WPIntell

Source evidence

Pre-selected file types

WP Extra File Types · support · 2021-11-12T14:22:00+00:00

questionsentiment
highseverity
0.95relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

2 / 30 rows with source links

6.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Gerinho resolved
@davideairaghi first of all, thanks for creating this plugin. It makes having client-side control over individual file types via UI a breeze. I have two questions regarding security: 1.) Upon install these are always pre-activated: .bz2|.tgz|.txz|.xz Why is that? Is it for WordPress core, updates, etc? I believe all are compressed packages file types and as far I can reason then these must be active for WordPress core & updates. But I’m not sure and if they’re optional, I’d rather turn them off to minimize potential attacking surface. 2.) Currently using it with WP v5.8.2 Although the plugin not updated for a while; is it still safe & compatible to use nowadays? I do have some server-side security in place, but as I said above, this little plugin makes control & overview a bit easier to work with from the client side. This topic was modified 4 years, 6 months ago by Gerinho . Reason: laying out questions and comments more clearly 1) those types are enabled to make sure compressed archives that are standard ones on *nix platforms are accepted 2) i released a new version compatible with WP 5.8.2, waiting for WP team’s approval Many thanks for replying @davideairaghi 1.) Already had a hunch that this was the purpose. Though, I always disable them after activating the plugin, until now I haven’t noticed any troublesome errors by doing that. Is it vital to leave them on, e.g. for any (WP) core or server processes involved? Can I have missed and caused faulty processes by disabling them? 2.) Ah, I see. Yesterday I’ve noticed the plugin was removed from WP Plugin repo and was a bit surprised, but now I know what’s the cause. Hopefully the new version gets approved. as far as i know it’s not a problem deselecting .bz2|.tgz|.txz|.xz 😉 Alright, thanks

Comments

4 shown
davide.airaghi 2021-12-04T18:17:00+00:00

1) those types are enabled to make sure compressed archives that are standard ones on *nix platforms are accepted 2) i released a new version compatible with WP 5.8.2, waiting for WP team’s approval

Gerinho 2021-12-04T21:48:00+00:00

Many thanks for replying @davideairaghi 1.) Already had a hunch that this was the purpose. Though, I always disable them after activating the plugin, until now I haven’t noticed any troublesome errors by doing that. Is it vital to leave them on, e.g. for any (WP) core or server processes involved? Can I have missed and caused faulty processes by disabling them? 2.) Ah, I see. Yesterday I’ve noticed the plugin was removed from WP Plugin repo and was a bit surprised, but now I know what’s the cause. Hopefully the new version gets approved.

davide.airaghi 2021-12-07T09:57:00+00:00

as far as i know it’s not a problem deselecting .bz2|.tgz|.txz|.xz 😉

Gerinho 2021-12-07T11:44:00+00:00

Alright, thanks