Bulk Media Register Security & Risk Analysis

wordpress.org/plugins/bulk-media-register

Bulk register files on the server to the Media Library.

8K active installs v1.41 PHP 8.0+ WP 4.6+ Updated Mar 29, 2026
filesftpimportmediauploads
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bulk Media Register Safe to Use in 2026?

Generally Safe

Score 100/100

Bulk Media Register has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "bulk-media-register" plugin v1.41 presents a mixed security picture. On the positive side, static analysis reveals no identified dangerous functions, no file operations, no external HTTP requests, and all identified outputs are properly escaped. The plugin also has no recorded vulnerability history, with zero known CVEs of any severity. This suggests a generally cautious approach to development and maintenance in certain areas. However, significant concerns arise from the complete absence of authorization checks on any entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, the single SQL query found is not using prepared statements, which is a notable vulnerability. The lack of nonces and capability checks across the board, combined with the absence of taint analysis data, leaves potential security gaps unexamined. While the plugin appears clean in terms of known vulnerabilities, the critical lack of access control mechanisms on all its potential interaction points represents a significant risk that could be exploited if any attack vectors were discovered or introduced.

Key Concerns

  • Raw SQL query without prepared statements
  • Missing capability checks on all entry points
  • Missing nonce checks on AJAX handlers
  • No permission callbacks on REST API routes
  • Potential unexamined taint flows
Vulnerabilities
None known

Bulk Media Register Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bulk Media Register Release Timeline

v1.41Current
v1.40
v1.39
v1.38
v1.37
v1.36
v1.35
v1.34
v1.33
v1.32
v1.31
v1.30
v1.26
v1.25
v1.24
v1.23
v1.22
v1.21
v1.20
v1.19
Code Analysis
Analyzed Mar 16, 2026

Bulk Media Register Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries
Attack Surface

Bulk Media Register Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Bulk Media Register Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 29, 2026
PHP min version8.0
Downloads128K

Community Trust

Rating90/100
Number of ratings22
Active installs8K
Developer Profile

Bulk Media Register Developer Profile

Katsushi Kawamori

54 plugins · 56K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
178 days
View full developer profile
Detection Fingerprints

How We Detect Bulk Media Register

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bulk-media-register/css/style.css/wp-content/plugins/bulk-media-register/js/main.js
Script Paths
/wp-content/plugins/bulk-media-register/js/main.js
Version Parameters
bulk-media-register/css/style.css?ver=bulk-media-register/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
bulk-media-register-wrap
HTML Comments
bulk-media-register
Data Attributes
data-bulkmediaregister-action
JS Globals
bulkMediaRegister
FAQ

Frequently Asked Questions about Bulk Media Register