{"id":250130,"date":"2025-09-20T06:03:40","date_gmt":"2025-09-20T06:03:40","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/bf-secret-file-downloader\/"},"modified":"2026-09-22T13:42:15","modified_gmt":"2026-09-22T13:42:15","slug":"bf-secret-file-downloader","status":"publish","type":"plugin","link":"https:\/\/szl.wordpress.org\/plugins\/bf-secret-file-downloader\/","author":23358970,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.3","stable_tag":"1.0.3","tested":"7.1.2","requires":"6.8","requires_php":"7.4","requires_plugins":null,"header_name":"BF Secret File Downloader","header_author":"BREADFISH","header_description":"A plugin for securely managing and distributing private files to authenticated users.","assets_banners_color":"","last_updated":"2026-09-22 13:42:15","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/square.link\/u\/Kl16kA0b","header_plugin_uri":"https:\/\/sfd.breadfish.jp\/","header_author_uri":"https:\/\/breadfish.jp\/","rating":5,"author_block_rating":0,"active_installs":100,"downloads":1069,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"breadfish","date":"2025-09-20 14:15:33","revision":3365010},"1.0.2":{"tag":"1.0.2","author":"breadfish","date":"2026-07-09 11:13:49","revision":3601390},"1.0.3":{"tag":"1.0.3","author":"breadfish","date":"2026-09-22 13:42:15","revision":3707460}},"upgrade_notice":{"1.0.3":"<p>Improves protection on Nginx servers. The secure directory is automatically moved to a hidden directory. If you upload files via FTP, use the new directory shown in the admin notice.<\/p>","1.0.1":"<p>Security improvements and bug fixes. Recommended update for all users.<\/p>","1.0.0":"<p>Initial release of BF Secret File Downloader.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3364860,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1","1.0.2","1.0.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3364844,"resolution":"1","location":"assets","locale":"","width":2196,"height":1642},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3364844,"resolution":"2","location":"assets","locale":"","width":2196,"height":1642},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3364844,"resolution":"3","location":"assets","locale":"","width":2196,"height":1642}},"screenshots":{"1":"Admin file list page showing protected files","2":"Settings page with authentication options","3":"Frontend download interface"}},"plugin_section":[],"plugin_tags":[568,8848,600],"plugin_category":[54],"plugin_contributors":[248106],"plugin_business_model":[],"class_list":["post-250130","plugin","type-plugin","status-publish","hentry","plugin_tags-download","plugin_tags-file-manager","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-breadfish","plugin_committers-breadfish"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/bf-secret-file-downloader\/assets\/icon-256x256.png?rev=3364860","icon_2x":"https:\/\/ps.w.org\/bf-secret-file-downloader\/assets\/icon-256x256.png?rev=3364860","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/bf-secret-file-downloader\/assets\/screenshot-1.png?rev=3364844","caption":"Admin file list page showing protected files"},{"src":"https:\/\/ps.w.org\/bf-secret-file-downloader\/assets\/screenshot-2.png?rev=3364844","caption":"Settings page with authentication options"},{"src":"https:\/\/ps.w.org\/bf-secret-file-downloader\/assets\/screenshot-3.png?rev=3364844","caption":"Frontend download interface"}],"raw_content":"<!--section=description-->\n<p>BF Secret File Downloader is a WordPress plugin that automatically creates secure directories and allows you to manage files within them. The plugin creates protected storage areas automatically and provides comprehensive file management, directory management, and download functionality with advanced access control.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>Automatic Secure Directory Creation<\/strong>: System automatically creates protected directories with unique names<\/li>\n<li><strong>File Management<\/strong>: Browse, upload, and manage files in secure directories<\/li>\n<li><strong>Download Control<\/strong>: Secure download functionality with access control<\/li>\n<li><strong>Access Control<\/strong>: Multiple authentication methods including WordPress login and simple password<\/li>\n<li><strong>Directory Management<\/strong>: Organize files in automatically created protected directories<\/li>\n<li><strong>i18n Ready<\/strong>: Translation ready with Japanese and English support<\/li>\n<\/ul>\n\n<h4>Authentication Methods<\/h4>\n\n<ul>\n<li>WordPress user login (with role-based access)<\/li>\n<li>Simple password protection<\/li>\n<\/ul>\n\n<h4>Use Cases<\/h4>\n\n<ul>\n<li>Private document distribution<\/li>\n<li>Member-only file downloads<\/li>\n<li>Protected resource sharing<\/li>\n<\/ul>\n\n<h3>Security<\/h3>\n\n<p>This plugin implements several security measures:<\/p>\n\n<ul>\n<li>Automatic secure directory creation with unique names<\/li>\n<li>Protected directories with .htaccess and index.php files to prevent direct access<\/li>\n<li>Nonce verification for all admin actions<\/li>\n<li>Input sanitization and validation<\/li>\n<li>Path traversal protection<\/li>\n<li>Access control verification<\/li>\n<li>Direct file access prevention<\/li>\n<li>Program code file upload blocking (PHP, JS, Python, etc.)<\/li>\n<li>Hidden file and dangerous file pattern filtering<\/li>\n<li>Secure file upload and download handling<\/li>\n<\/ul>\n\n<h3>Support<\/h3>\n\n<p>For support and feature requests, please visit the plugin's support forum.<\/p>\n\n<h3>Donate<\/h3>\n\n<p>If you find this plugin useful, please consider making a donation to support its development.<\/p>\n\n<p><a href=\"https:\/\/square.link\/u\/Kl16kA0b\">Donate via Square<\/a><\/p>\n\n<!--section=installation-->\n<ol>\n<li>Activate the plugin through the 'Plugins' screen in WordPress.<\/li>\n<li>The plugin automatically creates a secure directory on activation.<\/li>\n<li>Use the BF Secret File Downloader-&gt;Settings screen to configure authentication methods.<\/li>\n<li>Access the File List page to start uploading and managing files in the secure directory.<\/li>\n<li>Share the generated download URL with users who need access to the files.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20file%20types%20are%20supported%3F\"><h3>What file types are supported?<\/h3><\/dt>\n<dd><p>The plugin supports most common file types including documents, images, archives, and media files. For security reasons, program code files are blocked, including PHP, JavaScript, Python, shell scripts, and other executable file types.<\/p><\/dd>\n<dt id=\"how%20secure%20is%20the%20download%20functionality%3F\"><h3>How secure is the download functionality?<\/h3><\/dt>\n<dd><p>The plugin implements multiple security layers including nonce verification, user authentication, and sanitized file paths to prevent unauthorized access.<\/p><\/dd>\n<dt id=\"how%20does%20the%20automatic%20directory%20creation%20work%3F\"><h3>How does the automatic directory creation work?<\/h3><\/dt>\n<dd><p>The plugin automatically creates secure directories with unique names when activated. These directories are protected with .htaccess and index.php files to prevent direct access and have unique names for additional security.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20nginx%3F\"><h3>Does it work on Nginx?<\/h3><\/dt>\n<dd><p>Yes. The secure directory is a hidden directory (its name starts with a dot) under wp-content\/uploads. Most Nginx configurations for WordPress deny access to hidden files and directories (<code>location ~ \/\\. { deny all; }<\/code>), so direct access is blocked without any additional configuration.<\/p>\n\n<p>The plugin checks whether direct access is actually blocked and shows a warning on its admin screens if it is not. In that case, add the following to your Nginx configuration, or ask your hosting provider to add it:<\/p>\n\n<pre><code>location ^~ \/wp-content\/uploads\/bf-secret-file-downloader\/ { deny all; }\n<\/code><\/pre>\n\n<p>If you upload files via FTP, enable the option to show hidden files in your FTP client.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20multisite%3F\"><h3>Is it compatible with multisite?<\/h3><\/dt>\n<dd><p>Currently, the plugin is designed for single-site installations.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>[ Spec Change ] Move the secure directory to a hidden (dot-prefixed) directory so that direct access is blocked on most Nginx servers, and migrate existing directories automatically (reported by Farid Muslimov (torr3s))<\/li>\n<li>[ Spec Change ] Check whether direct access to the secure directory is actually blocked and show a warning with an Nginx configuration example if it is not<\/li>\n<li>[ Bug Fix ] Add protection files to the base directory so that the secure directory name is not exposed by directory listing<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>[ Bug Fix ] Fix intermittent 30-second stalls on plugin activation and block editor screens caused by unconditional session_start() on every request<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fix: Removed dangerous htmlspecialchars_decode() usage for improved security<\/li>\n<li>Fix: Removed unnecessary inline script tag from admin interface<\/li>\n<li>Fix: Added proper translation support for directory name validation messages<\/li>\n<li>Improvement: Updated PHPUnit tests to match current implementation<\/li>\n<li>Maintenance: Removed temporary .bak files from distribution<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>Automatic secure directory creation<\/li>\n<li>File management functionality in protected directories<\/li>\n<li>Upload and download control with authentication<\/li>\n<li>Multiple authentication methods (WordPress login, simple password)<\/li>\n<li>i18n support for Japanese and English<\/li>\n<\/ul>","raw_excerpt":"Manage and provide download functionality for files in secure, auto-generated directories.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/250130","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=250130"}],"author":[{"embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/breadfish"}],"wp:attachment":[{"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=250130"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=250130"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=250130"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=250130"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=250130"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/szl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=250130"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}