Easy WP Cleaner Security & Risk Analysis

wordpress.org/plugins/easy-wp-cleaner

Easy WP Cleaner is user friendly plugin to clean unnecessary data from WordPress database and also allows you to optimize your WordPress database.

2K active installs v2.2 PHP + WP 3.7+ Updated Oct 8, 2025
cachecleancleanerdatabaseeasy-wp-cleaner
100
A · Safe
CVEs total1
Unpatched0
Last CVESep 5, 2023
Safety Verdict

Is Easy WP Cleaner Safe to Use in 2026?

Generally Safe

Score 100/100

Easy WP Cleaner has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 5, 2023Updated 7mo ago
Risk Assessment

The overall security posture of easy-wp-cleaner v2.2 presents a mixed picture. On the positive side, the plugin demonstrates strong practices regarding SQL query handling, with all 23 queries utilizing prepared statements, and it includes a healthy number of nonce checks (12). The absence of external HTTP requests and file operations also contributes to a more secure baseline. However, a significant concern emerges from the output escaping, where 100% of the 25 outputs are not properly escaped. This lack of sanitization for output data could lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the pages where this plugin's output is displayed.

The static analysis shows a clean slate in terms of dangerous functions and taint analysis, with no identified critical or high severity issues. The attack surface is also reported as zero, which is highly encouraging. Despite these strengths, the vulnerability history indicates a past medium-severity vulnerability, identified as CSRF on September 5, 2023. While this vulnerability is reported as unpatched, it is important to note that the static analysis did not reveal any current indications of CSRF. This historical context suggests a potential for past security oversights, even if current code appears to have addressed that specific issue or it was resolved in a later version not captured by this specific analysis of v2.2.

In conclusion, while easy-wp-cleaner v2.2 exhibits good practices in database interactions and attack surface management, the critical lack of output escaping is a major security weakness that could expose users to XSS attacks. The past CSRF vulnerability, though historical, serves as a reminder to remain vigilant. Addressing the unescaped output is paramount to improving the plugin's security.

Key Concerns

  • 100% of outputs are not properly escaped
  • 1 medium severity vulnerability historically
Vulnerabilities
1 published

Easy WP Cleaner Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-41697medium · 5.4Cross-Site Request Forgery (CSRF)

Easy WP Cleaner <= 1.9 - Cross-Site Request Forgery

Sep 5, 2023 Patched in 2.0 (256d)
Version History

Easy WP Cleaner Release Timeline

v2.2Current
v2.1
v2.0
v1.91 CVE
v1.81 CVE
v1.71 CVE
v1.61 CVE
v1.51 CVE
v1.41 CVE
v1.31 CVE
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Easy WP Cleaner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
23 prepared
Unescaped Output
25
0 escaped
Nonce Checks
12
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared23 total queries

Output Escaping

0% escaped25 total outputs
Attack Surface

Easy WP Cleaner Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menueasy-wp-cleaner.php:28
Maintenance & Trust

Easy WP Cleaner Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 8, 2025
PHP min version
Downloads48K

Community Trust

Rating100/100
Number of ratings41
Active installs2K
Developer Profile

Easy WP Cleaner Developer Profile

Nikunj Soni

6 plugins · 3K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
256 days
View full developer profile
Detection Fingerprints

How We Detect Easy WP Cleaner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-wp-cleaner/easy-wp-cleaner-admin.php/wp-content/plugins/easy-wp-cleaner/easy-wp-cleaner-help.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Easy WP Cleaner