Folio Gatehouse
Role-based file access control. Restrict upload folders to specific user roles, serve files securely through PHP, and log every access attempt.
Use with caution
Folio Gatehouse works, but test it on a staging site before relying on it in 2026. Was last updated 2 months ago, and scores 55/100 on our health check.
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Folio Gatehouse stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| access-control | >100 |
| download protection | >100 |
| file protection | >100 |
| membership | >100 |
| role-based access | >100 |
About Folio Gatehouse
From the official readme · v1.2.1Description
Folio Gatehouse lets you protect files inside your uploads directory by restricting access to specific WordPress user roles. Files are served through PHP — the web server never delivers them directly — so direct URL access is blocked regardless of link sharing.
Key features:
- Zone-based protection — define named zones (subfolders inside your uploads directory) and assign allowed roles to each
- Custom denial screens — create HTML pages shown to blocked users, with full control over styling and messaging; separate screens for anonymous and logged-in users
- Redirect on denial — optionally redirect denied users to any URL (e.g. a sales page or membership signup) instead of showing a denial screen
- Login redirect shortcode —
[rbfa_login_link]inserts a secure login link that returns the user to the originally-requested file after authentication, using an opaque token so no file path is exposed in the URL - Zone virtual pages — each zone automatically gets a front-end page at
/protected-zone/{slug}/with customisable title and body content, rendered inside your active theme - Browsable file listing —
[rbfa_files]shortcode renders a collapsible, downloadable file listing for authorised users, with per-directory file counts, sizes, and ZIP download buttons - Access logging — every request is logged with timestamp, username, IP, file path, and status; filterable, sortable, and exportable as CSV
- Role management — create and manage custom WordPress roles (
fgh_prefix) directly from the plugin, with searchable member management .htaccessintegrity — automatically writes and repairs rewrite rules across all protected directories; optional hourly cron- NGINX support — dedicated tab generates ready-to-copy
locationblocks when NGINX is detected - Export / Import — back up and transfer zones, roles, denial screens, and settings as a JSON file; conflict resolution on import
Security
- Files served through PHP (
readfile) — web server never delivers protected files directly - Path traversal blocked by
realpath()boundary check before any file is served - Login redirect tokens are opaque — no file path, role, or zone information in the URL
- Denial screen HTML filtered through a strict
wp_ksesallowlist on save and read-back - CSRF protection on every form via WordPress nonces
- All
ORDER BYclauses use a server-side whitelist to prevent SQL injection
Requirements
- Apache with
mod_rewriteenabled, or NGINX (with manual server block configuration — see the NGINX Config tab)
Installation
- Upload the
folio-gatehousefolder towp-content/plugins/ - Activate the plugin from Plugins → Installed Plugins
- Navigate to Folio Gatehouse in the sidebar
- Go to Settings and set your base directory (the folder inside
wp-content/uploads/that will contain all protected zones) - Go to Zones and add zone rows — assign a folder slug and the roles that may access it
- Click Save & Sync Zones
If you are running NGINX, visit the NGINX Config tab for the server block rules you need to add before protection takes effect.
Frequently asked questions
Does this work with NGINX?
Yes, but you need to add server block rules manually. The plugin detects NGINX and shows a dedicated tab with ready-to-copy location blocks.
Will my files be accessible via direct URL?
Not after .htaccess rules are in place (Apache) or after you add the NGINX location blocks. All matched requests are routed through WordPress and through the plugin’s access check before any file content is returned.
What happens to my data if I deactivate or delete the plugin?
Deactivation never deletes any data. Deletion only removes data if you explicitly enable that option in Settings → Data Management.
Can I show different denial messages to guests vs logged-in users?
Yes. Each zone has separate denial screen dropdowns for anonymous visitors and logged-in users who lack the required role.
Can I use this to protect files for a WooCommerce membership?
Yes. Create a custom role for your members (or use an existing WooCommerce role), assign it to a zone, and the plugin will enforce access on every file request.
Does the login redirect shortcode work with custom login pages?
Yes. Configure the login page URL per denial screen (supports absolute URLs and relative paths like /my-account).
Changelog
Critical fix: Save & Sync Zones could silently delete zones not visible on the current page/filter view of the Zones tab. Update immediately if you're on 1.2.0, then check your Zones tab for anything that needs reconfiguring.
1.2.1
- Fixed: critical — “Save & Sync Zones” deleted every zone, then reinserted only the ones present in the submitted form. Since the Zones tab is paginated and filterable, a save only ever submits the zones on the current page/filter view — any zone outside it (on another page, or hidden by a filter) was silently and permanently deleted, while its folder stayed on disk and reappeared as an “unmanaged directory.” Zones are now updated in place by id; a zone is only deleted when its “Remove” button is explicitly clicked. If you’re on 1.2.0, check your Zones tab after upgrading — zones lost to this bug will need to be reconfigured from the unmanaged-directory prompt.
1.2.0
- Admin menu: the plugin now appears under a shared “Folio” menu alongside other Folio-suite plugins, instead of as its own top-level item. Existing settings links (?page=rbfa-pro) and the admin screen are unchanged.
- Performance: zone and base-folder lookups now share a single object-cache-backed query per request (previously two uncached queries on every front-end request). With a persistent object cache (Redis/Memcached) repeat requests serve from cache with zero queries. Cache is invalidated automatically when zones are saved, imported, or migrated.
- Fixed: zone and base-folder slugs were run through
sanitize_title()on save, which forces lowercase — a directory likeTestinggot stored astesting. On case-sensitive filesystems this pointed the zone at the wrong directory; on case-insensitive filesystems the directory still resolved, but the already-managed folder kept reappearing as a phantom “unmanaged directory” because the exact-case comparison never matched. Slugs now usesanitize_file_name(), which preserves case.
1.1.8
- Replaced two
str_starts_with()calls withstrpos()checks for compatibility with the declared minimum WordPress 5.8 (str_starts_with requires WP 5.9)
1.1.7
- Standardised all public shortcodes on the plugin’s 4-character
rbfa_prefix:[rbfa_files],[rbfa_login_link],[rbfa_zone_link](meets WordPress.org prefix-length guideline) - DB migration (v1.9) rewrites shortcode names in existing zone pages and denial screens automatically on upgrade
- Role renames now use core
remove_role()/add_role()instead of a directwp_user_rolesoption write
1.1.6
- All plugin-managed role slugs migrated from fsg_ prefix to fgh_ prefix; DB migration (v1.8) renames existing roles, moves user assignments, and updates zone allowed-roles JSON automatically on upgrade
- System role renamed from FSG Admins (fsg_admins) to FGH Admins (fgh_admins)
1.1.5
- Renamed shortcodes to fgh_ prefix: [fgh_files], [fgh_login_link], [fgh_zone_link]; fsg_ and older names kept as backwards-compatible aliases
- DB migration (v1.7) updates existing zone pages and denial screens to new shortcode names
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Folio Gatehouse alternatives
All access-control plugins →FAQ
Folio Gatehouse: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 8, 2026
Is Folio Gatehouse free?
Yes. Folio Gatehouse is free to download and use from the official WordPress.org plugin directory.
Is Folio Gatehouse safe to use in 2026?
Folio Gatehouse works, but test it on a staging site before relying on it in 2026. Was last updated 2 months ago, and scores 55/100 on our health check.
How many websites use Folio Gatehouse?
Folio Gatehouse is active on <10 WordPress websites and has been downloaded 365 times since it launched in June 2026. It was downloaded 76 times in the last 30 days.
Does Folio Gatehouse work with WordPress 7.1?
Folio Gatehouse is officially tested up to WordPress 7.0.7, while the latest release is 7.1.3. It may still work, but try it on a staging site first.
What PHP version does Folio Gatehouse need?
Folio Gatehouse requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Folio Gatehouse last updated?
The latest version, 1.2.1, was released on August 11, 2026 (2 months ago).
Who makes Folio Gatehouse?
Folio Gatehouse is developed and maintained by buffcleb.
What are the best alternatives to Folio Gatehouse?
The most popular alternatives to Folio Gatehouse are PublishPress Capabilities:… (100K+ installs), Restrict User Access (10K+ installs) and PublishPress Permissions: A… (10K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card