
Autoremove Attachments Security & Risk Analysis
wordpress.org/plugins/autoremove-attachmentsRemove child attachments when parent post, page or custom post type is deleted.
Is Autoremove Attachments Safe to Use in 2026?
Generally Safe
Score 85/100Autoremove Attachments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "autoremove-attachments" plugin v1.3.1 exhibits a generally good security posture with no known vulnerabilities in its history and a limited attack surface. The static analysis reveals no direct entry points that are unprotected, indicating a conscious effort to implement security checks. The presence of nonce and capability checks, though limited, is a positive sign. However, the code analysis raises significant concerns regarding data handling. The plugin performs SQL queries, and a concerning 100% of these queries are not using prepared statements, posing a high risk of SQL injection vulnerabilities. Furthermore, a substantial portion of output (83%) is not properly escaped, leading to potential Cross-Site Scripting (XSS) vulnerabilities. The absence of taint analysis results is noted, but the identified SQL and output issues are critical enough to warrant immediate attention.
Key Concerns
- SQL queries not using prepared statements
- High percentage of unescaped output
Autoremove Attachments Security Vulnerabilities
Autoremove Attachments Code Analysis
SQL Query Safety
Output Escaping
Autoremove Attachments Attack Surface
WordPress Hooks 10
Maintenance & Trust
Autoremove Attachments Maintenance & Trust
Maintenance Signals
Community Trust
Autoremove Attachments Alternatives
Auto Attachments Cleaner
auto-attachments-cleaner
Automatically deletes attachments on post delete
All Round Order
all-round-order
Order all items(Pages, Posts, Custom Post Types and attachments) easily with a drag and drop feature
Reveal IDs
reveal-ids-for-wp-admin-25
What this plugin does is to reveal most removed IDs on admin pages, as it was in versions prior to 2.5.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Autoremove Attachments Developer Profile
2 plugins · 4K total installs
How We Detect Autoremove Attachments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autoremove-attachments/assets/css/admin.css/wp-content/plugins/autoremove-attachments/assets/js/admin.js/wp-content/plugins/autoremove-attachments/assets/js/admin.jsautoremove-attachments/assets/css/admin.css?ver=autoremove-attachments/assets/js/admin.js?ver=