MontraFolio
Gives every user of your site an image portfolio of their own — and the organization the shared portfolios of events, field trips and campaigns, with designated contributors. The images live in a private folder, outside the Media Library.
It installs like any plugin from the directory: Plugins → Add New, search for MontraFolio, install and activate. No account to create, no license key, no external service.
- The images never leave your server
- Mobile first
- Three blocks and three shortcodes
- Updated by WordPress, like the others
- English · Português · Español
- WordPress 6.5+ · PHP 8.1+
The Media Library was not built for this
When three hundred people are publishing photographs — students, trainees, members, staff — WordPress has one place to put them: the same shared pile, served at a public address anybody can pass on to anybody. And to get there, every one of them needs the back office.
Without MontraFolio
- Every image in the same Media Library pile
- Whoever knows the address sees the file, always
- Either everybody is given wp-admin, or nobody is
- A page built by hand for every class, event or trip
- 8 MB photos straight off the phone, one at a time
- Nobody knows who uploaded what, or when
With MontraFolio
- Each person with a portfolio of their own and their own collections
- Files in a folder the web server does not serve; the plugin decides who sees each image
- An area of their own for the people who publish; wp-admin stays with the people who run the site
- The portfolio page and each collection’s gallery come ready-made
- The image is resized on the phone before it goes up
- Every upload and every designation is recorded
Four steps, and the site is ready
-
Install
Search for MontraFolio in Plugins → Add New and activate it. The private folder and the tables are created right there. In Settings you choose the address words and the limits a portfolio is born with.
-
Decide who gets in
The Permissions by Role card, inside Settings, decides who manages portfolios. Being an owner or a contributor is not a role: any user who can sign in may have one.
-
Publish
The people who publish work in the portfolio area, at
/p-admin/: camera, phone gallery or a folder dragged in on a desktop, order by touch, captions. -
Show
Every portfolio has its page and every collection its gallery, at the address you chose. Or they go into a page of your theme, through a block.
What sets it apart
Private by construction
Nothing goes to the Media Library. The files live in a folder the web server does not serve, under names nobody guesses, and it is the plugin that checks who is asking before it delivers an image. A hidden collection is really hidden.
Mobile first
Upload from the camera or the gallery, resized on the device itself before it goes up, reorder by touch, leaf through the carousel with a finger. On a desktop, dragging a whole folder feeds the same pipeline. HEIC photos from an iPhone are accepted with nothing to configure.
Nobody needs wp-admin
Owners and contributors work in an area of the plugin, at the address the site chooses. A user with nothing beyond a reading role lands there after signing in and never sees the WordPress dashboard. An owner runs their portfolio; contributors publish in the collections they were given.
Limits at four levels
Settings says what limits a portfolio and a collection are born with; then each portfolio has its own ceiling of storage and images, a collection can narrow it, and each contributor can be narrowed further still. No level grants more than the one above it, and lowering a limit never deletes anything — it decides what the next upload may add.
Videos among the images
Paste the address of a video from YouTube, Vimeo, Dailymotion or TikTok and it takes its place among the images, in the same order, with a caption and an observation — it can even be the cover. Of the video itself only the thumbnail is kept here, and the public page contacts nobody until the visitor presses play.
It never reports anything anywhere
No telemetry: no counters, no domain, no versions. The plugin reports nothing whatsoever about your site to anybody. The only requests that ever leave are the ones the videos need — and every one of them is listed on the plugin page, service by service.
Three blocks, and the portfolio goes into any page
The plugin serves pages of its own — the portfolio’s page and each collection’s gallery — but nothing obliges you to use them. The same content goes into a page of your theme through a block, or through the matching shortcode.
| Block | What it shows | Shortcode |
|---|---|---|
| MontraFolio – Collection | The gallery of one collection, as tiles, as a carousel or as both, with a lightbox | [mtfl_collection portfolio="ana" collection="trip"] |
| MontraFolio – Portfolio | The collections of a portfolio, as cards | [mtfl_portfolio] |
| MontraFolio – Details | The cover, the author and the description of either of the two | [mtfl_details] |
The Collection block inherits what the owner proposed when it is not told otherwise. A list of collections can point every line at the same page, so that a single page serves as the index and as the gallery of whichever one the visitor picks.
Photographs of people are personal data
A site that lets three hundred people publish photographs has obligations the day one of them asks for their data, or leaves. The plugin handles that with no additional plugins.
| What | How |
|---|---|
| Camera metadata | Images are stored without it — not the model, not the date, not the coordinates of where it was taken |
| Export personal data | Tools → Export Personal Data includes everything the plugin keeps about the account |
| Erase personal data | Tools → Erase Personal Data deletes the personal portfolio with its images, releases assigned portfolios without touching their content, and anonymizes who uploaded what in the others |
| Accounts left behind | A retention rule can remove personal portfolios with no activity: the owner is warned a long time in advance and keeps it with one button |
| Privacy policy | The paragraphs to include are suggested on the WordPress privacy page |
| Content terms | Whoever publishes accepts them before the first upload; the version and the date are kept |
If a lot of people have photographs to show, it is for you
| Who | What they publish |
|---|---|
| Schools and training centers | Portfolios of students and trainees, field trips, class projects, exhibitions |
| Universities and art schools | Coursework, graduation portfolios, the archive of the studios |
| Towns and local government | Events, public works, town festivals, a photographic archive by year |
| Associations and clubs | Competitions, gatherings, tours, each section with its own collections |
| Photographers and studios | A gallery per job, some public and others hidden until they are shown |
| Companies and marketing | Campaigns, trade shows, an internal catalog, with people publishing without entering the back office |
Search, install, activate
Version
Updates arrive through the normal WordPress mechanism, like those of any plugin in the directory. The plugin has no update channel of its own, it will ask nothing of any server of ours, and it does not even know your site’s address.
What you need to have
- WordPress 6.5 or later and PHP 8.1 or later.
- Any theme. The blocks go into the theme’s pages; the pages the plugin serves it writes whole, and that is what lets it answer a request for an image before the theme has even loaded.
- No server configuration. On Apache and IIS the image folder protects itself; on nginx you add one
locationrule, described in the manual — but the real defense is the unguessable names and the delivery through the plugin. - Nothing to change in PHP. A photograph larger than what your host accepts in one request is sent in parts and put back together on the server. No limit of your host’s forces you to lower quality.
- No external service, except the video ones, and only where somebody uses them.
Before you ask
Do the images really stay out of the Media Library?
They do. They are kept in wp-content/uploads/montrafolio/, a folder protected against direct access, and delivered by the plugin after it has checked who is asking. They do not appear in the Library, they are not WordPress attachments, and they are not served at an address anybody can pass on.
Do my users have to reach wp-admin?
No. Owners and contributors work in the portfolio area, a page of the plugin at the address chosen in Settings (/p-admin/ by default). A user with nothing beyond a reading role lands there after signing in and never sees the dashboard.
Do I need another plugin to sign in?
No. People sign in with their own WordPress accounts, on the plugin’s page. A single sign-on plugin — Microsoft Entra ID, LDAP and others — is optional and plugs into the normal WordPress login pipeline; if the site wants it, the WordPress password form can even disappear and leave only the provider’s button. Sign-in can also be restricted to certain e-mail domains.
Does the plugin send anything out?
About your site, nothing: no usage counters, no domain, no versions — and updates come from WordPress.org along the same path as those of every other plugin. The single exception is videos, and only where somebody uses them: adding one asks the service for the title and the thumbnail; viewing the page asks for nothing until the visitor presses play. The four services are listed on the plugin’s page, with their terms and privacy policies, and any of them can be switched off.
Can I show a portfolio inside a page of my theme?
You can, with the three blocks — Collection, Portfolio and Details — or with the matching shortcodes. The portfolio is picked on the block itself, and one page can serve at the same time as the list of collections and as the gallery of whichever one the visitor picks.
What about HEIC photos from an iPhone?
They are accepted everywhere, and there is nothing to configure. Safari converts them on its own; the other browsers convert them on the device itself, with a library the plugin loads only when such a photograph turns up.
Can I limit how much each person uploads?
Yes, at four levels: what the site gives a new portfolio, the ceiling of each portfolio, what a collection narrows inside it, and what each contributor may upload in that collection. A level set to zero has no limit of its own and follows the one above, and the meter each person sees is the level that runs out first for them.
What languages is it in?
English, Portuguese and Spanish, chosen in a setting of the plugin itself — whatever language WordPress is running in. The public pages and the portfolio area were gone through with a fine comb for the keyboard, screen readers, reduced motion and AA contrast.
Three hundred people, three hundred portfolios
Searching for the plugin, activating it and deciding who may have one of their own takes less time than reading this page.
MontraFolio is an LG-Systems product. Support: support@lg-systems.net · Support forum · WordPress.org · GPLv2 or later license
