PHP File Upload Script
A secure, feature-rich file upload system with drag-and-drop UI, real-time progress bars, automatic image thumbnail generation, file type validation, and chunked uploads for large files.
Overview
File uploads are one of the most security-sensitive operations in any web application. This script provides a complete solution that handles the complexities of secure file handling while delivering a modern user experience. Files are validated on both client and server sides, stored with randomized names to prevent directory traversal attacks, and served through a controlled download handler.
The drag-and-drop interface supports multiple simultaneous uploads with individual progress bars. For large files, chunked uploading splits the file into manageable pieces and reassembles them on the server, allowing uploads of files that exceed standard PHP upload limits. Image files automatically get thumbnails generated using the GD library.
Key Features
- Drag-and-drop upload with click fallback
- Multiple simultaneous file uploads
- Real-time progress bars per file
- Chunked upload for files over 10MB
- Automatic image thumbnail generation
- File type validation by extension and MIME
- Configurable file size limits
- Randomized file names for security
- Directory traversal protection
- Optional virus scanning via ClamAV
- File management interface with preview
- Download counter and access logging
Code Example
The upload handler validates and processes each file securely:
Security Architecture
File uploads are a prime attack vector, so this script implements defense in depth. Files are never stored with their original names, preventing overwrite and traversal attacks. MIME types are verified from actual file contents using finfo, not from the user-supplied Content-Type header. The upload directory is configured to prevent PHP execution with an .htaccess deny rule. Optional ClamAV integration scans uploaded files for malware before they are saved permanently.
Installation Steps
- Download and extract the script files to your web server
- Create the upload directory and set write permissions (chmod 755)
- Edit
config.phpto set allowed file types, size limits, and storage paths - Import
database.sqlif you want file metadata tracking (optional) - Include the upload form component in your page
- Verify the
.htaccessrules are active in the upload directory
Server Requirements
| Requirement | Minimum | Recommended |
|---|---|---|
| PHP Version | 8.0 | 8.2+ |
| PHP Extensions | fileinfo, GD | + Imagick for better thumbnails |
| Database | Optional | MySQL 5.7+ for metadata |
| Disk Space | Depends on usage | SSD recommended |
| php.ini | upload_max_filesize=10M | Adjust to your needs |
Thumbnail Generation
When an image file is uploaded, the script automatically generates thumbnails at configurable sizes using the GD library. Default sizes are 150x150 for grid views and 600x400 for previews. Thumbnails are cropped to maintain aspect ratio and stored alongside the originals. WebP output is supported for smaller file sizes. If the Imagick extension is available, it is used instead of GD for better quality results.