{"id":363905,"date":"2026-09-06T16:29:29","date_gmt":"2026-09-06T16:29:29","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/brightery-file-lockdown\/"},"modified":"2026-09-06T16:28:28","modified_gmt":"2026-09-06T16:28:28","slug":"brightery-file-lockdown","status":"publish","type":"plugin","link":"https:\/\/so.wordpress.org\/plugins\/brightery-file-lockdown\/","author":17316408,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.9","stable_tag":"1.0.9","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Brightery File Lockdown","header_author":"Brightery","header_description":"Locks down code-changing capabilities and restricts WordPress uploads to approved media types.","assets_banners_color":"0a2e5c","last_updated":"2026-09-06 16:28:28","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/brightery.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":44,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.9":{"tag":"1.0.9","author":"brighterycom","date":"2026-09-06 16:28:28","revision":3683667}},"upgrade_notice":{"1.0.9":"<p>WordPress.org review update: plugin path resolution and optional Must-Use deployment now use location-safe paths and the contributor username matches the plugin owner.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3683667,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3683667,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3683667,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3683667,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3683667,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3683667,"resolution":"1","location":"assets","locale":"","width":1280,"height":800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3683667,"resolution":"2","location":"assets","locale":"","width":1280,"height":800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3683667,"resolution":"3","location":"assets","locale":"","width":1280,"height":800},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3683667,"resolution":"4","location":"assets","locale":"","width":1280,"height":800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3683667,"resolution":"5","location":"assets","locale":"","width":1280,"height":800}},"screenshots":[]},"plugin_section":[],"plugin_tags":[29711,31093,84,600,85],"plugin_category":[50,54],"plugin_contributors":[257918],"plugin_business_model":[],"class_list":["post-363905","plugin","type-plugin","status-publish","hentry","plugin_tags-file-security","plugin_tags-hardening","plugin_tags-media","plugin_tags-security","plugin_tags-uploads","plugin_category-media","plugin_category-security-and-spam-protection","plugin_contributors-brighterycom","plugin_committers-brighterycom"],"banners":{"banner":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/banner-772x250.png?rev=3683667","banner_2x":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/banner-1544x500.png?rev=3683667","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/icon.svg?rev=3683667","icon":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/icon.svg?rev=3683667","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/screenshot-1.png?rev=3683667","caption":""},{"src":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/screenshot-2.png?rev=3683667","caption":""},{"src":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/screenshot-3.png?rev=3683667","caption":""},{"src":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/screenshot-4.png?rev=3683667","caption":""},{"src":"https:\/\/ps.w.org\/brightery-file-lockdown\/assets\/screenshot-5.png?rev=3683667","caption":""}],"raw_content":"<!--section=description-->\n<p>Brightery File Lockdown reduces the impact of a compromised WordPress administrator account by restricting high-risk code and upload capabilities.<\/p>\n\n<p>In standard plugin mode it:<\/p>\n\n<ul>\n<li>Disables theme and plugin source-editing capabilities.<\/li>\n<li>Blocks installation of new plugins and themes from wp-admin.<\/li>\n<li>Blocks plugin and theme ZIP uploads.<\/li>\n<li>Blocks plugin and theme deletion from wp-admin.<\/li>\n<li>Keeps core, plugin, and theme updates configurable.<\/li>\n<li>Restricts uploads to an explicit image, audio, and video allowlist.<\/li>\n<li>Rejects executable, script, archive, and configuration-file extensions.<\/li>\n<li>Rejects suspicious double extensions such as <code>example.php.jpg<\/code>.<\/li>\n<li>Uses WordPress file-type validation plus server-side MIME detection when available.<\/li>\n<li>Applies the same upload checks to normal uploads and sideloaded uploads.<\/li>\n<li>Keeps a bounded local record of the latest 100 blocked security events in the WordPress database.<\/li>\n<\/ul>\n\n<p>The plugin does not contact Brightery or any external service, does not send telemetry, and does not collect IP addresses or WordPress user IDs.<\/p>\n\n<h4>Admin-resistant Must-Use mode<\/h4>\n\n<p>A normal WordPress plugin can always be deactivated by an administrator. If your security goal is to remain active after a WordPress administrator account is compromised, use the optional Must-Use loader included in the <code>mu<\/code> directory.<\/p>\n\n<p>For WordPress.org transparency and normal plugin lifecycle behavior, Brightery File Lockdown does not copy or install itself into <code>wp-content\/mu-plugins<\/code> automatically.<\/p>\n\n<p>A trusted server administrator may manually deploy the Must-Use mode using two files from this package:<\/p>\n\n<ol>\n<li>Copy <code>mu\/brightery-file-lockdown-mu-loader.php<\/code> to <code>wp-content\/mu-plugins\/brightery-file-lockdown.php<\/code>.<\/li>\n<li>Create <code>wp-content\/mu-plugins\/brightery-file-lockdown\/<\/code> and copy <code>includes\/class-brightery-file-lockdown.php<\/code> into that directory as <code>class-brightery-file-lockdown.php<\/code>.<\/li>\n<\/ol>\n\n<p>The deployed MU loader resolves the copied engine relative to the loader's own location. It does not rely on <code>WP_PLUGIN_DIR<\/code> or the normal plugin directory name. This lets the Must-Use protection continue loading even if the normal plugin is deactivated or its directory is renamed.<\/p>\n\n<p>Remove both manually deployed Must-Use files with trusted filesystem access before uninstalling the normal plugin.<\/p>\n\n<p>This plugin is a hardening layer, not a guarantee against compromise. Keep WordPress, plugins, themes, PHP, and the web server updated and apply server-level upload execution restrictions where appropriate.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Brightery File Lockdown does not transmit data to external servers and does not collect IP addresses or WordPress user IDs. A bounded local event record may contain blocked filenames, MIME types, block reasons, and timestamps.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload and activate Brightery File Lockdown normally from Plugins &gt; Add New.<\/li>\n<li>Test normal media uploads and your update workflow.<\/li>\n<li>Apply the appropriate Apache or Nginx uploads rule from the included <code>server<\/code> directory.<\/li>\n<li>For admin-resistant protection, manually deploy the optional MU loader and its engine copy using trusted hosting, SSH, SFTP, or deployment access.<\/li>\n<li>Review <code>wp-config-example.txt<\/code> for optional server-side configuration.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20a%20wordpress%20administrator%20deactivate%20the%20plugin%3F\"><h3>Can a WordPress administrator deactivate the plugin?<\/h3><\/dt>\n<dd><p>In standard mode, yes. This respects the normal WordPress plugin lifecycle. For a compromised-admin threat model, manually deploy the included MU loader and engine copy using trusted server access.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20automatically%20write%20files%20outside%20its%20own%20directory%3F\"><h3>Does the plugin automatically write files outside its own directory?<\/h3><\/dt>\n<dd><p>No. The WordPress.org package does not automatically create or modify files in <code>wp-content\/mu-plugins<\/code> or other content directories.<\/p><\/dd>\n<dt id=\"why%20does%20must-use%20mode%20require%20two%20files%3F\"><h3>Why does Must-Use mode require two files?<\/h3><\/dt>\n<dd><p>The Must-Use loader is intentionally independent of the normal plugin directory. Deploying a copy of the engine beside the loader means the loader does not hardcode the normal plugin folder or rely on <code>WP_PLUGIN_DIR<\/code>.<\/p><\/dd>\n<dt id=\"does%20this%20block%20normal%20media%20uploads%3F\"><h3>Does this block normal media uploads?<\/h3><\/dt>\n<dd><p>Common image, audio, and video formats remain allowed. PDF is disabled by default and can be explicitly enabled in <code>wp-config.php<\/code>.<\/p><\/dd>\n<dt id=\"are%20plugin%20and%20theme%20updates%20blocked%3F\"><h3>Are plugin and theme updates blocked?<\/h3><\/dt>\n<dd><p>Updates are allowed by default. They can be disabled through server-side configuration constants when a site owner intentionally wants a stricter immutable-code workflow.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20data%20to%20brightery%3F\"><h3>Does the plugin send data to Brightery?<\/h3><\/dt>\n<dd><p>No. There are no telemetry, tracking, remote API, license-check, or external service calls.<\/p><\/dd>\n<dt id=\"where%20are%20security%20events%20stored%3F\"><h3>Where are security events stored?<\/h3><\/dt>\n<dd><p>The latest 100 blocked events are kept in a non-autoloaded WordPress option on the local site. Entries can contain the blocked filename, claimed MIME type, reason, and event time. IP addresses and user IDs are not collected.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20locally%20stored%20events%20when%20the%20plugin%20is%20uninstalled%3F\"><h3>What happens to locally stored events when the plugin is uninstalled?<\/h3><\/dt>\n<dd><p>The plugin removes its local blocked-event option during normal WordPress uninstall. Any manually deployed Must-Use files must be removed separately using trusted filesystem access.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>Updated the Contributors field to the WordPress.org owner username <code>brighterycom<\/code>.<\/li>\n<li>Defined the normal plugin location from <code>__FILE__<\/code> and <code>plugin_dir_path()<\/code> instead of relying on implicit paths.<\/li>\n<li>Reworked optional Must-Use deployment so the loader resolves a separately deployed engine relative to its own location.<\/li>\n<li>Removed the Must-Use loader dependency on <code>WP_PLUGIN_DIR<\/code> and the normal plugin folder slug.<\/li>\n<li>Added uninstall cleanup for the locally stored blocked-event option.<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Removed automatic writes to the Must-Use plugin directory from the WordPress.org build.<\/li>\n<li>Replaced file-based logging with a bounded local WordPress option.<\/li>\n<li>Removed direct PHP filesystem operations flagged by Plugin Check.<\/li>\n<li>Removed direct request-action inspection that generated nonce warnings.<\/li>\n<li>Removed runtime definition of the WordPress <code>DISALLOW_FILE_EDIT<\/code> constant; it is now documented as optional server configuration.<\/li>\n<li>Removed IP\/user actor logging.<\/li>\n<li>Added an explicit manual MU-loader workflow for administrator-resistant deployments.<\/li>\n<li>Retained WordPress 7.1 compatibility metadata.<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Updated compatibility metadata to WordPress 7.1.<\/li>\n<\/ul>","raw_excerpt":"Locks down code-changing capabilities and restricts WordPress uploads to approved media types.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/363905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=363905"}],"author":[{"embeddable":true,"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/brighterycom"}],"wp:attachment":[{"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=363905"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=363905"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=363905"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=363905"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=363905"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/so.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=363905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}