
Database Cleaner Security & Risk Analysis
wordpress.org/plugins/database-cleanerUser-friendly tool to clean and optimize databases. Efficiently manages large databases, simplifying repair and ensuring peak performance.
Is Database Cleaner Safe to Use in 2026?
Generally Safe
Score 99/100Database Cleaner has a strong security track record. Known vulnerabilities have been patched promptly.
The "database-cleaner" plugin v1.3.4 presents a mixed security posture. On the positive side, the static analysis reveals a lack of critical vulnerabilities in terms of attack surface, dangerous functions, and taint analysis. The plugin demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output. File operations are present but don't appear to be directly exposed to external input based on the available data. However, there are notable areas of concern. The absence of any nonce checks, despite having 11 capability checks, is a significant weakness. This could leave the plugin vulnerable to CSRF attacks if any of its functionalities are manipulated by an attacker. The presence of 2 medium severity historical vulnerabilities, specifically "Path Traversal" and "Insertion of Sensitive Information into Log File", even though currently unpatched, suggests past security oversights and potential for similar issues to re-emerge. The bundling of "Freemius" is also a factor to consider, as it represents an external dependency that could introduce its own security risks if not properly managed.
Key Concerns
- No nonce checks on any entry points
- 2 medium severity CVEs historically, last one recent
- Bundled library (Freemius)
Database Cleaner Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Database Cleaner <= 1.0.5 - Authenticated (Admin+) Arbitrary File Read
Database Cleaner <= 0.9.8 - Sensitive Information Exposure via Log File
Database Cleaner Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Database Cleaner Attack Surface
WordPress Hooks 60
Scheduled Events 5
Maintenance & Trust
Database Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
Database Cleaner Alternatives
Media Cleaner and Database Optimizer by ITPath
itpathsolutions-media-cleaner-and-database-optimizer
The most powerful tool for clearing unused media from your website and optimizing your database to boost site performance
Aims Quick Cleanup Tools
aims-quick-cleanup-tools
A fast and simple one-click toolset to clean, repair, and optimize your WordPress site.
Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance
advanced-database-cleaner
Clean database by deleting orphaned data such as 'revisions', 'expired transients', optimize database and more...
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
WPS Cleaner
wps-cleaner
WPS Cleaner cleans your WordPress site as well as your database.
Database Cleaner Developer Profile
27 plugins · 371K total installs
How We Detect Database Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/database-cleaner/app/vendor.js/wp-content/plugins/database-cleaner/app/index.js/wp-content/plugins/database-cleaner/app/vendor.js/wp-content/plugins/database-cleaner/app/index.jsdatabase-cleaner/app/index.js?ver=database-cleaner/app/vendor.js?ver=HTML / DOM Fingerprints
dbclnr-admin-settingsdbclnr/database-cleaner/v1