Security
How the plugin protects uploads — what it rejects, what it quarantines, and the privacy rules that apply.
7 articles, in the order most people need them
Allowed file types
Which extensions the plugin accepts by default, why the list tightened in 3.9.0, and how to add your own safely.
Quarantine
Hold a rejected upload in a folder that is not publicly reachable, review it, then accept it or delete it.
Captcha
Add Google reCAPTCHA to the form to stop automated uploads, in either the classic or the invisible version.
GDPR compliance
Ask for consent before storing personal data, record the answer, and let people change it afterwards.
File upload security
Why front-end uploads are the most exposed part of a website, and what an attacker actually tries.
How secure the plugin is
The threats a file upload form faces, and the mechanism the plugin uses against each one.
Security: a full study
A detailed walk through every protection the plugin applies, taken one threat at a time.
Other topics
Still stuck?
Ask a question on the article closest to your problem, or contact us.
