Plugin Pulse
← Pulse

Iptanus File Upload

by nickboss · Forms

THIS IS FORMER WORDPRESS FILE UPLOAD PLUGIN. Simple yet powerful plugin to allow users to upload files from any page, post or sidebar and manage them.

How scoring works →
88 Health · A
Maintenance 100/100
Rating quality 86/100
Support 70/100

88 health vs 63 average across 1,679 Forms plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

82 / 100

Well optimized

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 86/100
Listing tuning 100/100
Support resolution 0/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

+739% vs prior 30d
103Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

16.5K

now · peak 41.4K

16.5K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Iptanus File Upload · #1854 you Store file uploads f · #6185 Post Lists View Cust · #5110 Custom Post Type Att · #7735

Rating trend

Star average over time · dips mark rough releases

4.4Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.6Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

8

releases in the last 12 months

6mo ago

latest release · v5.1.8

148

tagged releases on record

Recent releases

5.1.8 · 6mo ago5.1.7 · 8mo ago5.1.6 · 9mo ago5.1.5 · 10mo ago5.1.4 · 10mo ago5.1.3 · 10mo ago5.1.2 · 10mo ago5.1.1 · 11mo ago5.1.0 · 1.4y ago5.0.0 · 1.5y ago4.25.3 · 1.5y ago4.25.2 · 1.6y ago4.25.1 · 1.6y ago4.25.0 · 1.6y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 60% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v5.1 60%
v4.24 9.2%
v4.25 8.7%
Older / other versions 22%

Estimated active installs

The public count shows “10K+”. Our estimate pins where the real number sits.

tracked estimate
10K–20K ≈18K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-03-10 · 1,469 observations

10KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.

Details

Version
5.1.10
Last updated
26d ago
Added
2013-12-09 · 12 yrs old
Requires WP
3.0
Tested up to
7.0.4
Requires PHP

Recent reviews

All reviews on wp.org ↗
  1. Moveksdizajn
    7mo ago

    so simple and works good

    Read on wp.org ↗
  2. laurendev
    1.6y ago

    I was looking for a simple plugin for users to upload a singular jpeg or PDF to my website. This plugin rejects every file that is uploaded. I tried uploading several different types (jpeg, PDF and .doc) and it rejected all of them, saying each one was suspicious. The way around this according to the plugin page is to set up the Quarantine feature. But of course the quarantine feature is only possible by upgrading to the Premium version, rendering this app completely useless unless you pay to upgrade.

    Read on wp.org ↗
  3. revayatejahad
    2.3y ago

    Thank you very much for your great work! well done! I have some issue with the plugin and It would be great if you help me with them as soon as possible. first of all, I use the plugin inside Gravity form and I want the uploaded link could be saved with the form entry! I’ve tried different ways but didn’t come with the result! finally I just added the %pathfile% in the comment below when file successfully uploaded as a way to see the uploaded link but I want this path be saved some where with the form. but the link will disappears when we move to next page or next file upload! secondly, in wordpress dashboard > uploaded files, it doesn’t show the file path with the domain name of ftp server but it shows the direct ftp address to the file which is not wanted! thirdly, It would be great if the plugin asks the domain name and replace it with the ftp file address at the beginning of each file link. lastly, it would be fantastic if the (uploaded files)’s links and names could be exported in an xlsx or csv file from wordpress dashboard > uploaded files.

    Read on wp.org ↗
  4. humananimal
    2.6y ago

    thank you for this!!

    Read on wp.org ↗
  5. Marcel
    2.8y ago

    The plugin is well-written and has a clean, logical interface. I am using it primarily for its webcam support, and it is working very well indeed. There is a currently a problem with uploading the resulting video to Dropbox or Google Drive; however, that is caused by another plugin that has a dependency on an outdated version of Guzzle (an HTTP client). Not only does the plugin work well, but Nickolas, the developer, delivers outstanding support. Highly recommended!

    Read on wp.org ↗
  6. LaurentAnimage
    3.0y ago

    Do exactly what it should ! Very useful with a lot of shortcodes.Support is fast and precise.Very good plug.

    Read on wp.org ↗
  7. kwekli
    3.0y ago

    This plugin is absolutely perfect and has everything one might need, especially in the pro version (awesome features that aren’t in the free version are listed there). If I was making a more serious website than I am currently working on, I’d definitely buy the pro version.

    Read on wp.org ↗
  8. qrmiz
    3.8y ago

    I’m impressed how great this plugin is… There might be some bits glitching, from design perspective, but the overall how it works is just amazing… Good job to the author!!

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 5.1.7 fixed File Overwrite Race Condition when uploading files with the same filename concurrently 5.1.7
  2. Version 5.1.6 verified compatibility with latest 6.9 WordPress version 5.1.6
  3. Version 5.1.5 added support for FTP over TLS (FTPS) uploads 5.1.5
  4. Version 5.1.4 fixed bug where the visual editor throwed warnings for not finding personaldata when Personal Data were deactivated from the plugin’s Settings in Dashboard corrected bug where the upload form visual editor was not openin 5.1.4
  5. Version 5.1.3 removed Post Method setting all GET and POST requests are now executed using the default WordPress functions 5.1.3
  6. Version 5.1.2 improvements on how AJAX endpoint is provided corrections to Requires at lease value replacement of eval() in minification function 5.1.2

Known vulnerabilities

via Wordfence Intelligence

32 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-05 CVE-2026-66447 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.1.7 Patched in 5.1.8
  2. 2026-08-03 CVE-2026-17044 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.1.7 Patched in 5.1.8
  3. 2025-02-24 CVE-2024-13494 Cross-Site Request Forgery (CSRF) Affects <= 4.25.2 Patched in 4.25.3
  4. 2025-01-07 CVE-2024-11635 Improper Control of Generation of Code ('Code Injection') Affects <= 4.24.12 Patched in 4.24.14
  5. 2025-01-07 CVE-2024-11613 Improper Control of Generation of Code ('Code Injection') Affects <= 4.24.15 Patched in 4.25.0
  6. 2025-01-07 CVE-2024-9939 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.24.13 Patched in 4.24.14
  7. 2025-01-06 CVE-2024-12719 Missing Authorization Affects <= 4.24.15 Patched in 4.25.0
  8. 2024-10-11 CVE-2024-9047 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.24.11 Patched in 4.24.12
  9. 2024-08-15 CVE-2024-7301 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.24.8 Patched in 4.24.9
  10. 2024-08-01 CVE-2024-39639 Missing Authorization Affects <= 4.24.7 Patched in 4.24.8
  11. 2024-07-16 CVE-2024-6494 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.24.7 Patched in 4.24.8
  12. 2024-07-16 CVE-2024-6651 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.24.7 Patched in 4.24.8
  13. 2024-07-15 CVE-2024-5852 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.24.7 Patched in 4.24.8
  14. 2024-03-29 CVE-2024-2847 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.24.5 Patched in 4.24.6
  15. 2023-11-14 Cross-Site Request Forgery (CSRF) Affects <= 4.24.0 Patched in 4.24.1
  16. 2023-09-12 CVE-2023-4811 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.23.3 Patched in 4.23.3
  17. 2023-05-23 CVE-2023-2767 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.19.1 Patched in 4.19.2
  18. 2023-05-23 CVE-2023-2688 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.19.1 Patched in 4.19.2
  19. 2022-05-15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.3 Patched in 4.16.4
  20. 2022-03-01 CVE-2021-24962 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.16.2 Patched in 4.16.3
  21. 2022-02-14 CVE-2021-24960 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.16.3 Patched in 4.16.3
  22. 2022-02-14 CVE-2021-24961 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.16.3 Patched in 4.16.3
  23. 2020-03-13 CVE-2020-10564 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.12.2 Patched in 4.13.0
  24. 2018-04-06 CVE-2018-9844 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.3.4 Patched in 4.3.4
  25. 2018-03-31 CVE-2018-9172 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.3.3 Patched in 4.3.3
  26. 2016-06-23 Unrestricted Upload of File with Dangerous Type Affects < 3.9.0 Patched in 3.9.0
  27. 2015-10-29 CVE-2015-9341 Unrestricted Upload of File with Dangerous Type Affects < 3.4.1 Patched in 3.4.1
  28. 2015-07-02 CVE-2015-9340 Unrestricted Upload of File with Dangerous Type Affects < 3.0.0 Patched in 3.0.0
  29. 2015-05-09 CVE-2015-9339 Unrestricted Upload of File with Dangerous Type Affects < 2.7.1 Patched in 2.7.1
  30. 2015-01-23 CVE-2015-9338 Unrestricted Upload of File with Dangerous Type Affects <= 2.4.6 Patched in 2.5.0
  31. 2014-08-20 CVE-2014-125110 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.4.3 Patched in 2.4.4
  32. 2014-08-08 CVE-2014-5199 Cross-Site Request Forgery (CSRF) Affects < 2.4.2 Patched in 2.4.2

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 11 languages, 0 at 90% or more

Dutch 17%
English (UK) 17%
German 8%
French (France) 7%
Greek 7%
Japanese 7%
Portuguese (Brazil) 7%
Serbian 6%
Danish 4%
Italian 4%
Spanish (Spain) 1%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2025-10-29 20K+ → 10K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Iptanus File Upload into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/wp-file-upload" width="480" height="300" style="border:0" loading="lazy" title="Iptanus File Upload — Plugin Pulse"></iframe>
Preview card ↗

Iptanus File Upload: 10K+ active installs, 4.4★ (117 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/wp-file-upload