Assetbroom – Unused Media & Duplicate Image Cleaner Security & Risk Analysis

wordpress.org/plugins/assetbroom-media-cleaner

Detect unused images, duplicate media files, and safely clean your WordPress media library without breaking your website.

0 active installs v1.0 PHP 7.4+ WP 6.0+ Updated Mar 9, 2026
cleancleaningmedia-cleaneroptimisationunused-images
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Assetbroom – Unused Media & Duplicate Image Cleaner Safe to Use in 2026?

Generally Safe

Score 100/100

Assetbroom – Unused Media & Duplicate Image Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The assetbroom-media-cleaner v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL injection vulnerabilities, unsanitized paths in taint analysis, or file operations significantly reduces the risk of common attack vectors. Furthermore, the use of prepared statements for all SQL queries and the majority of output escaping are excellent security practices. The presence of nonce checks, even without capability checks on all entry points, is also a positive indicator.

However, a notable concern is the complete lack of capability checks across all identified entry points. While the attack surface is reported as zero, this data might be incomplete if there are hidden entry points. Even with zero known CVEs and a clean vulnerability history, the absence of robust authorization checks presents a theoretical risk if any entry points were to be discovered or inadvertently exposed in future updates. This lack of comprehensive authorization is the primary area for improvement.

In conclusion, assetbroom-media-cleaner v1.0 appears to be a secure plugin with strong coding practices regarding data handling and output sanitization. Its vulnerability history is also a testament to its current state. The primary weakness lies in the potential for inadequate authorization enforcement, which, while not exploited in the current analysis, should be addressed to ensure long-term security.

Key Concerns

  • No capability checks on entry points
Vulnerabilities
None known

Assetbroom – Unused Media & Duplicate Image Cleaner Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Assetbroom – Unused Media & Duplicate Image Cleaner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
4
23 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

85% escaped27 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
dashboard (includes\class-abmc-admin.php:8)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Assetbroom – Unused Media & Duplicate Image Cleaner Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuassetbroom-media-cleaner.php:22
actionadmin_enqueue_scriptsassetbroom-media-cleaner.php:23
Maintenance & Trust

Assetbroom – Unused Media & Duplicate Image Cleaner Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads145

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Assetbroom – Unused Media & Duplicate Image Cleaner Developer Profile

KAP ASIAs

6 plugins · 5K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Assetbroom – Unused Media & Duplicate Image Cleaner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/assetbroom-media-cleaner/assets/admin.css/wp-content/plugins/assetbroom-media-cleaner/assets/admin.js
Script Paths
/wp-content/plugins/assetbroom-media-cleaner/assets/admin.js
Version Parameters
assetbroom-media-cleaner/assets/admin.css?ver=assetbroom-media-cleaner/assets/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
abmcAjaxabmcAjax.ajaxurlabmcAjax.nonce
FAQ

Frequently Asked Questions about Assetbroom – Unused Media & Duplicate Image Cleaner