
Clean Unused Medias Security & Risk Analysis
wordpress.org/plugins/clean-unused-mediasClean Unused Medias, another simple way to delete the medias you don't need anymore.
Is Clean Unused Medias Safe to Use in 2026?
Generally Safe
Score 85/100Clean Unused Medias has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "clean-unused-medias" plugin v1.10 presents a significant security risk due to a large number of unprotected AJAX handlers. With 10 AJAX handlers identified, all lacking authentication checks, any user, regardless of their role or permissions, can trigger these functions. This creates a broad attack surface that could be exploited to perform unintended actions within the WordPress site. The presence of the `unserialize` function, coupled with one high-severity taint flow involving an unsanitized path, further exacerbates the risk. While the plugin has no recorded vulnerability history, this absence could be due to lack of rigorous security testing or a small user base, rather than inherent security. The lack of capability checks and proper output escaping also contributes to a weak security posture. Overall, the plugin's strengths, such as a high percentage of prepared SQL statements, are overshadowed by critical weaknesses in authentication and input sanitization for its entry points.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow
- Dangerous function unserialize
- No capability checks
- Unescaped output
- Unsanitized paths in taint flow
Clean Unused Medias Security Vulnerabilities
Clean Unused Medias Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Clean Unused Medias Attack Surface
AJAX Handlers 10
WordPress Hooks 12
Scheduled Events 2
Maintenance & Trust
Clean Unused Medias Maintenance & Trust
Maintenance Signals
Community Trust
Clean Unused Medias Alternatives
Delete Post with Attachments
delete-post-with-attachments
A simple plugin to delete attached media files e.g. images/videos/documents, when the post is deleted. Supports Elementor, Divi Builder, Thrive Archit …
whatwedo ACF Cleaner
whatwedo-acf-cleaner
Cleanup old metadata created by Advanced Custom Fields.
Advanced Custom Fields: Real Media Library Folder Field
acf-real-media-library-field
Media library folder field for Advanced Custom Fields (ACF). Folder created by Real Media Library.
Advance Importer
advance-importer
A powerful plugin for import and export Post, Page, any Custom post type data, with any kind of attachments.
MCOD Delete Media by Content
mcod-bulk-delete-media-by-content
Bulk delete WordPress media files linked to any post type. Clean your media library in batches with smart exclusions and WooCommerce/ACF support.
Clean Unused Medias Developer Profile
4 plugins · 180 total installs
How We Detect Clean Unused Medias
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clean-unused-medias/library/css/admin.css/wp-content/plugins/clean-unused-medias/library/js/admin.jsclean-unused-medias/library/css/admin.css?ver=clean-unused-medias/library/js/admin.js?ver=HTML / DOM Fingerprints
lnjcm-admin-contentlnjcm_delete_all_unused_medias_confirmlnjcm_delete_all_unused_medias