Protect your uploads directory. Prevent browsing, add watermarks, disable right-click, and password-protect files. For more information, visit protect …
As of April 2026, Protect Uploads is a WordPress uploads plugin with 40K+ active installations and a 4.8/5 rating from 12 reviews. It has been downloaded 1.4M+ times in total. Requires WordPress 3.0.1+ and PHP 7.0+. Available on WordPress.org since 2015. Downloads are down 7% this week. Top alternative: Add From Server.
The uploads directory is where the files of the WordPress library are stored. Unfortunelty, this directory is not protected. A person who wants to see all your library could list it instantly going to : http://yourwebsite/wp-content/uploads . This plugin will hide the content by adding an index.php file on the root of your uploads directory or by setting an htaccess which will return a 403 error (Forbidden Access).
New Features in Version 0.6.0:
Thanks!
Tried with “Protect with index.php files“
Tried with “Protect with .htaccess file“
Neither one works. PDF happily appears in another browser where I’m not logged in, it’s got a little menu, it loads completely, and the crooks are off and away with my property. WordPress 6.2.
Thanks. Have a nice day.
This plugin is not malware.
The ‘malware’ you claim is a ‘fake plug-in’ created by a web server being hacked.
A year after downloading this plug-in from the official WordPress.org , my site is still very fine and secure. Don’t be fooled by fake reviews.
It just does what it has to do.
Restrict free browsing of your WP-content folder and subfolder.
You can still access a specific file if you have the exact path but you cannot sneak around any longer.
Still works great on wp 5.8
| WordPress | 3.0.1+ requiredTested up to 6.9.4 |
| PHP | 7.0+ required |
…and 4 more changes
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.