Secure File Uploads on Your Business Website

Stacks of paper documents arranged on a wooden office desk

A customer attaches project photos to a quote request. An applicant sends a résumé. A wholesale buyer uploads specifications. The form confirms receipt, and everyone assumes the process is working.

But a successful upload proves only that a file arrived. It does not prove that the file is private, safe to open, limited to the right employees, or removed when the business no longer needs it. Those are separate checks—and they belong in the acceptance criteria for any website that receives customer documents.

1. Decide which files the business actually needs

Start with one active form, not a sitewide technology project. Write down why it accepts files, which formats staff can use, and who handles the request. A repair shop may need photos of a damaged item; a B2B supplier may need a PDF specification. Neither automatically needs an unrestricted “upload anything” field.

Set a short list of allowed formats, a maximum file size, and a maximum number of files. Display those rules before the customer selects an attachment. Provide a clear alternative when a legitimate project exceeds the limit, such as requesting an approved file-transfer link from the team—not sending confidential documents to an arbitrary personal inbox.

Our website form data minimization checklist covers what to collect in the first place. The next steps address what happens to the files you genuinely need.

2. Verify privacy beyond the form page

A private form entry does not necessarily mean its attachment is private. In WordPress, ordinary Media Library files are generally served through publicly reachable upload URLs. A form plugin may use a different storage model, but that needs verification rather than assumption.

Ask your developer where attachments live and how every download is authorized. Confidential files should use private storage or an access-controlled delivery system. An obscure filename, a hidden page, and a noindex instruction are not substitutes for access control.

Use a harmless test document you created yourself. Have the maintainer check its download link while signed out and with an account that should not have permission. An ordinary private attachment should not download in either case. If the workflow deliberately uses expiring share links, verify their expiry, intended recipients, and revocation behavior; anyone possessing a bearer link may be able to use it until it expires.

3. Ask for layered validation, not just a file picker

The upload button can suggest file types in a browser, but the server must enforce the rules. Ask for a plain-English explanation of the controls rather than a reassuring plugin name.

  • Allowed types: validate the extension and actual file format on the server; do not trust the type claimed by the browser alone.
  • Safe storage: generate safe stored filenames, prevent uploaded content from executing, and keep private files out of ordinary public serving paths.
  • Resource limits: enforce file size, count, and request limits so intake cannot consume unlimited storage or processing capacity.
  • File checking: use appropriate malware scanning and, where justified, document sanitization before staff access or further processing.
  • Maintenance: keep the form extension and the libraries that read, preview, or convert files supported and updated.

These checks follow the layered approach in the OWASP File Upload Cheat Sheet. No single check makes every document safe. Avoid archives unless there is a clear business requirement, and use an authenticated, purpose-built portal for sensitive document intake. Do not send customer files to a public scanning service without reviewing its data-sharing and retention terms.

4. Make the staff handoff safer

Automatically emailing every attachment to several people creates copies that are difficult to control. For confidential intake, prefer a notification containing the request reference and a link to an authenticated workspace. Give access only to the employees handling that work.

Define what happens while scanning is pending, when a file is rejected, and when the checking service is unavailable. A pending file should not silently become available because a scan failed. Staff also need a safe way to ask for a replacement without encouraging customers to bypass the approved channel.

For a Winchester service business collecting project photos, the practical outcome is simple: the estimator can see the right images, other visitors cannot, and the customer knows whether the submission succeeded. That is more useful than adding another dashboard nobody checks.

5. Set a retention rule that reaches the copies

Assign a business owner and a deletion or review trigger for each upload workflow. A rejected application, a completed estimate, and a warranty claim may need different retention periods. Choose those periods with the people responsible for contractual and legal obligations rather than using one arbitrary deadline for everything.

Trace copies in form entries, file storage, email, CRM records, exports, and backups. Deleting a WordPress entry may not delete its attachment or a synced copy. Backups may retain deleted material until their normal expiry; document that behavior and ensure a restore does not quietly return previously removed files to active access.

A small Phase 1 you can verify this week

Choose the form with the most sensitive attachments or the highest submission volume. Ask its maintainer to record the storage location, allowed formats, limits, access rules, scanning behavior, and retention owner on one page. Then test the customer journey with benign files on an approved test environment:

  • An allowed sample uploads from a phone and produces a clear confirmation.
  • An unsupported format and an oversized sample receive useful error messages.
  • A signed-out visitor and an unauthorized account cannot retrieve the private sample.
  • The assigned employee receives the notification and can access the accepted file.
  • Deleting the test submission removes active access according to the documented workflow.

Do not upload malicious test files to a live business website. Have a qualified maintainer validate scanning and failure handling through the provider’s approved testing process. If a private sample is publicly accessible, pause that upload path and arrange a secure alternative while the issue is assessed.

Nexus Box can help review an existing WordPress or ecommerce upload flow without turning a focused security fix into a full rebuild. Start with one form, close the exposure, and keep the customer handoff easy. A file-upload feature is finished when it works for the customer and protects what they sent.

Photo: Valentin Sarte / Pexels, used under the Pexels License.