
Auto Delete Unattached Media Security & Risk Analysis
wordpress.org/plugins/auto-delete-unattached-mediaAutomatically delete unattached/unused media/images/attachments every minute silently in the background.
Is Auto Delete Unattached Media Safe to Use in 2026?
Generally Safe
Score 85/100Auto Delete Unattached Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'auto-delete-unattached-media' plugin v1.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the complete output escaping all indicate adherence to secure coding practices. Furthermore, the lack of external HTTP requests, file operations, and a minimal attack surface with no identified unprotected entry points contribute to its robust security. The plugin's vulnerability history is also clean, with no recorded CVEs, suggesting a well-maintained and secure codebase over time.
While the static analysis reveals no immediate vulnerabilities, the absence of nonce checks and capability checks on certain potential entry points (specifically the cron event, although its functionality is not detailed) could present a theoretical risk if the cron event were to perform sensitive actions. However, without further details on the cron event's implementation and the specific actions it takes, it is difficult to assign a concrete risk. The zero taint flows and zero unsanitized paths are positive indicators, but the analysis may not cover all potential interaction vectors. Overall, the plugin appears to be secure, but a deeper review of the cron event's implementation would be beneficial to confirm its complete security.
Key Concerns
- Missing nonce checks on cron event
- Missing capability checks on cron event
Auto Delete Unattached Media Security Vulnerabilities
Auto Delete Unattached Media Code Analysis
Auto Delete Unattached Media Attack Surface
WordPress Hooks 2
Scheduled Events 1
Maintenance & Trust
Auto Delete Unattached Media Maintenance & Trust
Maintenance Signals
Community Trust
Auto Delete Unattached Media Alternatives
Media Hygiene: Remove or Delete Unused Images and More!
media-hygiene
The Media Hygiene plugin removes unused media from the WordPress library to free up space, reduce clutter, and improve server performance.
Image Sizes Panel
image-sizes-panel
Display a meta box when viewing a media item in the admin that display all generated images sizes.
WP Tesseract
wp-tesseract
A plugin for extracting text from attached images using OCR via Tesseract.
PixRem – Unused Image Cleaner
pixrem
Find and delete unused images in your Media Library. Backup, restore, whitelist, and scan support for all major page builders.
AIR Download Attachments
air-download-attachments
The AIR Download Attachments plugin adds a "Download All Attachments" button to posts, allowing users to download all attached images as a z …
Auto Delete Unattached Media Developer Profile
2 plugins · 230 total installs
How We Detect Auto Delete Unattached Media
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.