
Bulk Trash by URL Security & Risk Analysis
wordpress.org/plugins/bulk-trash-by-urlBulk‑trash posts, pages and custom post types from pasted URLs. Fast URL mapping, batched processing with pause/resume, and an optional summary.
Is Bulk Trash by URL Safe to Use in 2026?
Generally Safe
Score 100/100Bulk Trash by URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bulk-trash-by-url' v1.1 plugin presents a generally good security posture, demonstrating several positive security practices. The static analysis reveals no critical security weaknesses such as dangerous functions, raw SQL queries, or file operations. Furthermore, the absence of known CVEs and a clean vulnerability history suggest a mature and well-maintained codebase. The plugin also utilizes nonces and capability checks, which are essential for protecting against common WordPress vulnerabilities, and its SQL queries are all prepared statements.
However, a potential area of concern lies in the output escaping, with only 60% of outputs being properly escaped. This could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without adequate sanitization. While the attack surface of AJAX handlers is small and none are explicitly found to be unprotected, a thorough review of the 3 AJAX handlers is recommended to ensure all inputs are properly validated and escaped before being processed or displayed.
Overall, 'bulk-trash-by-url' v1.1 is a relatively secure plugin with a strong foundation. Addressing the output escaping issues should be a priority to further harden the plugin against potential XSS attacks. The low number of entry points and absence of critical code signals are positive indicators of its current security standing.
Key Concerns
- Low output escaping percentage
Bulk Trash by URL Security Vulnerabilities
Bulk Trash by URL Code Analysis
Output Escaping
Data Flow Analysis
Bulk Trash by URL Attack Surface
AJAX Handlers 3
WordPress Hooks 2
Maintenance & Trust
Bulk Trash by URL Maintenance & Trust
Maintenance Signals
Community Trust
Bulk Trash by URL Alternatives
Smart Bulk Delete & Content Cleaner for WordPress
smart-bulk-content-remover
Safely bulk delete posts, pages, media, and comments with flexible filters and a clean interface.
Content Unpublisher
content-unpublisher
A lightweight plugin to automatically unpublish or trash posts and pages at a scheduled time.
Duplicate Post
copy-delete-posts
Duplicate post
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
CMS Tree Page View
cms-tree-page-view
Adds a tree view of all pages & custom posts. Get a great overview + options to drag & drop to reorder & option to add multiple pages.
Bulk Trash by URL Developer Profile
1 plugin · 10 total installs
How We Detect Bulk Trash by URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bulk-trash-by-url/admin/trasher.js/wp-content/plugins/bulk-trash-by-url/admin/trasher.jsbulk-trash-by-url/admin/trasher.js?ver=HTML / DOM Fingerprints
bulktrbybulktrby_trashbulktrby_mapbulktrby_summarybulktrby/wp-json/bulktrby/v1/bulk_trash/wp-json/bulktrby/v1/map_urls/wp-json/bulktrby/v1/store_summary