FreeIntermediatePHP 8.0+v1.8

PHP File Upload Script

A secure, feature-rich file upload system with drag-and-drop UI, real-time progress bars, automatic image thumbnail generation, file type validation, and chunked uploads for large files.

Overview

File uploads are one of the most security-sensitive operations in any web application. This script provides a complete solution that handles the complexities of secure file handling while delivering a modern user experience. Files are validated on both client and server sides, stored with randomized names to prevent directory traversal attacks, and served through a controlled download handler.

The drag-and-drop interface supports multiple simultaneous uploads with individual progress bars. For large files, chunked uploading splits the file into manageable pieces and reassembles them on the server, allowing uploads of files that exceed standard PHP upload limits. Image files automatically get thumbnails generated using the GD library.

Key Features

  • Drag-and-drop upload with click fallback
  • Multiple simultaneous file uploads
  • Real-time progress bars per file
  • Chunked upload for files over 10MB
  • Automatic image thumbnail generation
  • File type validation by extension and MIME
  • Configurable file size limits
  • Randomized file names for security
  • Directory traversal protection
  • Optional virus scanning via ClamAV
  • File management interface with preview
  • Download counter and access logging

Code Example

The upload handler validates and processes each file securely:

class FileUploader { private array $allowedTypes = [ 'image/jpeg', 'image/png', 'image/webp', 'application/pdf', 'text/plain', ]; public function upload(array $file): UploadResult { // Validate MIME type from file contents $finfo = new finfo(FILEINFO_MIME_TYPE); $mime = $finfo->file($file['tmp_name']); if (!in_array($mime, $this->allowedTypes)) { throw new InvalidFileException('File type not allowed'); } // Generate safe filename $safeName = bin2hex(random_bytes(16)) . '.' . $ext; move_uploaded_file( $file['tmp_name'], $this->uploadDir . '/' . $safeName ); return new UploadResult($safeName, $mime); } }

Security Architecture

File uploads are a prime attack vector, so this script implements defense in depth. Files are never stored with their original names, preventing overwrite and traversal attacks. MIME types are verified from actual file contents using finfo, not from the user-supplied Content-Type header. The upload directory is configured to prevent PHP execution with an .htaccess deny rule. Optional ClamAV integration scans uploaded files for malware before they are saved permanently.

Installation Steps

  1. Download and extract the script files to your web server
  2. Create the upload directory and set write permissions (chmod 755)
  3. Edit config.php to set allowed file types, size limits, and storage paths
  4. Import database.sql if you want file metadata tracking (optional)
  5. Include the upload form component in your page
  6. Verify the .htaccess rules are active in the upload directory

Server Requirements

RequirementMinimumRecommended
PHP Version8.08.2+
PHP Extensionsfileinfo, GD+ Imagick for better thumbnails
DatabaseOptionalMySQL 5.7+ for metadata
Disk SpaceDepends on usageSSD recommended
php.iniupload_max_filesize=10MAdjust to your needs

Thumbnail Generation

When an image file is uploaded, the script automatically generates thumbnails at configurable sizes using the GD library. Default sizes are 150x150 for grid views and 600x400 for previews. Thumbnails are cropped to maintain aspect ratio and stored alongside the originals. WebP output is supported for smaller file sizes. If the Imagick extension is available, it is used instead of GD for better quality results.