FolderPress
Installation
- In WordPress admin go to Plugins → Add New → Upload Plugin and choose
folderpress.zip(or unzip it into/wp-content/plugins/). - Click Activate.
- Open Media → FolderPress — the app opens in its own browser tab and takes over the full window.
Requirements: WordPress 6.0+, PHP 8.0+. The Imagick PHP extension is recommended for image optimization and watermarking (the plugin detects it and shows an honest status if it's missing).
First run & guided tour
On first open you'll see the Welcome screen with a feature overview. Choose Take the tour for an 8-step guided walkthrough of the sidebar, search, filters, uploads, optimization, activity log and settings — or Browse files to jump straight in. You can re-run the tour anytime from the keyboard-shortcuts dialog (?) or reopen the welcome screen from the sidebar footer.
Folders & tags
- Create folders from the sidebar + button; nest to any depth; give each a color.
- Move files by dragging them onto a folder (sidebar row or folder card). Drag a folder onto another folder to re-parent it.
- Right-click any folder for the context menu: Open, Rename, Share link, Settings, Delete. Right-click any file for Preview, Favorite, Copy URL, Share link, Trash.
- Tags live below folders in the sidebar — color-coded, filterable, with merge and rename in Settings → Tags.
- Deleting a folder never deletes files — they become Unassigned; subfolders move up one level.
Library, layouts & search
- Quick views: All files, Unassigned, Recent, Favorites, Trash.
- Layouts: grid, list and column (Miller) view, plus a thumbnail-density slider.
- Filters: type chips (Images, Video, Audio, Documents, Archives) and folder-color chips.
- Search covers filename, title, caption and alt text across the whole library.
- Click a file for the detail drawer (alt text, caption, folder, favorite, Copy URL, Share); double-click for the lightbox preview.
- Select multiple files for the bulk bar: move, edit metadata, download as .zip, trash / restore / delete forever.
- The folder filter also appears inside the standard WordPress media modal (Gutenberg, Classic editor and page builders that use
wp.media).
Uploads & upload rules
Upload with the header button, by dragging files anywhere onto the app, or straight onto a folder. The modal shows per-file progress and closes itself when everything succeeded. An optional rule files new uploads into month folders automatically.
Upload rules (Settings hub → Library → Upload rules) give you site-wide control:
- Every WordPress file type as clickable chips, grouped (Images / Video / Audio / Documents / Archives / Text) — click to block or re-allow a type; per-group "block all".
- Opt-in extra types: SVG (with a security warning), JSON, Markdown, WOFF2, EPUB, STL.
- A site upload-size cap, up to whatever your server allows (the screen shows the real server ceiling).
Image optimization
- Automatic on upload: new images are compressed (and optionally converted to WebP or AVIF) the moment they arrive.
- Batch: optimize the whole existing library with one click; the screen shows measured savings (real bytes, not estimates) and per-folder overrides.
- Quality, maximum dimensions (auto-resize) and EXIF stripping are configurable.
- SAFE The first optimization keeps an untouched
.fp-origcopy of every image, and a re-encode that would grow the file is rolled back automatically.
Watermarking
Text or logo watermarks applied during optimization: pick any image from your library as the logo (or type text), choose one of nine positions or tiling, and set opacity, scale and margin. Enable it in Settings → Watermark, and it applies to future optimizations.
CDN delivery
- Zero-config free CDN: one toggle rewrites image URLs to a free global image CDN — no account, no keys. Use Verify delivery to fetch a real library image through the CDN and confirm it works (response time and edge headers are shown).
- Custom CDN domain: if you have your own CDN (CloudFront, Bunny, KeyCDN…), enter the CNAME and verify.
- Cloudflare analytics: add an API token + zone to see 7-day requests, bandwidth and cache-hit ratio right in the panel.
Cloud storage (S3-compatible)
Offload media to Amazon S3, Cloudflare R2, DigitalOcean Spaces, Backblaze B2 or Google Cloud Storage (interop mode). Enter endpoint/bucket/keys, hit Test connection (the plugin performs a real write+delete probe), then enable offload. New uploads copy up automatically, deletions propagate, and URLs rewrite to your bucket or its public CDN URL. A batch tool syncs the existing library.
Private folders
Mark any folder Private in Folder settings (or the padlock toggle in the Permissions overview) and its files are physically moved out of the public uploads tree into a web-blocked protected area. The old /wp-content/uploads/… links genuinely stop working — this is real enforcement, not a cosmetic flag.
- Inside the library everything keeps working — thumbnails, previews, optimization, zips — served through an authentication-checked stream.
- Per-role View permissions on the folder are honored; administrators always have access.
- Subfolders inherit privacy from a private parent; files moved into a private folder are protected automatically, and moved back out when the folder (or file) leaves.
- Switching the folder back to Shared restores the files and their original URLs exactly.
Share links
Hand any file — or a whole folder — to someone with no WordPress login. Right-click → Share link…, or use the Share button in the file drawer / folder settings.
- Expiry: 1 hour, 24 hours, 7 days, 30 days, or never. Expired links show a friendly "link expired" page.
- Folder links open a clean public gallery (thumbnails, sizes, download buttons) covering the folder and its subfolders.
- Each link shows its view count; Revoke kills it instantly — even for someone who already opened it.
- The token is the authorization — links work for private and public files alike. Bad-token guessing is rate-limited per IP, and every create/revoke lands in the activity log.
Two-factor login
Settings hub → Security → Two-Factor Authentication. Three real methods, per user:
| Method | How it works |
|---|---|
| Authenticator app | Scan the QR code with Google Authenticator, 1Password, Authy… then codes are required at login (TOTP, RFC 6238). |
| SMS code | Site-wide Twilio credentials + the user's phone number; a code is texted at login. |
| Security key | Hardware keys or platform biometrics via WebAuthn/FIDO2 (YubiKey, Windows Hello, Touch ID). |
- Recovery codes download automatically on first enrollment — single-use each.
- Require 2FA for the team: one switch corrals every media user to the enrollment screen until they're set up; admins see an enrollment status list.
- Emergency kill switch: create an empty file at
wp-content/fp-2fa-off(via FTP/SSH) to disable all 2FA checks if you ever lock yourself out. Delete it afterwards.
Permissions, sessions & quotas
- Folder permissions: per-role View / Upload / Edit on every folder, in Folder settings or the all-folders Permissions overview.
- Sessions & devices: see every logged-in device (browser, IP, last active) and sign out any single device — or all others at once.
- Quotas: per-role storage limits with block or warn behavior, and a plan-wide cap, with live usage metering.
- Access log: browsable log of logins and actions with filters and CSV export.
REST API
Settings hub → Developer → API Keys & Webhooks. Create a key (Read or Read & write, with optional expiry and IP allowlist) and call the API with a Bearer token. The screen shows your site's exact base URL.
# List files
curl -H "Authorization: Bearer fpk_YOUR_KEY" \
"https://your-site.com/wp-json/folderpress/v1/files"
# Upload (multipart)
curl -H "Authorization: Bearer fpk_YOUR_KEY" \
-F "file=@photo.jpg" -F "folder=12" \
"https://your-site.com/wp-json/folderpress/v1/files"
| Endpoint | Methods | Purpose |
|---|---|---|
/files | GET, POST | List (filter by folder/tag/type/search) · upload |
/files/<id> | GET, DELETE | Details · trash (?force=1 deletes) |
/folders | GET, POST | Tree with counts · create |
/tags | GET | All tags with counts |
Keys are stored hashed; usage (today / this month / last used) meters live in the UI; rate-limit tiers apply per key with standard X-RateLimit-* headers. If your site uses plain permalinks the panel shows the working index.php?rest_route= base automatically.
Webhooks & notifications
- Webhooks: add endpoint URLs and click the event chips (upload, delete, move, folder changes…) each should receive. Deliveries are signed with an HMAC
X-FP-Signatureheader; the last delivery status shows per endpoint. - Email / Slack: per-event notification matrix with quiet hours and hourly/daily digest options; test buttons send a real message so you know the channel works before relying on it.
Backups & restore
- Snapshots capture your folder tree, tags (with colors), file assignments and favorites — plus settings if selected. Take them manually or on a schedule (with retention).
- Restore recreates the exact structure — folders, tag colors, assignments, favorites — and asks separately before touching settings.
- Export / import any restore point as JSON to move a structure between sites.
AI alt text
Generate descriptive alt text for images using Anthropic Claude or OpenAI — your API key, stored server-side and visible to administrators only. Generate per image (with preview) or batch-fill everything that's missing alt text; optionally auto-generate on upload.
Localization
- Interface chrome in English, Spanish, French, German, Portuguese, Japanese — switching languages retranslates live, no reload.
- Date format (MM/DD/YYYY · DD/MM/YYYY · YYYY-MM-DD) and 12/24-hour time apply to file cards, logs and backups.
- Right-to-left layout mirror, first day of week, and time zone.
Keyboard shortcuts
| Key | Action | Key | Action |
|---|---|---|---|
| / | Focus search | U | Upload |
| ↑↓←→ | Move cursor | Enter | Open details |
| Space | Select / deselect | A | Select all |
| F | Favorite | N | New folder |
| G L C | Grid / List / Columns | D | Light / dark |
| Del | Trash selection | ? | This list + tour |
Uninstalling
Deactivate and delete from the Plugins screen. The uninstaller removes all plugin data (options, activity log, folders/tags, meta, scheduled tasks) and — before anything else — moves every private file back into the public uploads folder, so nothing is ever stranded. Your media files and the .fp-orig originals are never deleted.
FAQ
Does FolderPress move or rename my upload files?
No — folders are virtual (a taxonomy). The only exception is folders you explicitly mark Private, and those files return the moment the folder is public again (or on uninstall).
Will it work with my page builder?
Yes — the folder filter appears inside the standard WordPress media modal, which Gutenberg, Classic and most builders use.
Is the free CDN really free?
Yes — it uses a public image CDN that requires no account. For business-critical delivery you can plug in your own CDN domain instead.
I locked myself out with 2FA.
Create an empty file called fp-2fa-off inside wp-content/ (FTP, SSH or your host's file manager). 2FA is bypassed while it exists — log in, fix your method, delete the file.
Something in the UI looks stale after updating.
Hard-refresh the FolderPress tab (Ctrl/Cmd+Shift+R) and clear any page-cache plugin. Assets are version-stamped, so this resolves itself.
Support
- Support portal: support.alphaxp.net
- Website: alphaxp.net
- GitHub: github.com/Alpha-xp5-ai
- YouTube: @alpha_xp0
- Discord: join the community
- Microsoft Store: Alpha-xp apps
When reporting an issue please include your WordPress + PHP versions and what the Activity log shows around the time of the problem.