BACK TO DIRECTORY

Lord of the Files: Enhanced Upload Security

by Blobfolio

5.0
(11 ratings)

WordPress relies mostly on name-based validation when deciding whether or not to allow a particular file, leaving the door open for various kinds of attacks.

Lord of the Files adds to this content-based validation and sanitizing, making sure that files are what they say they are and safe for inclusion on your site.

The main features include:

  • Robust real filetype detection;
  • Full MIME alias mapping;
  • SVG sanitization (if SVG uploads have been independently allowed);
  • File upload validation debugger;
  • Fixes issues related to #40175 that have been present since WordPress 4.7.1.
  • Fixes ambiguous media extensions #40921

Requirements

  • WordPress 5.2 or later.
  • PHP 7.4 or later.
  • dom PHP extension.
  • fileinfo PHP extension.
  • mbstring PHP extension.
  • xml PHP extension.

Please note: it is not safe to run WordPress atop a version of PHP that has reached its End of Life. Future releases of this plugin might, out of necessity, drop support for old, unmaintained versions of PHP. To ensure you continue to receive plugin updates, bug fixes, and new features, just make sure PHP is kept up-to-date. 🙂

Privacy Policy

This plugin does not make use of or collect any “Personal Data”.

Screenshots

Example output from Tools > Debug File Validation.

Example output from Tools > Debug File Validation.

The plugin includes a settings wizard under Settings > File Settings.

The plugin includes a settings wizard under Settings > File Settings.

Plugin Details

Active Installs
1K+
Total Downloads
102,391
Version
1.4.3
Requires WP
5.2
Requires PHP
7.4
Tested Up To
7.1
Added
2017-03-27
Last Updated
2026-08-19 9:37pm GMT

Ratings

5
11
4
0
3
0
2
0
1
0