[WordPress] 外掛分享: Kodlo Media Manager

首頁外掛目錄 › Kodlo Media Manager
WordPress 外掛 Kodlo Media Manager 的封面圖片
100+
安裝啟用
尚無評分
4 天前
最後更新
問題解決
WordPress 6.6+ PHP 7.4+ v1.8.7 上架:2026-06-17

內容簡介

Kodlo Media Manager 外掛讓使用者能夠為媒體庫設定清晰且一致的上傳規則,確保上傳的媒體格式、大小、維度及檔名符合要求,提升媒體管理的效率與安全性。

【主要功能】
• 定義媒體上傳格式與規則
• 支援 SVG 和 WebP 格式上傳
• 獨立控制各種媒體格式的政策
• 正規化檔名以避免重複
• 本地處理 SVG 檔案以確保安全
• 在熟悉的 WordPress 界面中設定

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.8.7) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Kodlo Media Manager」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Turn your Media Library requirements into clear, consistent upload rules.
Kodlo Media Manager adds a focused rules builder to Settings -> Media. Define which formats WordPress may accept, where each format is allowed, how large an upload may be, which image dimensions are acceptable, and how filenames should be formatted.
The plugin validates uploads on the server and provides early feedback in the standard WordPress media uploader. It uses native WordPress, PHP, and browser APIs and includes no third-party libraries or external services.
Why Use Kodlo Media Manager?

Keep upload standards consistent: Replace written instructions with rules WordPress can enforce for supported upload flows.
Start using SVG and WebP without code: Fresh installations include ready-to-use Media Library rules for both formats.
Avoid an extra SVG upload plugin: SVG permission, MIME handling, size limits, and sanitization are managed in one place.
Control each format separately: Give SVG, WebP, AVIF, video, document, font, and archive formats their own policy and limits.
Reduce duplicate filename clutter: Optionally block an exact normalized filename when it already exists in the Media Library.
Normalize filenames: Mirror WordPress locale-aware accent conversion, transliterate supported Cyrillic characters, apply a predictable separator, and validate the final name.
Handle SVG locally: Sanitize canonical .svg uploads with an internal allowlist before WordPress stores them.
Keep sensitive media processing local: Files are validated on your server without cloud processing, telemetry, or external services.
Protect editorial workflows: Browser feedback and authoritative server validation apply the same upload policy consistently.
Stay inside familiar WordPress screens: Configure everything on the native Media Settings page and use the standard media uploader.

SVG and WebP Ready After Activation
On a fresh installation, Kodlo Media Manager automatically configures SVG and WebP uploads for the standard WordPress Media Library. No code snippet, manual MIME filter, or separate SVG upload plugin is required.
SVG files are sanitized locally on the server before WordPress stores them. The plugin removes unsupported or potentially active content, rejects external references and malformed SVG documents, and accepts only the canonical .svg extension and image/svg+xml MIME type.
WebP files can be uploaded and used through the normal WordPress media workflow while the plugin enforces the configured MIME type, file size, image dimensions, filename, and duplicate rules.
Upload Rules
Each rule combines a file extension and MIME type with one of three policies:

Allowed (Media Library Only): Accept the format in verified WordPress Media Library upload contexts.
Allowed (Globally): Allow the format in other WordPress upload contexts as well.
Blocked (Globally): Reject the format throughout WordPress upload handling.

WordPress uses several upload flows beyond the Media Library. Importers, plugin and theme installers, custom frontend forms, and third-party tools may upload files through different WordPress endpoints. The separate policies let you allow a format only where it is needed instead of enabling it for every upload flow on the site.
Allowed (Media Library Only) is the recommended choice for content files such as SVG, WebP, AVIF, PDF, and regular images. It includes uploads made through the standard Media Library modal used by WordPress editors and normal Elementor image controls. Selecting or reusing a file that is already in the Media Library is not restricted by these upload policies.
Use Allowed (Globally) only when the format must also work outside the standard Media Library, such as through an importer, a custom upload form, or a third-party tool with its own upload endpoint. Some specialized Elementor features or add-ons may use such custom endpoints even though normal Elementor image selection uses the WordPress Media Library.
An administrator can also set a per-format maximum file size and, for raster images, maximum width and height. Dangerous executable and active-content formats remain unavailable even if they are submitted through malformed settings data.
Filename and Duplicate Controls
The filename validator accepts a bounded regular-expression subset shared by PHP and JavaScript. Unsupported, malformed, or excessive patterns fall back to the plugin’s safe default. Optional auto-sanitization can reshape filenames for compatible positive character-class patterns before validation; safe validation-only patterns remain available without automatic rewriting.
Duplicate Guard compares exact normalized basenames rather than image contents. Every distinct filename is checked directly against Media Library attachment metadata. Short-lived hashed upload locks prevent two plugin-managed requests from claiming the same available filename at the same time, without building a filename index or custom database table.
SVG Handling
The internal SVG sanitizer accepts a limited set of SVG elements and attributes, removes unsupported content, rejects document types and entities, and permits only safe internal fragment references. It also applies a fixed payload ceiling before DOM parsing. SVG content must use the canonical .svg extension and image/svg+xml MIME pair.
SVG sanitization is a focused upload safeguard. It does not replace appropriate WordPress capabilities, server hardening, backups, or review of untrusted content.
Media Uploader Experience
The browser-side guard mirrors format, filename, size, dimension, and duplicate checks to provide feedback before an upload begins. Asynchronous dimension probes and duplicate lookups share one validation barrier, use bounded batches, concurrency, and timeouts, and finish before a paused queue resumes. Invalid or unavailable duplicate responses stop affected files and explain the failure. Server-side validation remains authoritative for native uploads and sideload-based REST uploads.
Warning dialogs use native button semantics, labelled dialog markup, Escape handling, managed keyboard focus, and focus restoration. Settings controls include accessible names and predictable focus movement when rules are added or removed.
Default Configuration
The initial rules allow ZIP globally so WordPress can upload plugin and theme packages. SVG, WebP, AVIF, MP4, WebM, PDF, DOCX, and WOFF2 start in Media Library contexts with format-specific limits, while JPG, JPEG, and PNG start blocked. These defaults are a starting point, not a universal recommendation; review them for your site’s editorial workflow and hosting limits.
By default, verified uploads initiated by an administrator from WordPress General Settings bypass format, filename, duplicate, size, and dimension policies so core settings such as the site icon are not unexpectedly blocked. SVG files are still sanitized. Enable General Settings Page Uploads to apply the configured policies there as well.
Deactivation and Uninstall
Deactivating Kodlo Media Manager turns off its upload rules and interface but preserves all saved settings, so the same configuration is available if the plugin is activated again.
Deleting the plugin through the WordPress Plugins screen runs its uninstall cleanup. The plugin removes all of its saved settings and any remaining temporary upload locks, including across a WordPress Multisite network, leaving no plugin-specific options or custom database tables behind.
Try It Before Installing
Use Live Preview on WordPress.org to explore the upload rules directly in Settings -> Media before installing the plugin.
Security
Security Contact: https://kodlo.dev/
Report a suspected vulnerability privately through the Contact button at that address. Please include the affected plugin version, WordPress and PHP environment details, observed impact, reproducible steps, required privileges, and a minimal proof of concept.
Do not include passwords, API keys, customer data, or other credentials. Do not publish exploit details in a support topic before the report can be assessed. Use the public support forum only for non-sensitive support questions.
The packaged SECURITY.md documents supported versions, coordinated disclosure, and an expected initial response within five business days.
PHP 8.2 or newer is recommended for production because it remains supported by the PHP project. PHP 7.4 is the plugin’s minimum compatibility requirement, not a recommendation to operate an unsupported PHP branch.
Privacy
Kodlo Media Manager operates locally and does not send upload data, filenames, settings, telemetry, or analytics to Kodlo or any other external service.
The plugin stores its configuration in WordPress options. Duplicate Guard does not create a filename index or custom table. During an upload it may store a short-lived site option containing a filename hash, ownership token, and timestamp; the original filename is not stored in that lock.
Deactivation preserves the plugin settings. Successful upload locks are removed immediately; an abandoned expired lock is reclaimed when the same filename is checked again.

延伸相關外掛

文章
Filter
Mastodon