{"id":345483,"date":"2026-08-12T22:28:17","date_gmt":"2026-08-12T22:28:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/developersd-manage-media-support\/"},"modified":"2026-08-12T22:27:58","modified_gmt":"2026-08-12T22:27:58","slug":"developersd-manage-media-support","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/developersd-manage-media-support\/","author":18675011,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.3","stable_tag":"1.1.3","tested":"7.0.4","requires":"6.3","requires_php":"8.0","requires_plugins":null,"header_name":"Developersd Manage Media Support","header_author":"Developersd","header_description":"Advanced control over which file types WordPress accepts, with per-role permissions, upload limits, MIME &amp; magic-byte validation, SVG sanitization, import\/export and more.","assets_banners_color":"","last_updated":"2026-08-12 22:27:58","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/sudipdebnath-cloud.github.io\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":33,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.3":{"tag":"1.1.3","author":"developersd","date":"2026-08-12 22:27:58"}},"upgrade_notice":{"1.1.0":"<p>Renames internal option keys (dms_settings -&gt; devds_settings); saved settings will reset to defaults once. Also adds a hard security denylist for custom file types.<\/p>","1.0.3":"<p>Resolves all WordPress Plugin Check errors\/warnings from 1.0.2. Recommended for anyone preparing to submit to WordPress.org.<\/p>","1.0.2":"<p>Important fix: previous versions could block normal JPG\/PNG\/GIF\/ZIP uploads. Update recommended for all sites.<\/p>","1.0.1":"<p>Fixes tab-redirect and duplicate-notice bugs from 1.0.0. Recommended update.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.3"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"The File Types tab, showing searchable, groupable file type cards with toggle switches.","2":"The Upload Limits tab, with server limit detection and per-role permissions.","3":"The Tools tab, with preset profiles, import\/export, and the live upload tester."}},"plugin_section":[],"plugin_tags":[148482,84,7885,2904,85],"plugin_category":[50],"plugin_contributors":[269280],"plugin_business_model":[],"class_list":["post-345483","plugin","type-plugin","status-publish","hentry","plugin_tags-file-types","plugin_tags-media","plugin_tags-mime-types","plugin_tags-svg","plugin_tags-uploads","plugin_category-media","plugin_contributors-developersd","plugin_committers-developersd"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/developersd-manage-media-support.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>Developersd Manage Media Support<\/strong> is an advanced media management plugin that gives administrators precise control over what can be uploaded to their WordPress site \u2014 far beyond the handful of file types WordPress supports out of the box.<\/p>\n\n<p>Enable support for SVG, WebP, AVIF, HEIC, fonts, PDFs, Office documents, archives, developer files (JSON, YAML, SQL, Markdown), audio\/video, certificates, contact cards, and design files (Figma, Sketch, Adobe XD) \u2014 or register your own custom MIME types entirely.<\/p>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li>Enable or disable dozens of built-in file types across nine categories: Images, Fonts, Documents, Archives, Development Files, Media, Certificates, Contacts, and Design.<\/li>\n<li>Register unlimited custom MIME types with your own extension, MIME string, and description.<\/li>\n<li>Strict MIME validation using WordPress core's own file inspection \u2014 never trusts the browser-supplied content type alone.<\/li>\n<li>Optional magic-byte (file signature) checking to catch files renamed to bypass extension-based filters.<\/li>\n<li>Built-in, dependency-free SVG sanitizer that strips scripts, event handlers, and other XSS vectors before an SVG is stored.<\/li>\n<li>Configurable maximum upload size, with automatic detection of your server's real <code>upload_max_filesize<\/code> \/ <code>post_max_size<\/code> limits and a clear warning when your setting exceeds what the server allows.<\/li>\n<li>Copy-paste <code>.htaccess<\/code> and <code>php.ini<\/code> snippets for hosts that support raising those limits.<\/li>\n<li>Per-role upload permissions, so you can allow SVG uploads for Administrators while blocking them for Authors, for example.<\/li>\n<li>One-click preset profiles for common site types: Developer, Designer\/Agency, Media Site, Business Website, and Educational.<\/li>\n<li>Import, export, and reset settings as JSON.<\/li>\n<li>Optional local upload audit log (who uploaded what, when, and whether it was allowed).<\/li>\n<li>Live Upload Tester \u2014 check whether a file would be accepted without adding it to the Media Library.<\/li>\n<li>System compatibility page showing PHP\/WordPress versions and required extensions.<\/li>\n<li>Full multisite compatibility.<\/li>\n<li>Developer filters and actions for extending the plugin (<code>devds_mime_catalog<\/code>, <code>devds_presets<\/code>, <code>devds_default_settings<\/code>, and more).<\/li>\n<li>Zero tracking. Zero telemetry. Zero external requests. Everything runs locally on your site.<\/li>\n<\/ul>\n\n<h4>Security First<\/h4>\n\n<p>Every uploaded file is checked against the extensions and MIME types you've explicitly enabled, validated against WordPress's own file-type detection, and optionally checked against known file signatures. SVG uploads are sanitized by default when enabled. Nothing here ever relies on trusting a browser-supplied filename or content type.<\/p>\n\n<h4>Developer Friendly<\/h4>\n\n<p>The plugin is built with a clean, fully namespaced, object-oriented architecture. Every class has a single responsibility, all settings live in a single option (no custom database tables), and a full set of filters and actions lets other plugins register additional MIME types or adjust behavior without editing core files.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>developersd-manage-media-support<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install directly through the WordPress Plugins screen.<\/li>\n<li>Activate the plugin through the \"Plugins\" screen in WordPress.<\/li>\n<li>Go to <strong>Settings \u2192 Media Support<\/strong> to configure which file types are allowed and set your upload limits.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20let%20me%20exceed%20my%20host%27s%20upload%20size%20limit%3F\"><h3>Will this let me exceed my host's upload size limit?<\/h3><\/dt>\n<dd><p>No. The plugin enforces whichever is smaller: your configured maximum, or your server's actual PHP <code>upload_max_filesize<\/code> \/ <code>post_max_size<\/code> values. It will clearly warn you if your configured value exceeds what the server allows, and provides optional <code>.htaccess<\/code>\/<code>php.ini<\/code> snippets you can try \u2014 but ultimately your hosting provider controls those hard limits.<\/p><\/dd>\n<dt id=\"is%20svg%20upload%20safe%3F\"><h3>Is SVG upload safe?<\/h3><\/dt>\n<dd><p>SVG support is disabled by default. When you enable it, the plugin sanitizes every uploaded SVG file \u2014 stripping scripts, event handler attributes, external references, and other known XSS vectors \u2014 using a dependency-free sanitizer built on PHP's DOMDocument. For maximum safety, we also recommend restricting SVG uploads to trusted roles using the Upload Limits tab.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20track%20anything%20or%20phone%20home%3F\"><h3>Does this plugin track anything or phone home?<\/h3><\/dt>\n<dd><p>No. This plugin makes no external requests, collects no user data, and includes no analytics or tracking of any kind.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20settings%20if%20i%20deactivate%20the%20plugin%3F\"><h3>What happens to my settings if I deactivate the plugin?<\/h3><\/dt>\n<dd><p>Nothing \u2014 deactivating leaves all settings intact. Settings and the audit log are only removed on uninstall (deleting the plugin), and only if you've explicitly enabled \"Delete data on uninstall\" in the Advanced tab.<\/p><\/dd>\n<dt id=\"can%20other%20plugins%20register%20their%20own%20file%20types%3F\"><h3>Can other plugins register their own file types?<\/h3><\/dt>\n<dd><p>Yes. Use the <code>devds_mime_catalog<\/code> filter to add entire new groups or individual file types programmatically.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Fixed: the denylist of disallowed custom-type extensions was incomplete \u2014 css, xsl\/xslt, svgz (gzip-compressed SVG, which bypasses the SVG sanitizer), wasm, swf, and class have been added alongside the existing script\/executable entries.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Fixed: removed .phpcs.xml.dist from the distributed package \u2014 WordPress.org's packaging scanner disallows hidden\/dot files and dev-tooling config files in the submitted plugin ZIP entirely. The underlying naming-convention fixes (inline phpcs:disable comments in the actual PHP files) don't depend on this file, so nothing else changes.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fixed: uninstall.php's multisite loop now runs inside its own function instead of at file top-level, so its working variables are no longer flagged as unprefixed globals.<\/li>\n<li>Fixed: added documented, targeted suppressions for a PHPCS naming-convention sniff that flagged this plugin's PHP namespace (<code>Developersd\\MediaSupport<\/code>) as an unrecognized global prefix, and flagged template-partial local variables as if they were globals (they're always <code>include()<\/code>d from within a class method, so they're not).<\/li>\n<li>Added: a <code>.phpcs.xml.dist<\/code> ruleset declaring this plugin's recognized prefixes, for anyone running PHPCS\/WPCS directly against the codebase.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Security: added a hard denylist of server- and browser-executable extensions (php and variants, js, html\/htm, htaccess, sh, exe, and similar) that can never be enabled, whether via the built-in catalog, a custom type, or a settings import \u2014 closing a gap where the Custom File Types feature had no restriction on what an admin could register.<\/li>\n<li>Changed: all previously generic <code>dms<\/code>-prefixed identifiers (constants, hooks\/filters, option names, the AJAX action, the nonce, and the enqueued script\/style handle) have been renamed to the <code>devds<\/code>\/<code>DEVDS<\/code> prefix, per WordPress.org Plugin Directory review feedback that the original prefix was too short. This includes the <code>devds_settings<\/code> and <code>devds_audit_log<\/code> options (previously <code>dms_settings<\/code> \/ <code>dms_audit_log<\/code>) \u2014 sites that saved settings under the old prefix will start fresh with defaults after updating.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Fixed: replaced direct unlink() calls with wp_delete_file(), per WordPress Plugin Check.<\/li>\n<li>Fixed: replaced direct fopen()\/fread()\/fclose() calls in the magic-byte signature check with a bounded file_get_contents() read.<\/li>\n<li>Fixed: added documented nonce\/sanitization annotations where Plugin Check couldn't trace verification performed in a separate method, and reviewed each flagged case individually.<\/li>\n<li>Removed: the manual load_plugin_textdomain() call \u2014 WordPress 4.6+ auto-loads translations for plugins whose text domain matches their slug, so this was both unnecessary and flagged as discouraged.<\/li>\n<li>Fixed: readme.txt \"Tested up to\" updated to the current WordPress version, and the short description trimmed to fit WordPress.org's 150-character limit.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Fixed: uploads of file types WordPress core already supports by default (JPG, PNG, GIF, ZIP, and dozens more) were being blocked with \"disabled by the site administrator\", because validation only consulted this plugin's own catalog instead of WordPress's actual accepted-types list.<\/li>\n<li>Fixed: custom file types added on the File Types tab had no way to actually take effect \u2014 they're now active as soon as they're added.<\/li>\n<li>Fixed: saving one settings tab (e.g. General) could silently reset settings that live on a different tab (e.g. File Types, Upload Limits) back to empty\/default, because each tab's form only submits its own fields. Saving is now scoped per tab.<\/li>\n<li>Changed: default enabled file types are now computed from WordPress core's actual mime whitelist at runtime (jpg, png, gif, pdf, zip, docx, mp3, etc. default ON; SVG, fonts, PSD, JSON, and similar higher-risk formats default OFF), rather than a hard-coded guess.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fixed: saving settings on a non-General tab redirected back to the General tab instead of staying put.<\/li>\n<li>Fixed: a duplicate \"Settings saved\" notice appeared alongside the toast message.<\/li>\n<li>Improved: success\/error messages now render as a floating toast appended to the page body, ensuring correct positioning above the admin bar with no visual overlap with the plugin's own header.<\/li>\n<li>Added: a \"Settings\" link on the Plugins list screen.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Control exactly which file types WordPress accepts, with per-role permissions, upload limits, and built-in MIME, magic-byte, and SVG security checks.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/345483","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=345483"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/developersd"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=345483"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=345483"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=345483"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=345483"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=345483"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=345483"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}