contexts if the plugin were to introduce interaction points in the future. The absence of taint analysis results also means that the full extent of potential data flow vulnerabilities might not have been uncovered. Overall, the plugin is promisingly secure due to its minimal attack surface and clean vulnerability history, but the un-prepared SQL query warrants attention.
Key Concerns
- Raw SQL query without prepared statements
ZIP from Media Security Vulnerabilities
ZIP from Media Release Timeline
ZIP from Media Code Analysis
SQL Query Safety
ZIP from Media Attack Surface
Maintenance & Trust
ZIP from Media Maintenance & Trust
Maintenance Signals
Community Trust
ZIP from Media Alternatives
Media from ZIP
media-from-zip
Extract from ZIP archive to Media Library.
Zippy
zippy
Incredibly easy solution to archive pages and posts as zip file and unpack them back even on the other website!
Archivarix External Images Importer
archivarix-external-images-importer
Import external images in posts and pages from external sources or Web Archive if original sources are not available anymore.
WP HTTP Compression
wp-http-compression
This plugin allows your WordPress blog to output pages compressed in gzip format if a browser supports compression. HTTP compression generally means …
Image Quality
image-quality
Lets you adjust the quality of image thumbnails that WordPress generates.
ZIP from Media Developer Profile
54 plugins · 56K total installs
How We Detect ZIP from Media
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zip-from-media/js/zipfrommedia.js/wp-content/plugins/zip-from-media/css/zipfrommedia.css/wp-content/plugins/zip-from-media/js/zipfrommedia.jszip-from-media/js/zipfrommedia.js?ver=zip-from-media/css/zipfrommedia.css?ver=