Secure Files
Protected file delivery with expiring links. Files live outside the web root, downloads are gated by tag, and every link expires.
A protected download on a normal WordPress site is a URL that only protected people know about. That isn't protection; that is obscurity, and it fails the first time someone shares the link in a Facebook group. Secure Files starts from the opposite assumption: the URL is public knowledge and the file is still safe.
The files themselves live outside the web root, so there is no direct URL to share. When an authorized member requests a file, the module generates a link that is bound to that member and expires after a window you control. A link forwarded to a friend is a link that stops working, for the friend and eventually for the original member. Access rules are tags, like everything else, so a download can require the same tag that gates the page it appears on.
Delivery works for large media too. Secure video and audio stream through the same gated pipeline, so a course's video assets get the same protection as its PDFs without a separate streaming service.
The member experience stays ordinary: [memb_file_link] renders a download button, [memb_file_url] gives the raw URL where a theme needs one. Everything hostile about the arrangement is invisible to the person legitimately downloading.
Shortcodes
| Shortcode | What it does |
|---|---|
| [memb_file_link] | Renders a clickable download link to a file stored on a secure storage provider. |
| [memb_file_url] | Outputs a secure file URL as an escaped plain string. |
| [memb_secure_audio] | Renders an HTML5 audio player with a directly signed source URL. |
| [memb_secure_video] | Renders an HTML5 video player with a directly signed source URL. |