Medifence – Access Control for Media Uploads
by Redwoodcity 1 (0 reviews)

Medifence – Access Control for Media Uploads

Blocks direct access to uploaded media files for visitors who are not logged in. File URLs stay unchanged.

Medifence ranks #67,124 among WordPress.org plugins with 1+ active installations, is #4,427 of 6,314 in the Media category, a 1/5 rating from 0 reviews, and was last updated Jul 25, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1)
v1.17.0 Current Version v1.17.0
Updated 1 month ago Last Update on 25 Jul, 2026
Refreshed 8 hours ago Last Refreshed on
#4,427 of 6,314 in Media
View on WordPress.org
Rank
#67,124
-8074 this week
Active Installs
1+
-75%
KW Avg Position
N/A
No change
Downloads
403
+4 today
Support Resolved
0%
No change
Rating
20%
Review 1 out of 5
1 (0 reviews)

Next Milestone 10

Total Progress 10%
0+ 10+
66,416
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 10+

Rank Changes

45,739 51,999 58,258 64,518 70,777 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
45,739 51,999 58,258 64,518 70,777 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
Current #67,124
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 30 40 50 60 70 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
0 10 20 30 40 50 60 70 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
0 reviews
Overall 20%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Medifence – Access Control for Media Uploads

No. Existing URLs in posts, themes, and the database keep working exactly as before. Logged-in visitors see no difference at all.
The settings screen runs a live test: it creates a temporary file, requests it over HTTP without any session cookie, deletes it, and reports the status code. If your server configuration prevents the rules from working, you will see it there — not months later.
No. The plugin relies on .htaccess rewrite rules, which nginx does not support. You would need an equivalent rule in your nginx configuration, which is outside what a plugin can safely manage.
The rules are removed from the .htaccess file and all files are served normally again. Uninstalling additionally deletes the plugin's settings.
Medifence detects this and shows a warning on your admin screens. One click on "Regenerate .htaccess rules" restores them. A daily scheduled check also rewrites the rules on its own, so the protection comes back even if nobody logs in; you can turn that off in the settings.
Switch on the email notification in the settings. The daily check then sends one message when it finds that anonymous visitors can reach your files, and one more when the protection works again. It is sent only when the verdict changes, so a problem that persists does not fill your inbox, and a live test that could not reach the site at all is never reported as a failure. Use "Send a test email" first to confirm that this site can send mail at all.
Yes, one file: the .htaccess inside your uploads directory. The plugin uses WordPress's insert_with_markers() function, which only touches its own marked block and preserves everything else. The block is removed on deactivation and uninstall.
No. The live test sends one HTTP request to your own site. Nothing is sent anywhere else.
No. The optional access log records the file path, what happened to it, and when — no IP addresses, no user agents, and no user names, so it does not collect personal data. It is off unless you switch it on, keeps at most 200 files for 30 days, and can be cleared with one click.
Switch on the access log in the settings, then look at the Access log tab. It counts per file what Medifence did: blocked the request, served the placeholder, sent the visitor to the login screen, or accepted a share link. A file that is blocked over and over is usually one your theme or another plugin needs for everyone — exclude its extension or its folder.

Sign In / Register

You need to sign in or register to use this feature.