Restrict WP Upload Type
Restrict WP Upload Type
Description
Restrict WP Upload Type gives you complete control over which files your users can upload to WordPress. Prevent security risks, maintain brand standards, and eliminate media library chaos with granular file type controls.
Why You Need Upload Restrictions
Uncontrolled uploads create serious problems:
- Security vulnerabilities from unvetted file types
- Brand inconsistency from mixed formats
- Media library bloat from oversized files
- Wasted time managing user uploads
- Compliance violations with upload policies
What This Plugin Does
- Control over 97 file extensions and MIME types
- Allow or block any format with a single click
- Dedicated SVG file management with security
- Real-time upload validation (prevents bad uploads before they happen)
- Clear, customizable file type error messages guiding users to approved formats
- Global file size limit controls
- Zero configuration complexity—works instantly
Who Should Use This
- WordPress site owners wanting better media management
- Teams needing consistent upload policies
- Digital agencies managing multiple client sites
- Organizations with compliance requirements
- Anyone managing user permissions on WordPress
Key Features
- Comprehensive Format Support: Images (PNG, JPG, GIF, WebP, SVG, HEIC), Documents (PDF, DOCX, XLSX, PPT), Audio/Video (MP3, MP4, WAV, AVI), Archives (ZIP, RAR, 7Z), and more
- Flexible Controls: Whitelist allowed formats or blacklist restricted ones
- SVG Security: Dedicated toggle for SVG files with proper MIME type handling
- Lightweight Design: Minimal server overhead, zero performance impact
- User Feedback: Clear, customizable messages when file type uploads are blocked
- File Size Limits: Set a global maximum upload size from the plugin settings
- WordPress Integrated: Works with Gutenberg, classic editor, REST API uploads, and block-based themes
How It Works
- Install and activate the plugin
- Visit Media > Restrict Files
- Check the boxes for file types you want to allow
- Click Save
- Done! Your restrictions are immediately active
Installation & Setup
The plugin requires zero configuration. Default settings allow common media formats. Customize by selecting exactly which types your site needs. Changes take effect immediately.
Tested Compatibility
- WordPress 5.4 through 6.8+
- PHP 5.6+
- Multisite compatible
- All modern browsers
- Gutenberg block editor
- WooCommerce (for product uploads)
What Users Are Saying
“Simple, fast, and objective.” — 5-star review
“Excellent little plugin that will prove very useful.” — 5-star review
“Works like a charm. Simple to configure and highly effective.” — 5-star review
Performance Impact
This plugin adds minimal overhead. It uses lightweight MIME type filtering without database bloat. Your site’s speed remains unaffected.
Future Roadmap
We’re actively developing Restrict WP Upload Type based on user feedback. Planned features include role-based restrictions, custom MIME management, and upload logs.
Support
Have questions? Visit our support forum on WordPress.org. We’re here to help!
Learn More
Donate link
- If you’d like to support development, please visit https://profiles.wordpress.org/kushang78/
What about security?
The plugin validates both file extensions and MIME types server-side to prevent header manipulation. It follows WordPress security best practices and standards.
Can I override the restrictions for specific users?
Not in the current version. The plugin applies restrictions globally. This feature is being considered for future versions.
How often is this plugin updated?
The plugin is actively maintained and updated as needed for WordPress compatibility and bug fixes. Subscribe to the support forum for update notifications.
What if I find a bug?
Please report issues in the support forum:
https://wordpress.org/support/plugin/restrict-wp-upload-type/
We take all bug reports seriously and work to fix them promptly.
Does this plugin work with multisite?
Yes, it’s fully compatible with WordPress multisite. Each site in the network can have its own upload restrictions.
Can I test the plugin on a staging site first?
Absolutely! We recommend testing on a staging/development site first, then deploying to production.
Installation
Method 1: Direct Installation (Recommended)
- Log into your WordPress admin panel
- Go to Plugins Add New
- Search for “Restrict WP Upload Type”
- Click Install Now
- Click Activate
- Visit Media > Restrict Files to configure your upload restrictions
Installation takes less than 1 minute.
Method 2: Manual Installation (FTP)
- Download the plugin from WordPress.org
- Unzip the downloaded file
- Upload the
restrict-wp-upload-typefolder to/wp-content/plugins/via FTP - Log into WordPress and go to Plugins
- Find “Restrict WP Upload Type” in the list
- Click Activate
- Configure via Restrict Files page
Getting Started
After activation:
1. Navigate to Media > Restrict Files in your WordPress admin
2. Review the list of 97 file types
3. Check the boxes for formats you want to allow (uncheck to restrict)
4. Click Save Changes
5. Your upload restrictions are immediately active
That’s it! Wrong formats will now be blocked with a clear error message.
Need Help?
- Check the FAQ section below
- Visit the support forum: https://wordpress.org/support/plugin/restrict-wp-upload-type/
Screenshots
Faq
Restrict WP Upload Type supports 97 file extensions with their corresponding MIME types. This includes:
* Images: PNG, JPG, GIF, WebP, SVG, HEIC, BMP, TIFF, ICO, JPEG
* Documents: PDF, DOCX, DOC, XLSX, XLS, PPTX, PPT, ODT, ODP, ODS
* Audio: MP3, WAV, M4A, FLAC, OGG, AAC, WMA, AIFF
* Video: MP4, AVI, MOV, WMV, FLV, MKV, WEBM, 3GP
* Archives: ZIP, RAR, 7Z, TAR, GZ, BZ2, CAB
* And many more…
No. This plugin only controls new uploads. Previously uploaded files are unaffected and remain accessible.
Yes! SVG files have a dedicated toggle in the plugin settings. This allows you to independently control SVG uploads with proper MIME type validation and security considerations.
They receive a clear, user-friendly error message indicating the file type isn’t allowed. You can customize this file type message from Media > Restrict Files.
Example: “Upload blocked by Restrict WP Upload Type. This file type is not allowed on this site.”
Yes. Restrict WP Upload Type works with WordPress multisite installations. Each site can maintain independent upload restrictions.
No. The plugin uses lightweight MIME type filtering with minimal server overhead. Performance impact is negligible—your site’s speed remains virtually unchanged.
The current version applies restrictions globally to all users. For role-based restrictions, consider combining with user role management plugins. This feature is on our roadmap for future versions.
Settings are stored in your WordPress options table (wp_options). When you uninstall the plugin, all settings are removed. You can backup your configuration through WordPress backup solutions.
Yes. You can set a global maximum file size in MB from Media > Restrict Files. Use 0 to follow your server and WordPress upload limits.
Yes. The plugin will apply file restrictions to WooCommerce product uploads as well. Configure the allowed file types in the plugin settings.
- Allow: Check boxes for formats you want to permit. All others are blocked.
- Restrict: In future versions, we’ll add an option to specify blocked formats
while allowing everything else.
Currently, the plugin works on an “allow” basis for security.
Restrict WP Upload Type is 100% free with no upsells or premium tier. All features are available to every user.
- Check this FAQ section
- Visit the support forum: https://wordpress.org/support/plugin/restrict-wp-upload-type/
- Review the plugin settings after installation
Reviews
Excellent
By superbr on January 30, 2025
Simple, fast and objective.
It worked great until it didn't
By daphnetalbot on May 7, 2024
I have this installed on several sites. Everything is working except for one. Settings would not save. Even though I deleted the plugin, my client is barred from all uploads. I posted in the support area but there is no reply to the ticket. Now my client cannot upload documents even though I removed the plugin. Really need to know where the settings are that this plugin created so I can undo them.
Great little plugin
By tufty on May 6, 2024
Excellent little plugin that will prove very useful. My use case for this is to discourage colleagues from uploading things they aren't supposed to, such as:
- png, because almost certainly it's a large file and may have transparency that we don't need
- webp, because we still have plenty of customers with older safari versions that can't use webp. We use cloudflare to deliver webp dynamically, so we want the site itself to have one version that is fully compatible as a fallback.
This plugin could be improved further by:
- Tucking the Restrict Files admin menu item inside the media menu, and saying in the documentation where it is.
- Adding a file size restriction.
- Adding to the upload failure message to say what plugin has caused this limitation, so that a user has a clue what to do if they need an exception. "Sorry, you are not allowed to upload this file type, as it has been limited by the Restrict Files plugin."
Works like a charm
By makemyday on July 6, 2022
Changelog
1.1.0 (July 07, 2026)
- Added Restrict Files under the WordPress Media menu
- Added global maximum file size restriction
- Added customizable blocked file type message
- Improved blocked upload validation before WordPress shows the generic security error
- Added settings search and enabled/disabled extension filters
- Added nonce protection to the settings form
- Added uninstall cleanup for new settings
1.0.4 (May 24, 2026)
- Added support for
.jsonand.epubupload types - Improved plugin cleanup during deactivation and uninstall
- Converted admin settings JavaScript to vanilla JavaScript
- Updated plugin version and readme metadata
1.0.3 (December 27, 2024)
- Fixed: Checkbox design improvements for better usability
- Fixed: MIME type value selection issue after form submission
- Improved: Overall UI responsiveness
1.0.2 (December 3, 2023)
- Fixed: SVG MIME type validation and handling
- Fixed: Multiple minor bugs and edge cases
- Improved: Error message clarity
1.0.1 (Previous)
- Bug fixes and minor improvements
1.0.0 (April 14, 2022)
- Initial Release: Core functionality for file type restrictions
- 97 file types supported
- SVG file management
- WordPress media library integration



