attachmentAV for WordPress: FAQ

Which file types are supported? (#)

attachmentAV scans all file types.

What’s the maximum supported file size? (#)

The maximum file size is 10 MB.

Which upload methods are covered? (#)

attachmentAV scans all files uploaded via:

How does attachmentAV block infected files? (#)

attachmentAV scans every upload in real time while WordPress processes it. If a file is infected, the upload or form submission is rejected with an error message. The exact mechanism differs per upload method (see Concepts for details).

Are uploaded files temporarily stored on my WordPress server? (#)

Yes, briefly. WordPress and the form plugins write every upload to a temporary location on the web server before any plugin can inspect it. attachmentAV scans the file in that temporary location and makes sure infected files are removed from the server: they are either blocked while still in PHP’s temporary upload folder — which PHP discards automatically at the end of the request — or deleted from disk immediately after the scan detects an infection. See Concepts for details.

Where does attachmentAV process my files (region)? (#)

In the EU (European Union). The plugin sends files to the API endpoint https://eu.developer.attachmentav.com. Files are stored on encrypted disks only for the duration of the scan and are deleted immediately afterwards. See Security for details.

Does attachmentAV support WordPress Multisite Networks? (#)

Yes. You can install attachmentAV for the whole network (network activation) and activate it for individual sites.

Note that attachmentAV is configured per site. Each site stores its own settings: open Settings > attachmentAV in the site’s admin dashboard to enter the API key and configure the scan options. There are no network-wide settings, so make sure to configure attachmentAV — especially the API key — for every site that should scan file uploads.

Need help?

Do you have any questions? Please get in touch.

Send email