Title: ScanUpload
Author: donaldanet1
Published: <strong>Ọwẹ́wẹ̀  11, 2026</strong>
Last modified: Ọwẹ́wẹ̀  11, 2026

---

Ṣàwárí àwọn plugin

![](https://ps.w.org/scanupload/assets/banner-772x250.png?rev=3692051)

![](https://ps.w.org/scanupload/assets/icon-256x256.png?rev=3692051)

# ScanUpload

 Láti ọwọ́ [donaldanet1](https://profiles.wordpress.org/donaldanet1/)

[Ṣe ìgbàsílẹ̀](https://downloads.wordpress.org/plugin/scanupload.1.0.1.zip)

 * [Àwọn àlàyé](https://yor.wordpress.org/plugins/scanupload/#description)
 * [Àwọn àgbéyẹ̀wò](https://yor.wordpress.org/plugins/scanupload/#reviews)
 *  [Ìgbéwọlẹ̀](https://yor.wordpress.org/plugins/scanupload/#installation)
 * [Ìdàgbàsókè](https://yor.wordpress.org/plugins/scanupload/#developers)

 [Ìrànlọ́wọ́](https://wordpress.org/support/plugin/scanupload/)

## Àpèjúwe

ScanUpload adds a QR-code upload widget to any page with a shortcode. A visitor 
scans the QR code with their phone, uploads files, and those files are automatically
imported into your WordPress site.

**How it works**

 1. You add the `[scanupload]` shortcode to any page or post.
 2. The page renders a live QR code.
 3. A visitor scans it with their phone and uploads files using the ScanUpload mobile
    flow.
 4. Files arrive in your WordPress site automatically (Media Library or a sub-folder,
    your choice).

The plugin is powered by the [ScanUpload](https://app.scanupload.net/) service, 
which requires a free ScanUpload account, Client ID and Client Secret.

**Features**

 * Configurable Client ID and Client Secret, stored securely in the WordPress options
   table.
 * Choose where uploads land: Media Library (unattached), Media Library attached
   to a post/page, or a dedicated uploads sub-folder.
 * Live file preview while the visitor uploads.
 * Fully automatic import Ìtumọ̀ Yorùbá: – no button clicks required.
 * Works on any theme via the `[scanupload]` shortcode.

#### Getting started

 1. Create a free account at [app.scanupload.net](https://app.scanupload.net/) and 
    copy your **Client ID** and **Client Secret** from **Dashboard  Settings  Client
    Credentials**.
 2. In WordPress, open **Settings  ScanUpload**, paste both values and click **Save
    Settings**.
 3. In the ScanUpload Dashboard, add your site address to **Allowed Origins** (for 
    example `https://example.com`). While developing on `localhost`, enable **Test 
    Mode** instead.
 4. Add the `[scanupload]` shortcode to the page where you want the widget (see below).

That is the whole configuration. Until credentials are saved, the widget shows a
friendly “ScanUpload is not configured” message instead of a QR code.

#### Putting the widget on a page

**Block Editor (nothing extra to install):** edit the page, click **+**, search 
for **Shortcode**, add the block and paste `[scanupload]` into it.

**Elementor:** drag the **Shortcode** widget into the page and paste `[scanupload]`
into its Shortcode field.

**Any other theme or builder that renders shortcodes:** paste `[scanupload]` where
the widget should appear.

A visitor then points their phone camera at the code, chooses the files they want
to send, and the files arrive on your site automatically. The widget lists each 
file as it arrives, so the visitor can see the upload working.

#### Where do the files go?

 * **Media Library, unattached** (`import_mode="media"`, the default) Ìtumọ̀ Yorùbá:–
   files appear under **Media  Library**.
 * **Media Library, attached to a post or page** (`import_mode="media_attach"`) 
   Ìtumọ̀ Yorùbá: – files appear in the library, attached to the post or page you
   choose.
 * **A sub-folder of the uploads directory** (`import_mode="folder"`) Ìtumọ̀ Yorùbá:–
   files are saved under `wp-content/uploads/<sub-folder>/` and are not added to
   the Media Library.

In `folder` mode the plugin also writes `.htaccess`, `index.html` and `web.config`
guard files into that folder so uploaded files cannot be executed.

#### Shortcode

    ```
    [scanupload]
    ```

Optional attributes:

 * `header` Ìtumọ̀ Yorùbá: – Header text shown above the QR code. Default: “Upload
   files from your phone”.
 * `show_header` Ìtumọ̀ Yorùbá: – `1` or `0`. Default `1`.
 * `size` Ìtumọ̀ Yorùbá: – `small`, `medium`, `large` or `xlarge`. Default `large`.
 * `file_preview_mode` Ìtumọ̀ Yorùbá: – `list` or `grid`. Default `list`.
 * `import_mode` Ìtumọ̀ Yorùbá: – `media`, `media_attach` or `folder`. Overrides
   the site-wide setting for this widget.
 * `attach_to` Ìtumọ̀ Yorùbá: – Post ID to attach imported media to when `import_mode
   ="media_attach"`. Use `attach_to="current"` to attach to the post currently being
   viewed.
 * `class` Ìtumọ̀ Yorùbá: – Extra CSS class for the widget container.

Example:

    ```
    [scanupload header="Scan to send us files" size="large" import_mode="media_attach" attach_to="42"]
    ```

When a logged-in visitor uploads files, the imported attachments are attributed

to that user. Anonymous visitors upload unattributed (author 0).

Media is only attached to a post the uploader is allowed to edit; otherwise it
 
is imported unattached. Use the `scanupload_allow_attach_to_post` filter to allow
guest submissions to a fixed public post.

#### Developer Hooks

 * `scanupload_import_author_id` Ìtumọ̀ Yorùbá: – author ID assigned to imported
   attachments (default: the current user, `0` for anonymous visitors).
 * `scanupload_allow_attach_to_post` Ìtumọ̀ Yorùbá: – whether imported media may
   be attached to a post (default: only when the uploader can edit it). Use it to
   allow guest submissions to a fixed public post.
 * `scanupload_import_rate_limit` Ìtumọ̀ Yorùbá: – maximum import requests per rate-
   limit window (default `10`).
 * `scanupload_import_rate_window` Ìtumọ̀ Yorùbá: – rate-limit window in seconds(
   default `600`, i.e. 10 minutes).
 * `scanupload_import_client_ip` Ìtumọ̀ Yorùbá: – client IP used for rate limiting(
   default: the direct peer address). Useful behind a trusted reverse proxy.

#### External services and data

This plugin is a bridge to the [ScanUpload](https://app.scanupload.net/) service
and only connects to it when you configure it and a visitor uses the widget:

 * The visitorÌtumọ̀ Yorùbá: ’s browser creates a scan upload session with ScanUpload(`
   https://hub.scanupload.net`) when a `[scanupload]` widget is shown. The browser
   sends only the configured Client ID and your siteÌtumọ̀ Yorùbá: ’s origin.
 * Your server requests an access token from the ScanUpload identity service (`https://
   identity.scanupload.net`) using the Client ID and Client Secret you entered.
 * Your server downloads the uploaded files for a session and imports them into 
   your own WordPress site.

No tracking or analytics data is collected or sent by this plugin. Uploaded files
are transmitted to and from the ScanUpload service solely to operate the upload 
feature, and are then stored on your site. No data is shared with any third party.
See the [ScanUpload Terms and Conditions](https://app.scanupload.net/terms-conditions)
for how ScanUpload handles the files it processes.

By installing, configuring and using the plugin you consent to the connections described
above.

### Credits

This plugin bundles the following open-source libraries. Both are included as
 readable,
unminified source so the shipped code can be reviewed as-is:

 * [@microsoft/signalr](https://github.com/dotnet/aspnetcore) Ìtumọ̀ Yorùbá: – MIT
   License. Used for the live file preview.
 * [qrcode-generator](https://github.com/kazuhikoarase/qrcode-generator) Ìtumọ̀ 
   Yorùbá: – MIT License. Used to render the QR code.

Both licences are GPL-compatible. The pluginÌtumọ̀ Yorùbá: ’s own code is licensed
under
 GPL-2.0-or-later; see `license.txt`.

## Àwọn àwòrán ìbòjú

[⌊Settings, ScanUpload: add your Client ID and Client Secret.⌉⌊Settings, ScanUpload:
add your Client ID and Client Secret.⌉[

Settings, ScanUpload: add your Client ID and Client Secret.

[⌊Choose where uploads land: the Media Library, attached to a page, or an uploads
sub-folder.⌉⌊Choose where uploads land: the Media Library, attached to a page, or
an uploads sub-folder.⌉[

Choose where uploads land: the Media Library, attached to a page, or an uploads 
sub-folder.

[⌊Advanced service endpoints, pre-filled with the ScanUpload defaults.⌉⌊Advanced
service endpoints, pre-filled with the ScanUpload defaults.⌉[

Advanced service endpoints, pre-filled with the ScanUpload defaults.

[⌊ScanUpload active on the Plugins screen.⌉⌊ScanUpload active on the Plugins screen
.⌉[

ScanUpload active on the Plugins screen.

[⌊Add [scanupload] to a page with the Shortcode block.⌉⌊Add [scanupload] to a page
with the Shortcode block.⌉[

Add `[scanupload]` to a page with the Shortcode block.

[⌊The widget on a page, showing the live QR code for visitors to scan.⌉⌊The widget
on a page, showing the live QR code for visitors to scan.⌉[

The widget on a page, showing the live QR code for visitors to scan.

[⌊Files received through the widget appear in the WordPress Media Library.⌉⌊Files
received through the widget appear in the WordPress Media Library.⌉[

Files received through the widget appear in the WordPress Media Library.

## Ìgbéwọlẹ̀

 1. In your WordPress admin, go to **Plugins  Add New**, search for **ScanUpload**,
    then click **Install Now**. Alternatively, upload the plugin ZIP under **Plugins
    Add New  Upload Plugin**.
 2. Click **Activate**.
 3. Continue with **Getting started** above: save your Client ID and Client Secret,
    allow your site origin, then add the `[scanupload]` shortcode to a page.

**Requirements:** WordPress 6.0+, PHP 7.4+, a free ScanUpload account, and HTTPS.
The widget opens a secure WebSocket to the ScanUpload hub, so an HTTP page is blocked
by the browserÌtumọ̀ Yorùbá: ’s mixed-content protection.

## FAQ

### Do I need a ScanUpload account?

Yes. Create a free account at [app.scanupload.net](https://app.scanupload.net/),
then generate a Client ID and Client Secret from the Dashboard.

### Is my Client Secret exposed to visitors?

No. The Client Secret is used only on your server to download uploaded files. It
is never printed in the page source.

### Why do I get an “origin not allowed” error?

ScanUpload validates the browser origin that creates a session. Add your exact site
origin (for example `https://example.com`) to **Allowed Origins** in the ScanUpload
Dashboard. Origins are scheme, host and port specific.

### Can I test on localhost?

Yes. Enable **Test Mode** in the ScanUpload Dashboard to bypass origin validation
for local development, and disable it before going live.

### Where are the files stored?

By default they are imported into the WordPress Media Library. You can change this
under **Settings  ScanUpload** to attach them to a post/page or save them in a sub-
folder of the uploads directory.

### Does my site need to be HTTPS?

Yes. The widget connects to the ScanUpload hub over a secure WebSocket (`wss://`),
so your site must be served over HTTPS. An HTTP page is blocked by the browserÌtumọ̀
Yorùbá: ’s mixed-content protection.

### What if my site has a Content Security Policy (CSP)?

Allow the hub for both protocols in your `connect-src` directive:

    ```
    connect-src 'self' https://hub.scanupload.net wss://hub.scanupload.net;

    https:// permits the session request and `wss://` permits the live SignalR updates. CSP does not infer one from the other.
    ```

### Where can I get help?

Email [support@scanupload.net](https://yor.wordpress.org/plugins/scanupload/support@scanupload.net?output_format=md)
or see the [ScanUpload integration guide](https://app.scanupload.net/integration).

## Àwọn àgbéyẹ̀wò

Kò sí àwọn àgbéyẹ̀wò fún plugin yìí.

## Àwọn Olùkópa & Olùgbéejáde

“ScanUpload” jẹ́ ètò ìṣàmúlò orísun ṣíṣí sílẹ̀. Àwọn ènìyàn wọ̀nyí ti ṣe ìkópa sí
plugin yìí.

Àwọn Olùkópa

 *   [ donaldanet1 ](https://profiles.wordpress.org/donaldanet1/)

[Túmọ̀ “ScanUpload” sí èdè rẹ.](https://translate.wordpress.org/projects/wp-plugins/scanupload)

### Ṣe o nífẹ̀ẹ́ sí ìdàgbàsókè?

[Ṣàwárí koodu](https://plugins.trac.wordpress.org/browser/scanupload/), ṣàyẹ̀wò 
[ibi ìpamọ́ SVN](https://plugins.svn.wordpress.org/scanupload/), tàbí ṣe àgbékalẹ̀
sí [àkọsílẹ̀ ìdàgbàsókè](https://plugins.trac.wordpress.org/log/scanupload/) nípasẹ̀
[RSS](https://plugins.trac.wordpress.org/log/scanupload/?limit=100&mode=stop_on_copy&format=rss).

## Àkọsílẹ̀ àwọn àyípadà

#### 1.0.1

 * Replaced direct filesystem calls with WordPress APIs (`wp_delete_file()` and `
   WP_Filesystem`), removed the redundant `load_plugin_textdomain()` call, and added
   translator comments for placeholder strings. No behaviour changes.

#### 1.0.0

 * Initial release: settings page, `[scanupload]` shortcode, live QR widget, SignalR
   file preview, and automatic import into the Media Library or uploads sub-folder.

## Àkójọpọ̀ Meta

 *  Ẹ̀yà **1.0.1**
 *  Ìgbàgbọ́hùn tó kẹ́yìn **ọjọ́ 3 sẹ́yìn**
 *  Àwọn ìgbéwọlẹ̀ tó ṣiṣẹ́ **Tó kéré sí 10**
 *  Ẹ̀yà WordPress ** 6.0 tàbí ju bẹ́ẹ̀ lọ **
 *  Dánwò dé **7.1**
 *  Ẹ̀yà PHP ** 7.4 tàbí ju bẹ́ẹ̀ lọ **
 *  Èdè
 * [English (US)](https://wordpress.org/plugins/scanupload/)
 * Àwọn àmì
 * [file upload](https://yor.wordpress.org/plugins/tags/file-upload/)[media library](https://yor.wordpress.org/plugins/tags/media-library/)
   [qr code](https://yor.wordpress.org/plugins/tags/qr-code/)[upload](https://yor.wordpress.org/plugins/tags/upload/)
 *  [Ìwòye Tó Péye](https://yor.wordpress.org/plugins/scanupload/advanced/)

## Àwọn ìbò

Kò sí ìwádìí tí a tíì fi ránṣẹ́.

[Your review](https://wordpress.org/support/plugin/scanupload/reviews/#new-post)

[Wo gbogbo àwọn àgbéyẹ̀wò](https://wordpress.org/support/plugin/scanupload/reviews/)

## Àwọn Olùkópa

 *   [ donaldanet1 ](https://profiles.wordpress.org/donaldanet1/)

## Ìrànlọ́wọ́

Nǹkan wà tí o fẹ́ sọ? Ṣé o nílò ìrànlọ́wọ́?

 [Wo àpéjọ ìrànlọ́wọ́](https://wordpress.org/support/plugin/scanupload/)