FolderPress

The complete media manager for WordPress — nested folders & tags, image optimization, CDN delivery, private folders with share links, two-factor login, a REST API and backups. This guide covers every screen.

Installation

  1. In WordPress admin go to Plugins → Add New → Upload Plugin and choose folderpress.zip (or unzip it into /wp-content/plugins/).
  2. Click Activate.
  3. Open Media → FolderPress — the app opens in its own browser tab and takes over the full window.

Requirements: WordPress 6.0+, PHP 8.0+. The Imagick PHP extension is recommended for image optimization and watermarking (the plugin detects it and shows an honest status if it's missing).

First run & guided tour

On first open you'll see the Welcome screen with a feature overview. Choose Take the tour for an 8-step guided walkthrough of the sidebar, search, filters, uploads, optimization, activity log and settings — or Browse files to jump straight in. You can re-run the tour anytime from the keyboard-shortcuts dialog (?) or reopen the welcome screen from the sidebar footer.

Folders & tags

Library, layouts & search

Uploads & upload rules

Upload with the header button, by dragging files anywhere onto the app, or straight onto a folder. The modal shows per-file progress and closes itself when everything succeeded. An optional rule files new uploads into month folders automatically.

Upload rules (Settings hub → Library → Upload rules) give you site-wide control:

Image optimization

Watermarking

Text or logo watermarks applied during optimization: pick any image from your library as the logo (or type text), choose one of nine positions or tiling, and set opacity, scale and margin. Enable it in Settings → Watermark, and it applies to future optimizations.

CDN delivery

Cloud storage (S3-compatible)

Offload media to Amazon S3, Cloudflare R2, DigitalOcean Spaces, Backblaze B2 or Google Cloud Storage (interop mode). Enter endpoint/bucket/keys, hit Test connection (the plugin performs a real write+delete probe), then enable offload. New uploads copy up automatically, deletions propagate, and URLs rewrite to your bucket or its public CDN URL. A batch tool syncs the existing library.

Private folders

Mark any folder Private in Folder settings (or the padlock toggle in the Permissions overview) and its files are physically moved out of the public uploads tree into a web-blocked protected area. The old /wp-content/uploads/… links genuinely stop working — this is real enforcement, not a cosmetic flag.

Heads-up: content already embedded in published posts keeps its old URL, which will 404 once the folder is private. Re-embed from the library (URLs update automatically) or use a share link.

Share links

Hand any file — or a whole folder — to someone with no WordPress login. Right-click → Share link…, or use the Share button in the file drawer / folder settings.

Two-factor login

Settings hub → Security → Two-Factor Authentication. Three real methods, per user:

MethodHow it works
Authenticator appScan the QR code with Google Authenticator, 1Password, Authy… then codes are required at login (TOTP, RFC 6238).
SMS codeSite-wide Twilio credentials + the user's phone number; a code is texted at login.
Security keyHardware keys or platform biometrics via WebAuthn/FIDO2 (YubiKey, Windows Hello, Touch ID).

Permissions, sessions & quotas

REST API

Settings hub → Developer → API Keys & Webhooks. Create a key (Read or Read & write, with optional expiry and IP allowlist) and call the API with a Bearer token. The screen shows your site's exact base URL.

# List files
curl -H "Authorization: Bearer fpk_YOUR_KEY" \
  "https://your-site.com/wp-json/folderpress/v1/files"

# Upload (multipart)
curl -H "Authorization: Bearer fpk_YOUR_KEY" \
  -F "file=@photo.jpg" -F "folder=12" \
  "https://your-site.com/wp-json/folderpress/v1/files"
EndpointMethodsPurpose
/filesGET, POSTList (filter by folder/tag/type/search) · upload
/files/<id>GET, DELETEDetails · trash (?force=1 deletes)
/foldersGET, POSTTree with counts · create
/tagsGETAll tags with counts

Keys are stored hashed; usage (today / this month / last used) meters live in the UI; rate-limit tiers apply per key with standard X-RateLimit-* headers. If your site uses plain permalinks the panel shows the working index.php?rest_route= base automatically.

Webhooks & notifications

Backups & restore

AI alt text

Generate descriptive alt text for images using Anthropic Claude or OpenAI — your API key, stored server-side and visible to administrators only. Generate per image (with preview) or batch-fill everything that's missing alt text; optionally auto-generate on upload.

Localization

Keyboard shortcuts

KeyActionKeyAction
/Focus searchUUpload
↑↓←→Move cursorEnterOpen details
SpaceSelect / deselectASelect all
FFavoriteNNew folder
G L CGrid / List / ColumnsDLight / dark
DelTrash selection?This list + tour

Uninstalling

Deactivate and delete from the Plugins screen. The uninstaller removes all plugin data (options, activity log, folders/tags, meta, scheduled tasks) and — before anything else — moves every private file back into the public uploads folder, so nothing is ever stranded. Your media files and the .fp-orig originals are never deleted.

FAQ

Does FolderPress move or rename my upload files?

No — folders are virtual (a taxonomy). The only exception is folders you explicitly mark Private, and those files return the moment the folder is public again (or on uninstall).

Will it work with my page builder?

Yes — the folder filter appears inside the standard WordPress media modal, which Gutenberg, Classic and most builders use.

Is the free CDN really free?

Yes — it uses a public image CDN that requires no account. For business-critical delivery you can plug in your own CDN domain instead.

I locked myself out with 2FA.

Create an empty file called fp-2fa-off inside wp-content/ (FTP, SSH or your host's file manager). 2FA is bypassed while it exists — log in, fix your method, delete the file.

Something in the UI looks stale after updating.

Hard-refresh the FolderPress tab (Ctrl/Cmd+Shift+R) and clear any page-cache plugin. Assets are version-stamped, so this resolves itself.

Support

When reporting an issue please include your WordPress + PHP versions and what the Activity log shows around the time of the problem.