{"id":327156,"date":"2026-06-18T22:13:49","date_gmt":"2026-06-18T22:13:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/kodlo-media-manager\/"},"modified":"2026-07-20T13:24:12","modified_gmt":"2026-07-20T13:24:12","slug":"kodlo-media-manager","status":"publish","type":"plugin","link":"https:\/\/eu.wordpress.org\/plugins\/kodlo-media-manager\/","author":23517482,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.8.6","stable_tag":"1.8.6","tested":"7.0.2","requires":"6.6","requires_php":"8.1","requires_plugins":null,"header_name":"Kodlo Media Manager","header_author":"Kodlo","header_description":"Enforce custom format, size, and naming rules for uploads to keep your WordPress media library clean, organized, and optimized.","assets_banners_color":"9598a6","last_updated":"2026-07-20 13:24:12","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/kodlo.dev\/","header_plugin_uri":"","header_author_uri":"https:\/\/kodlo.dev\/","rating":0,"author_block_rating":0,"active_installs":10,"downloads":638,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.7.4":{"tag":"1.7.4","author":"kodlo","date":"2026-06-19 08:26:16"},"1.7.5":{"tag":"1.7.5","author":"kodlo","date":"2026-06-19 08:43:50"},"1.7.6":{"tag":"1.7.6","author":"kodlo","date":"2026-06-19 16:04:24"},"1.7.7":{"tag":"1.7.7","author":"kodlo","date":"2026-06-21 22:30:14"},"1.7.8":{"tag":"1.7.8","author":"kodlo","date":"2026-06-25 14:41:49"},"1.7.9":{"tag":"1.7.9","author":"kodlo","date":"2026-06-25 15:17:08"},"1.8.0":{"tag":"1.8.0","author":"kodlo","date":"2026-06-25 16:47:55"},"1.8.1":{"tag":"1.8.1","author":"kodlo","date":"2026-06-25 18:37:20"},"1.8.2":{"tag":"1.8.2","author":"kodlo","date":"2026-06-25 19:00:29"},"1.8.3":{"tag":"1.8.3","author":"kodlo","date":"2026-06-27 08:39:00"},"1.8.4":{"tag":"1.8.4","author":"kodlo","date":"2026-06-29 15:22:55"},"1.8.5":{"tag":"1.8.5","author":"kodlo","date":"2026-07-11 15:05:36"},"1.8.6":{"tag":"1.8.6","author":"kodlo","date":"2026-07-20 13:24:12"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3587930,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3587629,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3587645,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3587930,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","1.7.9","1.8.0","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3587629,"resolution":"1","location":"assets","locale":"","width":1560,"height":1320},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3587629,"resolution":"2","location":"assets","locale":"","width":1560,"height":1320}},"screenshots":{"1":"Upload policies, size limits, image dimensions, and filename controls on the WordPress Media Settings screen.","2":"Early validation feedback in the standard WordPress media uploader."}},"plugin_section":[],"plugin_tags":[5887,17706,3473,233,2904],"plugin_category":[50,54],"plugin_contributors":[267796,267795],"plugin_business_model":[],"class_list":["post-327156","plugin","type-plugin","status-publish","hentry","plugin_tags-file-upload","plugin_tags-filename","plugin_tags-image-sizes","plugin_tags-media-library","plugin_tags-svg","plugin_category-media","plugin_category-security-and-spam-protection","plugin_contributors-imaginary222","plugin_contributors-kodlo","plugin_committers-kodlo"],"banners":{"banner":"https:\/\/ps.w.org\/kodlo-media-manager\/assets\/banner-772x250.png?rev=3587930","banner_2x":"https:\/\/ps.w.org\/kodlo-media-manager\/assets\/banner-1544x500.png?rev=3587645","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/kodlo-media-manager\/assets\/icon-128x128.png?rev=3587930","icon_2x":"https:\/\/ps.w.org\/kodlo-media-manager\/assets\/icon-256x256.png?rev=3587629","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/kodlo-media-manager\/assets\/screenshot-1.png?rev=3587629","caption":"Upload policies, size limits, image dimensions, and filename controls on the WordPress Media Settings screen."},{"src":"https:\/\/ps.w.org\/kodlo-media-manager\/assets\/screenshot-2.png?rev=3587629","caption":"Early validation feedback in the standard WordPress media uploader."}],"raw_content":"<!--section=description-->\n<p><strong>Turn your Media Library requirements into clear, consistent upload rules.<\/strong><\/p>\n\n<p>Kodlo Media Manager adds a focused rules builder to <strong>Settings -&gt; Media<\/strong>. Define which formats WordPress may accept, where each format is allowed, how large an upload may be, which image dimensions are acceptable, and how filenames should be formatted.<\/p>\n\n<p>The plugin validates uploads on the server and provides early feedback in the standard WordPress media uploader. It uses native WordPress, PHP, and browser APIs and includes no third-party libraries or external services.<\/p>\n\n<h3>Why Use Kodlo Media Manager?<\/h3>\n\n<ul>\n<li><strong>Keep upload standards consistent:<\/strong> Replace written instructions with rules WordPress can enforce for supported upload flows.<\/li>\n<li><strong>Control each format separately:<\/strong> Give SVG, WebP, AVIF, video, document, font, and archive formats their own policy and limits.<\/li>\n<li><strong>Reduce duplicate filename clutter:<\/strong> Optionally block an exact normalized filename when it already exists in the Media Library.<\/li>\n<li><strong>Normalize filenames:<\/strong> Mirror WordPress locale-aware accent conversion, transliterate supported Cyrillic characters, apply a predictable separator, and validate the final name.<\/li>\n<li><strong>Handle SVG locally:<\/strong> Sanitize canonical <code>.svg<\/code> uploads with an internal allowlist before WordPress stores them.<\/li>\n<li><strong>Stay inside familiar WordPress screens:<\/strong> Configure everything on the native Media Settings page and use the standard media uploader.<\/li>\n<\/ul>\n\n<h3>Upload Rules<\/h3>\n\n<p>Each rule combines a file extension and MIME type with one of three policies:<\/p>\n\n<ul>\n<li><strong>Allowed (Media Library Only):<\/strong> Accept the format in verified WordPress Media Library upload contexts.<\/li>\n<li><strong>Allowed (Globally):<\/strong> Allow the format in other WordPress upload contexts as well.<\/li>\n<li><strong>Blocked (Globally):<\/strong> Reject the format throughout WordPress upload handling.<\/li>\n<\/ul>\n\n<p>An administrator can also set a per-format maximum file size and, for raster images, maximum width and height. Dangerous executable and active-content formats remain unavailable even if they are submitted through malformed settings data.<\/p>\n\n<h3>Filename and Duplicate Controls<\/h3>\n\n<p>The filename validator accepts a bounded regular-expression subset shared by PHP and JavaScript. Unsupported, malformed, or excessive patterns fall back to the plugin's safe default. Optional auto-sanitization can reshape filenames for compatible positive character-class patterns before validation; safe validation-only patterns remain available without automatic rewriting.<\/p>\n\n<p>Duplicate Guard compares exact normalized basenames rather than image contents. Every distinct filename is checked directly against Media Library attachment metadata. Short-lived hashed upload locks prevent two plugin-managed requests from claiming the same available filename at the same time, without building a filename index or custom database table.<\/p>\n\n<h3>SVG Handling<\/h3>\n\n<p>The internal SVG sanitizer accepts a limited set of SVG elements and attributes, removes unsupported content, rejects document types and entities, and permits only safe internal fragment references. It also applies a fixed payload ceiling before DOM parsing. SVG content must use the canonical <code>.svg<\/code> extension and <code>image\/svg+xml<\/code> MIME pair.<\/p>\n\n<p>SVG sanitization is a focused upload safeguard. It does not replace appropriate WordPress capabilities, server hardening, backups, or review of untrusted content.<\/p>\n\n<h3>Media Uploader Experience<\/h3>\n\n<p>The browser-side guard mirrors format, filename, size, dimension, and duplicate checks to provide feedback before an upload begins. Asynchronous dimension probes and duplicate lookups share one validation barrier, use bounded batches, concurrency, and timeouts, and finish before a paused queue resumes. Invalid or unavailable duplicate responses stop affected files and explain the failure. Server-side validation remains authoritative for native uploads and sideload-based REST uploads.<\/p>\n\n<p>Warning dialogs use native button semantics, labelled dialog markup, Escape handling, managed keyboard focus, and focus restoration. Settings controls include accessible names and predictable focus movement when rules are added or removed.<\/p>\n\n<h3>Default Configuration<\/h3>\n\n<p>The initial rules allow ZIP globally so WordPress can upload plugin and theme packages. SVG, WebP, AVIF, MP4, WebM, PDF, DOCX, and WOFF2 start in Media Library contexts with format-specific limits, while JPG, JPEG, and PNG start blocked. These defaults are a starting point, not a universal recommendation; review them for your site's editorial workflow and hosting limits.<\/p>\n\n<p>By default, verified uploads initiated by an administrator from WordPress General Settings bypass format, filename, duplicate, size, and dimension policies so core settings such as the site icon are not unexpectedly blocked. SVG files are still sanitized. Enable <strong>General Settings Page Uploads<\/strong> to apply the configured policies there as well.<\/p>\n\n<h3>Security<\/h3>\n\n<p>Report a suspected vulnerability privately through the <strong>Contact<\/strong> button at <a href=\"https:\/\/kodlo.dev\/\">https:\/\/kodlo.dev\/<\/a>. Please include the affected plugin version, WordPress and PHP environment details, observed impact, reproducible steps, required privileges, and a minimal proof of concept.<\/p>\n\n<p>Do not include passwords, API keys, customer data, or other credentials. Do not publish exploit details in a support topic before the report can be assessed. Use the public support forum only for non-sensitive support questions.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Kodlo Media Manager operates locally and does not send upload data, filenames, settings, telemetry, or analytics to Kodlo or any other external service.<\/p>\n\n<p>The plugin stores its configuration in WordPress options. Duplicate Guard does not create a filename index or custom table. During an upload it may store a short-lived site option containing a filename hash, ownership token, and timestamp; the original filename is not stored in that lock.<\/p>\n\n<p>Deactivation preserves the plugin settings. Successful upload locks are removed immediately; an abandoned expired lock is reclaimed when the same filename is checked again.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>kodlo-media-manager<\/code> directory to <code>\/wp-content\/plugins\/<\/code>, or install the plugin through the WordPress Plugins screen.<\/li>\n<li>Activate <strong>Kodlo Media Manager<\/strong>.<\/li>\n<li>Go to <strong>Settings -&gt; Media<\/strong>.<\/li>\n<li>Review every default rule and adjust the policies, limits, filename pattern, and Duplicate Guard setting for your site.<\/li>\n<li>Test the intended administrator and contributor upload workflows before applying the rules to a production editorial team.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20optimize%20or%20convert%20uploaded%20files%3F\"><h3>Does the plugin optimize or convert uploaded files?<\/h3><\/dt>\n<dd><p>No. It validates configured formats, sizes, dimensions, filenames, duplicate names, and SVG content. It does not compress images, convert JPG or PNG files to WebP or AVIF, or remove unused media.<\/p><\/dd>\n<dt id=\"why%20are%20jpg%2C%20jpeg%2C%20and%20png%20blocked%20by%20default%3F\"><h3>Why are JPG, JPEG, and PNG blocked by default?<\/h3><\/dt>\n<dd><p>The initial profile encourages a WebP or AVIF workflow. It is only a starting point. Change the applicable rule to <strong>Allowed (Media Library Only)<\/strong> or <strong>Allowed (Globally)<\/strong> if your project uses JPG, JPEG, or PNG.<\/p><\/dd>\n<dt id=\"why%20is%20zip%20allowed%20globally%20by%20default%3F\"><h3>Why is ZIP allowed globally by default?<\/h3><\/dt>\n<dd><p>WordPress handles administrator-uploaded plugin and theme ZIP packages outside the Media Library. Allowing ZIP globally keeps those native installation workflows available, while WordPress's own capability and package validation still apply. Change the rule only if your site has a different package-upload policy and you have tested the affected administration screens.<\/p><\/dd>\n<dt id=\"what%20does%20a%20maximum%20size%20of%20zero%20mean%3F\"><h3>What does a maximum size of zero mean?<\/h3><\/dt>\n<dd><p>Zero or a blank value disables the plugin's per-format size limit for that rule. WordPress, PHP, the web server, and the hosting provider may still impose their own limits.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20the%20three%20upload%20policies%3F\"><h3>What is the difference between the three upload policies?<\/h3><\/dt>\n<dd><p><strong>Allowed (Media Library Only)<\/strong> requires a verified Media Library context. <strong>Allowed (Globally)<\/strong> also permits the configured format in other WordPress upload contexts. <strong>Blocked (Globally)<\/strong> rejects the format throughout WordPress upload handling.<\/p><\/dd>\n<dt id=\"how%20does%20duplicate%20guard%20work%3F\"><h3>How does Duplicate Guard work?<\/h3><\/dt>\n<dd><p>It blocks exact normalized filename matches, not visually similar images or identical file contents with different names. Each distinct name is queried directly against Media Library attachment metadata. A short-lived hashed lock closes the race between lookup and storage for plugin-managed uploads. If WordPress cannot verify a name, the upload is stopped conservatively and can be retried.<\/p><\/dd>\n<dt id=\"does%20duplicate%20guard%20create%20a%20filename%20index%20or%20change%20attachment%20data%3F\"><h3>Does Duplicate Guard create a filename index or change attachment data?<\/h3><\/dt>\n<dd><p>No. Each filename is checked directly against existing <code>_wp_attached_file<\/code> metadata. The plugin does not rewrite attachment content, add attachment metadata, or maintain a custom filename table. Concurrent plugin-managed uploads use short-lived hashed option locks that do not contain the original filename.<\/p><\/dd>\n<dt id=\"how%20does%20the%20svg%20sanitizer%20work%3F\"><h3>How does the SVG sanitizer work?<\/h3><\/dt>\n<dd><p>Canonical <code>.svg<\/code> uploads are parsed locally with PHP's DOM extension. The sanitizer uses element and attribute allowlists, accepts only safe internal fragment references, and rejects document types, entities, external URLs, foreign namespaces, event handlers, and other unsupported active content. Files above the fixed parser ceiling are rejected before DOM parsing.<\/p><\/dd>\n<dt id=\"can%20i%20use%20a%20custom%20filename%20pattern%3F\"><h3>Can I use a custom filename pattern?<\/h3><\/dt>\n<dd><p>Yes. Patterns must be anchored and remain within the bounded subset that the plugin can evaluate consistently in PHP and JavaScript. Groups, alternation, backreferences, engine-specific escapes, excessive lengths, invalid quantifiers, and malformed expressions are rejected in favor of the default pattern.<\/p><\/dd>\n<dt id=\"how%20does%20filename%20auto-sanitization%20work%3F\"><h3>How does filename auto-sanitization work?<\/h3><\/dt>\n<dd><p>When enabled for a compatible positive character-class pattern, the plugin mirrors the active WordPress locale's accent conversions in the media uploader, transliterates supported Cyrillic characters, chooses a separator that fits the pattern, normalizes letter case when practical, and removes unsupported characters. The server applies WordPress filename sanitization once and validates WordPress's final unique filename again before storage. Patterns with required literals, negated classes, or other constructs that cannot be generated deterministically remain validation-only and automatically disable rewriting.<\/p><\/dd>\n<dt id=\"how%20are%20image%20dimensions%20and%20wordpress%20big-image%20scaling%20handled%3F\"><h3>How are image dimensions and WordPress big-image scaling handled?<\/h3><\/dt>\n<dd><p>When a rule defines width or height limits, the plugin verifies the uploaded raster image dimensions. For active rules, it also adjusts WordPress's big-image threshold to reflect the configured bounds while preserving a threshold that another component has explicitly disabled.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20affect%20frontend%20performance%3F\"><h3>Does the plugin affect frontend performance?<\/h3><\/dt>\n<dd><p>The plugin does not enqueue assets on public frontend pages. Upload validation runs only in relevant administrator or upload contexts. Duplicate Guard uses direct per-filename Media Library queries and deliberately rechecks an available name after locking and before movement, so its upload-time cost depends on upload volume, Media Library size, and database performance.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.8.6<\/h4>\n\n<ul>\n<li>Security: Replaced permissive SVG filtering with a self-contained element and attribute allowlist, safe internal references, canonical SVG extension and MIME validation, and a hard payload ceiling before DOM parsing.<\/li>\n<li>Security: Expanded the non-configurable dangerous-format denylist and hardened settings input, extension\/MIME pairs, upload and sideload contexts, malformed request values, and General Settings authorization.<\/li>\n<li>Correctness: Added one-pass WordPress filename normalization, locale-aware browser parity, bounded PHP\/JavaScript-safe patterns, deterministic auto-sanitization limits, effective MIME correction, and final unique-name validation before storage.<\/li>\n<li>Duplicate Guard: Added direct per-filename Media Library lookups, short-lived hashed upload locks, final-name rechecks, and fail-closed native, sideload, REST, and database-error handling without a filename index or custom table.<\/li>\n<li>Upload experience: Coordinated asynchronous duplicate and image-dimension checks behind one uploader barrier with bounded batches, strict response validation, request timeouts, bounded dimension concurrency, and object URL cleanup.<\/li>\n<li>Accessibility: Added labelled warning dialogs with keyboard and focus management, accessible rule controls, and predictable focus after adding or deleting a rule.<\/li>\n<li>Performance: Scoped admin assets and upload filters to relevant contexts and removed document-wide file-input rescanning.<\/li>\n<li>Maintenance: Split upload context, filename identity, direct duplicate lookup, temporary reservations, and upload orchestration into focused internal components, aligned native callback signatures, and removed unreachable branches without third-party libraries.<\/li>\n<li>Defaults: Allowed ZIP globally so native WordPress plugin and theme package uploads are not restricted by the initial rules.<\/li>\n<\/ul>\n\n<h4>1.8.5<\/h4>\n\n<ul>\n<li>Maintenance: Synchronized the current plugin interface across English source strings and the bundled Ukrainian and German translation catalogs.<\/li>\n<li>Maintenance: Updated WordPress compatibility metadata to 7.0.<\/li>\n<\/ul>\n\n<h4>1.8.4<\/h4>\n\n<ul>\n<li>Fix: Matched client-side filename normalization to the server so names containing spaces are reshaped consistently before validation.<\/li>\n<li>Fix: Added a re-entrancy guard around the filename sanitization filter to prevent recursive processing during WordPress filename cleanup.<\/li>\n<\/ul>","raw_excerpt":"Set upload rules for file types, sizes, image dimensions, filenames, duplicate names, and SVG content in the WordPress Media Library.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/327156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=327156"}],"author":[{"embeddable":true,"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/kodlo"}],"wp:attachment":[{"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=327156"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=327156"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=327156"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=327156"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=327156"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/eu.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=327156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}