
Bulk Change Media Author Security & Risk Analysis
wordpress.org/plugins/bulk-change-media-authorBulk change author for multiple media files, using the default WP Media Library.
Is Bulk Change Media Author Safe to Use in 2026?
Generally Safe
Score 85/100Bulk Change Media Author has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bulk-change-media-author" plugin v1.3.2 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) in its history, suggesting a generally stable and secure codebase. Furthermore, the static analysis reveals a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events detected. The absence of dangerous functions, file operations, and external HTTP requests also contributes positively to its security profile. The plugin also exclusively uses prepared statements for its SQL queries, which is an excellent security practice.
However, several concerns are raised by the static analysis. A significant portion of output (73%) is not properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is reflected in the output. The taint analysis indicates two flows with unsanitized paths, although these did not reach critical or high severity. This could still lead to information disclosure or path traversal if exploited, especially in conjunction with the unescaped output. The complete lack of nonce and capability checks is also a major concern, as it means any authenticated user, regardless of their role or permissions, could potentially trigger actions within the plugin. This lack of authorization checks, combined with the unescaped output, is the most significant risk identified.
Key Concerns
- Significant amount of unescaped output
- Taint flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
Bulk Change Media Author Security Vulnerabilities
Bulk Change Media Author Code Analysis
Output Escaping
Data Flow Analysis
Bulk Change Media Author Attack Surface
WordPress Hooks 4
Maintenance & Trust
Bulk Change Media Author Maintenance & Trust
Maintenance Signals
Community Trust
Bulk Change Media Author Alternatives
Media Deduper
media-deduper
Save disk space and bring some order to the chaos of your media library by removing and preventing duplicate files.
F4 Media Taxonomies
f4-media-taxonomies
Add filters and bulk actions for attachment categories, tags and custom taxonomies.
LH Copy Media File
lh-copy-media-file
Allows you to create duplicate images in the media library.
Default Media Uploader View
default-media-uploader-view
Sets "Uploaded to this post" instead of "All media items" as the default view in the media uploader.
bbPress Multi Image Uploader
bbpress-multi-image-uploader
Upload multiple images to bbPress topics and replies.
Bulk Change Media Author Developer Profile
1 plugin · 2K total installs
How We Detect Bulk Change Media Author
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bulk-change-media-author/languages/HTML / DOM Fingerprints
resultmediamedia-authormedia-thumbname="for"name="author"name="media"window.location