
Cleanup Action Scheduler Security & Risk Analysis
wordpress.org/plugins/cleanup-action-schedulerDelete Action Scheduler Events to avoid having large database tables.
Is Cleanup Action Scheduler Safe to Use in 2026?
Generally Safe
Score 92/100Cleanup Action Scheduler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cleanup-action-scheduler" plugin version 1.2.4 demonstrates a generally good security posture based on the provided static analysis. It has a limited attack surface with only two AJAX entry points, and crucially, none of these are exposed without authentication checks. The absence of raw SQL queries, file operations, and external HTTP requests further strengthens its security. The high percentage of properly escaped output and the presence of nonce checks are positive indicators of secure coding practices. The taint analysis also revealed no critical or high severity unsanitized flows.
While the static analysis is encouraging, the lack of capability checks on the AJAX handlers is a potential concern. Although nonce checks are in place, relying solely on nonces without verifying user capabilities could allow authenticated users to perform actions they shouldn't. The bundled Freemius library, while not flagged as outdated in this report, is a component that should be monitored for potential vulnerabilities if it's an older version. However, the plugin's vulnerability history is exceptionally clean, with no recorded CVEs, suggesting a well-maintained and secure codebase. Overall, the plugin appears robust, but the missing capability checks represent a minor area for improvement to further harden its security.
Key Concerns
- AJAX handlers without capability checks
- Bundled library (Freemius v1.0) might be outdated
Cleanup Action Scheduler Security Vulnerabilities
Cleanup Action Scheduler Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Cleanup Action Scheduler Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Cleanup Action Scheduler Maintenance & Trust
Maintenance Signals
Community Trust
Cleanup Action Scheduler Alternatives
Easy Actions Scheduler Cleaner
easy-actions-scheduler-cleaner-ayudawp
Clean up your Actions Scheduler database with manual or scheduled cleanup. Remove old actions and logs automatically.
ZS Action Scheduler Optimizer
zs-action-scheduler-optimizer
This plugin optimizes Action Scheduler by clearing the Action Scheduler Actions table, truncating the logs, and modifying the retention period.
Failed Actions Monitor for Action Scheduler
failed-actions-monitor-for-action-scheduler
Monitors failed Action Scheduler jobs and sends daily email notifications about them.
Disable Bloat for WordPress & WooCommerce
disable-dashboard-for-woocommerce
All-in-One solution to speed up your WordPress & WooCommerce. Remove unnecessary features and make your site faster and cleaner.
Mobile Contact Bar
mobile-contact-bar
Allow your visitors to contact you via mobile phones, or access your site's pages instantly.
Cleanup Action Scheduler Developer Profile
5 plugins · 3K total installs
How We Detect Cleanup Action Scheduler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cleanup-action-scheduler/assets/build/css/admin.css/wp-content/plugins/cleanup-action-scheduler/assets/build/js/admin.jsHTML / DOM Fingerprints
cas_paramscas_delete_noncecas_paramscfas_fs