Where are files stored in Client Portal?
Client Portal stores all files in your WordPress uploads directory, organized by file type and security level.
Storage locations
Client Portal uses two main storage paths:
Regular files (Files module): Stored in your standard WordPress uploads folder at
wp-content/uploads/[year]/[month]/Private files and client uploads (Private Files and Client Uploads modules): Stored in a protected subfolder at
wp-content/uploads/leco-cp/[year]/[month]/
The plugin automatically creates the leco-cp folder if needed and follows your WordPress year/month organization setting.
All files are integrated with the WordPress Media Library, so you can reuse files across multiple portals and manage them from the standard WordPress media interface.
How file types differ
Regular files work like standard WordPress media uploads. They're accessible through the portal after login and integrate fully with the Media Library.
Private files and client uploads are stored in a protected directory with additional access controls. WordPress verifies user permissions before serving these files, so clients can only access files in their assigned portals. For a full comparison, see Private files vs regular files: which should you use?.
The protected directory includes server-level restrictions that prevent direct URL access to private files and client uploads.
Managing file storage
As an admin, you manage files through the WordPress block editor when editing portals or templates:
Add a Files, Private Files, or Client Uploads module to your portal
Click "Add or Upload Files" to open the WordPress media modal
Upload new files or select existing ones from your Media Library
Drag to reorder, or use the delete/download icons to manage files
Clients see an upload dropzone on the front-end where they can drag and drop files. They can download or delete their own uploads directly from their portal.
Storage considerations
File uploads respect your server's maximum upload size limit, which Client Portal displays to users. If you're on Nginx, you may need to add a server rewrite rule—follow Troubleshooting nginx issues for the exact configuration steps.
Since files are stored in WordPress uploads, they're included in your regular WordPress backups. Private files remain in the protected leco-cp folder even after plugin updates.