
AMW Clear Upload Folder Security & Risk Analysis
wordpress.org/plugins/amw-clear-upload-folderRemoves unused files from the 'uploads' folder
Is AMW Clear Upload Folder Safe to Use in 2026?
Generally Safe
Score 100/100AMW Clear Upload Folder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "amw-clear-upload-folder" v1.1.5 plugin exhibits a concerning security posture primarily due to its extensive unprotected attack surface and lack of basic security checks. All 12 identified AJAX handlers are exposed without any authentication or capability checks, making them prime targets for unauthorized actions. Furthermore, the presence of the dangerous `unserialize` function, coupled with two high-severity taint flows involving unsanitized paths, indicates a significant risk of arbitrary code execution or data manipulation if malicious data can be injected into these flows.
The plugin also shows a complete absence of nonce checks and capability checks, which are fundamental WordPress security mechanisms. While there is no documented vulnerability history, this is likely due to the plugin not being widely used or analyzed, rather than a sign of inherent security. The poor output escaping (0% properly escaped) further exacerbates the risk, potentially leading to Cross-Site Scripting (XSS) vulnerabilities.
In conclusion, despite having no known CVEs, the plugin's code analysis reveals critical weaknesses. The unprotected AJAX endpoints, dangerous function usage, and unsanitized data flows represent a substantial security risk. Addressing these fundamental security oversights is paramount to mitigating potential exploitation.
Key Concerns
- All AJAX handlers lack authentication
- Dangerous function 'unserialize' used
- 2 high severity taint flows with unsanitized paths
- No nonce checks found
- No capability checks found
- 0% of outputs properly escaped
- SQL queries lack prepared statements (71%)
- File operations present without clear sanitization context
AMW Clear Upload Folder Security Vulnerabilities
AMW Clear Upload Folder Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
AMW Clear Upload Folder Attack Surface
AJAX Handlers 12
WordPress Hooks 5
Maintenance & Trust
AMW Clear Upload Folder Maintenance & Trust
Maintenance Signals
Community Trust
AMW Clear Upload Folder Alternatives
Pro Uploads Cleaner
pro-uploads-cleaner
Scan and clean unused images from your WordPress uploads folder safely.
Disable Media Sizes
disable-media-sizes
Provides options to disable the extra images generated by WordPress.
WP Image Size Limit
wp-image-size-limit
Adds a new setting under Settings -> Media where an admin can set a maximum upload file size for image files.
PixRem – Unused Image Cleaner
pixrem
Find and delete unused images in your Media Library. Backup, restore, whitelist, and scan support for all major page builders.
Assetbroom – Unused Media & Duplicate Image Cleaner
assetbroom-media-cleaner
Detect unused images, duplicate media files, and safely clean your WordPress media library without breaking your website.
AMW Clear Upload Folder Developer Profile
1 plugin · 10 total installs
How We Detect AMW Clear Upload Folder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amw-clear-upload-folder/assets/css/bootstrap-responsive.css/wp-content/plugins/amw-clear-upload-folder/assets/css/bootstrap.css/wp-content/plugins/amw-clear-upload-folder/assets/css/amw-style.css/wp-content/plugins/amw-clear-upload-folder/assets/js/bootstrap.js/wp-content/plugins/amw-clear-upload-folder/assets/js/sweetalert.min.js/wp-content/plugins/amw-clear-upload-folder/assets/js/amw-admin.js/wp-content/plugins/amw-clear-upload-folder/assets/js/amw-settings.js/wp-content/plugins/amw-clear-upload-folder/assets/js/bootstrap.js/wp-content/plugins/amw-clear-upload-folder/assets/js/sweetalert.min.js/wp-content/plugins/amw-clear-upload-folder/assets/js/amw-admin.js/wp-content/plugins/amw-clear-upload-folder/assets/js/amw-settings.jsamw-clear-upload-folder/assets/js/bootstrap.js?ver=amw-clear-upload-folder/assets/js/sweetalert.min.js?ver=amw-clear-upload-folder/assets/js/amw-admin.js?ver=amw-clear-upload-folder/assets/js/amw-settings.js?ver=amw-clear-upload-folder/assets/css/bootstrap.css?ver=amw-clear-upload-folder/assets/css/bootstrap-responsive.css?ver=amw-clear-upload-folder/assets/css/amw-style.css?ver=HTML / DOM Fingerprints
amw-clear-upload-folder-wrap<!-- Clear Upload Folder --><!-- AMW CUF -->data-amw-cuf-actiondata-amw-cuf-nonceamw_cuf_admin_obj