Filevue turns your WordPress site into a private client portal. Create clients, upload files into organized folders, and give each client their own login where they can view and download documents, upload their own files, and update their personal details and password from My Account. No WordPress account needed.
Your site name is used for all branding. No “Powered by” labels, no third-party logos. The portal adapts to your WordPress admin color scheme automatically.
When you reach a free-plan cap, Filevue shows clear upgrade prompts on the Home page, View Clients, and Edit Client screens. You can still browse, download, and delete existing content normally.
Upgrade to Filevue Pro
Purchase a license on filevue.app. Monthly, annual, and lifetime billing options are available at checkout.
???? Single Site (1 WordPress site) — Purchase Pro — from $49.99/year
???? Agency (up to 5 sites) — Purchase Agency — from $99/year
After purchase, install or update to the Pro package and activate your license under Filevue in the WordPress admin.
Features at a Glance
Private client portal – each client gets a unique login with access to only their files
Client self-service – clients upload files, update personal details, and change their password from the portal
Drag-and-drop file uploads – upload single or multiple files from the admin or from the client portal
Custom folders – organize files with named folders, SVG icons, and accent colors
Drag to reorganize – move files between folders without reloading the page
Inline file preview – clients can view PDFs and images directly in the browser
Editable data sheets – attach spreadsheets to folders with rows, columns, and Excel export
Branded email notifications – send credentials on setup and automatic alerts every time new files are uploaded
Built-in SMTP – configure email delivery with one-click presets for Gmail, Outlook, and Yahoo
Team roles – assign Portal Manager or Portal Contributor roles to staff members
One-click portal preview – preview the portal as any client without sharing credentials
Portal appearance – basic styling in Settings (Free); full Portal Design customiser (Pro)
Toggle file extensions – show or hide file extensions in folder listings
AES-256-CBC encryption – client passwords and SMTP credentials are encrypted at rest
Auto-created portal page – the /client-portal/ page is set up on activation with no manual steps
Session security – client sessions expire after 1 hour with manual logout available
Data protection – choose whether plugin data is preserved or deleted on uninstall
Client Management
Create and manage clients from a clean admin dashboard.
Create clients with a unique Client ID, encrypted password, optional email, and internal notes.
Organize work into multiple projects per client (Pro users with higher volume often rely on unlimited caps).
Search, filter, and paginate your client list.
View client details in a quick-view modal to copy credentials, check file stats, and open the portal link.
Preview the portal as any client with one click. No need to copy or share credentials.
File Uploads and Folders
Upload and organize client files without leaving the admin. Clients can also upload files directly from their portal.
Drag-and-drop single or multi-file uploads (admin and client portal).
Create named folders with custom SVG icons and accent colors.
Drag files between folders to reorganize instantly.
Supported formats: PDF, Word, Excel, images (PNG, JPG, GIF), text, ZIP, and RAR.
Toggle file extension visibility from the Settings page.
Client Portal
A dedicated, branded login page for your clients.
Automatically created at /client-portal/ on activation. No setup needed.
Clients log in with their Client ID and password. No WordPress account required.
Collapsible folder tree with icons and colors matching the admin setup.
Upload files to any folder from the portal (upload button on each folder).
My Account profile panel: clients update name, email, country, phone, address, and notes, and change their password without contacting you.
Inline preview for PDFs and images. No download required.
Secure one-click downloads verified with nonces and path validation.
Sessions expire after 1 hour. Clients can log out at any time.
Customize basic portal colors from Settings (Free) or use Portal Design for full white-label control (Pro).
Data Sheets
Share structured data alongside files.
Attach editable spreadsheets to any folder. Add rows, columns, and multiple sheets.
Clients see a read-only view of data sheets in the portal.
Download any data sheet as an Excel file. Available to both admins and clients.
Email Notifications
Keep clients informed without manual effort.
Send branded HTML emails with portal link, Client ID, and password.
Clients are automatically notified every time new files are uploaded to their folder. No manual follow-up needed.
All emails use your site name and are styled to match your brand.
Pro: customise email header, colours, and footer from Portal Design > Emails.
SMTP Configuration
Reliable email delivery built in.
Configure SMTP with a test-before-save approach. Settings activate only after a successful test.
One-click presets for Gmail, Outlook, and Yahoo with step-by-step guidance.
SMTP passwords encrypted at rest using AES-256-CBC.
Team Access
Share portal management with your team without giving full site access.
Portal Contributor – can manage clients and upload files, but cannot change settings or delete content.
Portal Manager – full portal access including settings, user management, and content deletion.
Both roles see only the Filevue menu. No access to the rest of WordPress.
Staff portal – staff log in on the same portal page (separate tab) and see only projects assigned to them.
Security
Built with security in mind at every level.
Client passwords encrypted with AES-256-CBC using your site’s AUTH_KEY.
Upload directory protected with .htaccess rules and a silent index.php.
Every action (download, upload, delete, login) is nonce-verified with path traversal protection.
Data protection toggle to choose whether plugin data is preserved or removed on uninstall.
Supported languages
Filevue includes translation files for the WordPress admin and client portal. The Site Language list under Settings > General is provided by WordPress core. If a language (for example Nederlands) is missing there, install the WordPress language pack first via Filevue > Settings (Install buttons) or Dashboard > Updates > Languages, then select it as the site language.
English (default)
Arabic (ar)
Chinese (Simplified) (zh_CN)
Dutch (nl_NL, nl_BE)
French (fr_FR)
German (de_DE)
Hindi (hi_IN)
Romanian (ro_RO)
Russian (ru_RU)
Spanish (es_ES)
Translation files live in languages/ as .po and compiled .mo pairs.
Support Development
Filevue Free is open source on WordPress.org. If it saves you time or helps your business, consider supporting continued development:
Filevue offers two different support channels. Pick the one that fits your question:
Filevue Support Portal — https://www.filevue.app/support/
Official help from the Filevue team. Use this for setup guidance, bug reports, license questions, and opening or tracking support tickets. This is the Filevue website, not WordPress.org.
WordPress.org Support Forum — https://wordpress.org/support/plugin/filevue/
Free, public community discussions hosted on wordpress.org. Use this for general how-to questions you are happy to post publicly. It is separate from the Filevue Support Portal and is not where you open private Filevue tickets.
What is the difference between Filevue Free and Filevue Pro?
Filevue Free (WordPress.org) includes the full client portal workflow with caps of 5 clients, 20 folders, 100 files, and 2 staff members, plus SMTP, data sheets, team roles, basic portal styling, projects, staff portal login, and activity notifications.
Filevue Pro removes all usage caps and adds Portal Design (white-label portal and email styling), Telegram alerts, image compression, CSV export for the activity log, Elementor widgets, and priority support. See the comparison on filevue.app.
How do I upgrade to Filevue Pro?
Visit filevue.app pricing, choose a plan (Single Site, Agency, or Unlimited), and complete checkout:
Install the Pro package and activate your license under Filevue in WordPress. Your existing clients, files, and settings are kept.
What are the limits of Filevue Free?
Filevue Free is fully functional for solo practitioners and small teams. The current caps are:
Up to 5 clients in total.
Up to 20 folders in total across all clients.
Up to 100 files in total across all clients.
Up to 2 staff members.
When you reach any cap, an inline notice appears on the Home page, View Clients page, and Edit Client page. You can still log in, browse, download, and delete content normally. Upgrade to Pro for unlimited usage.
Where do clients log in?
Filevue automatically creates a portal page on activation (default slug portal; older installs may still use /client-portal/). Clients visit that URL, enter their Client ID and password, and immediately see their files. You can also place the [client_files] shortcode on any page to create an alternative portal entry point.
After an update, the portal page only shows `[filevue_client_files]` as plain text. How do I fix it?
This usually means the portal page still uses a legacy shortcode from Filevue 1.x ([filevue_client_files] or [scp_client_files]), while current versions use [client_files].
Quick fix:
In WordPress admin, go to Pages and open your portal page (often still at /client-portal/).
Replace [filevue_client_files] with [client_files] and click Update.
Reload the portal URL in a private browser window.
Also check:
Filevue → Settings → URL Slug must match the page you share with clients (this is not the same as a client’s login ID slug).
Confirm Filevue is active under Plugins.
Recent Filevue versions register legacy shortcodes for backward compatibility and migrate page content automatically on the next site visit. Updating to the latest release and loading the portal page once is often enough; use the manual step above if the page still shows the old tag.
How can I preview the portal as a specific client?
On the Clients page, click the Portal button (the Filevue icon) next to any client. This generates a secure, single-use token that auto-logs you into the portal as that client in a new tab. The token expires after 60 seconds and can only be used once. No credentials are exposed.
Can clients upload files or update their own details?
Yes. After logging in, clients can:
Upload files to folders using the upload button on each folder in the portal.
Update personal details (name, email, country, phone, address, and notes) from My Account in the portal header.
Change their password from the same My Account panel.
You and your team still manage clients from the WordPress admin. Clients only see and edit their own account and files.
Can clients see each other’s files?
No. Each client can only access files uploaded to their own folder. Downloads are verified against the logged-in client’s session.
Can staff see all clients?
No. Staff members only see the projects they are assigned to. They log in on the staff tab of the same portal page.
What file types can I upload?
PDF, XLSX, XLS, DOC, DOCX, TXT, PNG, JPG, JPEG, GIF, ZIP, and RAR. File size limits follow your WordPress and server configuration.
Can I use my own SMTP server?
Yes. Go to Filevue > SMTP Settings, enter your credentials, and send a test email. Settings only activate after a successful test.
What happens to client data if I deactivate or delete the plugin?
By default, all data is preserved, which is safe for updates and reinstalls. You can enable “Delete all data on uninstall” from the home page if you want a clean removal.
Does the portal show my plugin or brand name?
No. The portal uses your WordPress site name for all labels and headings. There is no hardcoded branding.
How do I customise the look of the client portal? (Pro)
Open Filevue > Portal Design. Six tabs cover Login Page, Dashboard, Typography, Presets, Custom CSS, and Tools — plus an Emails tab for branded transactional messages. Free users can adjust basic button and accent colours from Filevue > Settings.
Are there Elementor widgets for the portal? (Pro)
Yes. Filevue Pro ships four widgets under a Filevue category: Login Form, Folder Tree, Recent Files, and Client Header. Four dynamic tags (Client name, Project name, File count, Last login) work in any Elementor text control. With Elementor Pro, a Filevue Portal Theme Builder location is available for fully custom layouts.
I get “Not Acceptable” / HTTP 406 error when logging in or uploading files
This error is returned by your hosting provider’s ModSecurity (a Web Application Firewall), not by Filevue itself. It’s a false positive where a legitimate request is being blocked because it matches a “suspicious” pattern.
Common triggers:
Passwords containing special characters like %, ', ", <, >, =, or words like select, union, drop.
Uploading files with unusual filenames (brackets, quotes, encoded characters).
Filenames or folder names with accented / non-ASCII characters (very common in Spanish, French, Portuguese, German, etc. — e.g. Facturación.pdf, Año 2026.xlsx, Diseño.png, Niño.jpg). When the browser URL-encodes ó as %C3%B3, ModSecurity may block the request as a suspected encoding attack.
Saving content that contains SQL-like words or HTML/JS snippets.
Good news: As of version 1.5.0, Filevue prevents most of these 406 errors automatically:
Filenames are auto-transliterated at upload time while keeping spaces intact: Año 2026.pdf becomes Ano 2026.pdf (not Ano-2026.pdf), Facturación enero.pdf becomes Facturacion enero.pdf, Diseño final.png becomes Diseno final.png.
Folder names follow the same rule: Diseño becomes Diseno, Año 2026 becomes Ano 2026.
Client passwords can no longer contain characters that trigger ModSecurity: quotes ('"), angle brackets (<>), backslash (\), percent (%), semicolon (;), or accented / non-ASCII characters. Allowed characters are letters, numbers and - _ . ! @ # $ * + = : ? ~ ^ ( ) [ ] { } | ,. Existing passwords keep working; only newly-saved ones are validated.
Client names, descriptions, and email messages are not affected — they fully support accented characters (á, é, í, ó, ú, ñ, ü, ¿, ¡), so you can still enter José García as a client name, write Spanish/French/Portuguese descriptions, and send localized emails. These fields are never sent through URLs, so WAFs can’t block them.
If you have existing files with accents on disk or old passwords with special characters and still hit the error, rename those files / reset the password to a safe one, or use one of the solutions below.
Solutions (in order of recommendation):
Option 1. Contact your hosting provider. Ask them to check the ModSecurity logs for the blocked request and either whitelist the triggered rule IDs for your site or disable ModSecurity for /wp-admin/admin-ajax.php and /wp-admin/admin-post.php.
Option 2. Try a different password for the client (use only letters, numbers, and -_.!@#) to confirm the password is the trigger.
Option 3. Rename the file you are uploading to something simpler (letters, numbers, hyphens, underscores only).
Option 4. Add a rule to your .htaccess if your host allows it. Both endpoints (admin-ajax.php and admin-post.php) need to be covered because Filevue uses admin-post.php for uploads, login, and form submissions, and admin-ajax.php for inline actions. Edit the .htaccess file at the root of your WordPress install (the same folder where wp-config.php lives) and paste the block below near the top, before the WordPress block.
The snippet disables ModSecurity only for the two WordPress admin endpoints that Filevue uses, so the rest of your site remains protected by ModSecurity:
<IfModule mod_security.c>
<LocationMatch "/wp-admin/admin-ajax\.php">
SecRuleEngine Off
</LocationMatch>
<LocationMatch "/wp-admin/admin-post\.php">
SecRuleEngine Off
</LocationMatch>
</IfModule>
Some hosts ship ModSecurity 2.9 or newer under the module name mod_security2.c. If the rules above are ignored, replace the wrapper with the alternative module name:
<IfModule mod_security2.c>
<LocationMatch "/wp-admin/admin-ajax\.php">
SecRuleEngine Off
</LocationMatch>
<LocationMatch "/wp-admin/admin-post\.php">
SecRuleEngine Off
</LocationMatch>
</IfModule>
After saving the file, retry the action that produced the 406 error. If you still get it, check with your host whether .htaccess overrides for mod_security are enabled. Some managed hosts (WP Engine, Kinsta, Pressable) do not allow this and require a support ticket instead.
Option 5. Whitelist a specific rule ID if you want to keep ModSecurity active and only silence the false positive. Replace 949110 with the rule ID shown in your host’s ModSecurity log:
This error is almost always a hosting configuration issue, not a plugin bug. Most shared hosts (Bluehost, SiteGround, HostGator, GoDaddy) ship with ModSecurity enabled and will gladly tune the rules if you contact support.
Refactoring the Project Template and Folder Templates sections
2.5.4
Updated some translations
Plugin check fixes, improvements and cleanup
2.5.3
Bugfix – Folder hierarchy state was not preserved after drag and drop and page refresh
2.5.2
Added one time only NEW badge for Report Builder page
2.5.1
Small improvement for Report Builder functionality
2.5.0
Fixed broken HTML paragraph on Important Upgrade Notice section from WP Plugins page
Some Elementor compatibility issues fixes on Portal My account section
Changes for Report Builder functionality – this should be available in both Free and Pro packages
Updated translations
Added Report Builder to generate client document audits and completeness reports.
2.4.1
Fixed broken plugin logo on activation step before user is opt in
Updated a link for Free license activation step
2.4.0
Updated translated content
Some more Elementor compatibility fixes
Added multi language readme files
Client is automatically logged out from Portal page on session timeout
Fixed style rendering issues with specific Elementor components on Portal page
Added support for more languages
2.3.3
Critical fix for Portal not rendering after upgrade from legacy shortcodes
2.3.2
Hardening Data Sheet modal style
Added Project description section when adding a new Project.
Backward compatibility for legacy portal shortcodes ([filevue_client_files], [scp_client_files]) with automatic page content migration to [client_files].
2.3.1
Added integration with Cloudflare Turnstile for Portal page
UX and style improvements
2.2.1
Major release Filevue Free on WordPress.org with usage limits, Filevue Pro for unlimited clients, folders, files, and staff plus Portal Design, Telegram, image compression, and activity log CSV export. Includes 10 bundled translations and a redesigned Settings page. Existing data is preserved when you upgrade.
Major release Filevue Free on WordPress.org with usage limits, Filevue Pro for unlimited clients, folders, files, and staff plus Portal Design, Telegram, image compression, and activity log CSV export. Includes 22 bundled translations and a redesigned Settings page. Existing data is preserved when you upgrade.
Description updates & bug fixes
Manual update checks on Settings page
Fixed upgrade algorithm & Premium slug
Improved Pro vs Free plugin name display
Translation loading fix
Free Presets added
Style improvements & bug fixes
Clients can update personal details on Portal
Portal Design improvements
Style & upgrade notification fixes
Filevue Free & Pro launched
Usage limits on free plan (5 clients, 2 staff, 20 folders, 100 files)