ZIP from Media Security & Risk Analysis

wordpress.org/plugins/zip-from-media

Compress from Media Library to ZIP archive.

300 active installs v1.08 PHP 8.0+ WP 4.7+ Updated Mar 29, 2026
archivecompressmediazip
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZIP from Media Safe to Use in 2026?

Generally Safe

Score 100/100

ZIP from Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The zip-from-media plugin version 1.08 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface points such as AJAX handlers, REST API routes, shortcodes, or cron events, especially those without authentication checks, is a significant strength. The code also appears to handle output correctly with 100% proper escaping and avoids dangerous functions and file operations, further contributing to a secure foundation. The complete lack of any recorded vulnerabilities, including CVEs, across all severity levels and common types is also a very positive indicator. This suggests a development team that is either highly diligent in their security practices or has not yet encountered exploitable flaws.

However, a notable concern arises from the presence of a single SQL query that is not using prepared statements. While the volume is low (1 total query), the fact that it's not prepared introduces a potential risk of SQL injection. The lack of nonce checks and capability checks, while not directly tied to an identified attack vector in this analysis, can be a concern in broader contexts if the plugin were to introduce interaction points in the future. The absence of taint analysis results also means that the full extent of potential data flow vulnerabilities might not have been uncovered. Overall, the plugin is promisingly secure due to its minimal attack surface and clean vulnerability history, but the un-prepared SQL query warrants attention.

Key Concerns

  • Raw SQL query without prepared statements
Vulnerabilities
None known

ZIP from Media Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ZIP from Media Release Timeline

v1.08Current
v1.07
v1.06
v1.05
v1.04
v1.03
v1.02
v1.01
v1.00
Code Analysis
Analyzed Mar 16, 2026

ZIP from Media Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries
Attack Surface

ZIP from Media Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

ZIP from Media Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 29, 2026
PHP min version8.0
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

ZIP from Media Developer Profile

Katsushi Kawamori

54 plugins · 56K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
178 days
View full developer profile
Detection Fingerprints

How We Detect ZIP from Media

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zip-from-media/js/zipfrommedia.js/wp-content/plugins/zip-from-media/css/zipfrommedia.css
Script Paths
/wp-content/plugins/zip-from-media/js/zipfrommedia.js
Version Parameters
zip-from-media/js/zipfrommedia.js?ver=zip-from-media/css/zipfrommedia.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ZIP from Media