• Hi,

    I have recently installed WordPress download manager plugin but its server file browser show my root server and another website too.

    How can I limit the server file Browser for my Website Directory or specific directory?

    Thanks

    • This topic was modified 6 years, 2 months ago by Rajibul Islam.
Viewing 4 replies - 1 through 4 (of 4 total)
  • Plugin Support Nayeem Hyder

    (@nriddhi)

    Hi,

    You can do it from Downloads > Settings > Basic adjusting Server File Browser option also checking the Reset Base Dir button. I hope it will help you.

    Thanks.

    Thread Starter Rajibul Islam

    (@rajibms)

    @nriddhi Thanks for your response.

    After following your instructions it worked to browse my website directly. But after changing the directory it can browse the root folder again.

    Is there any option to remove server file browsing?

    I am fearing because if a hacker hacks my website then he will get server root and also know other websites.

    Plugin Contributor Shafaet Alam

    (@shafayat-alam)

    Hi,
    You can allow file browser access only to the administrator, only admin has access to wpdm settings, so other user levels will not have access to the asset manager and also can’t change settings. So, there is nothing to worry. However, in the next update, we are introducing a constant to disable asset manager.

    Thread Starter Rajibul Islam

    (@rajibms)

    @shafayat-alam Thanks for your response.

    I got it and researched over the WPDM plugin even I am not a developer. I am glad to know that you are adding option to disable asset manager.

    Here is another thing I will suggest WPDM team,

    There are many options available in WPDM plugin and that’s great but browsing a server root directory and it’s not safe, May server contains other websites and many files/folders. If you specify a WPDM folder and it will be best for future management and it will not affect in server migration and other changes. I think the specified folder for WPDM is a good option. (I am asking this because WPDM can get access to other domains/websites in my servers)

    Also if you hide the .php .htacces then it will more safe and nobody need to download WordPress core Php or other server-based files.

    I hope you will consider this and this is my personal opinion and you can also ignore this if you don’t like it.

    Thanks again.

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Limit Directory for Server File Browser’ is closed to new replies.