
LWS Cleaner Security & Risk Analysis
wordpress.org/plugins/lws-cleanerClean everything on your website easily!
Is LWS Cleaner Safe to Use in 2026?
Generally Safe
Score 94/100LWS Cleaner has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'lws-cleaner' plugin v2.4.3 exhibits a mixed security posture. While the static analysis shows a high percentage of properly escaped output and a lack of critical taint flows, several concerning areas persist. The plugin exposes a significant attack surface with 16 AJAX handlers, and alarmingly, one of these lacks any authentication checks. This is a major security gap that could allow unauthorized users to trigger plugin functionality.
The vulnerability history of this plugin is a significant concern. It has a history of three known CVEs, with two classified as high severity, one medium, and a common pattern including Absolute Path Traversal, Cross-Site Request Forgery (CSRF), and Missing Authorization. Although there are currently no unpatched vulnerabilities, this history indicates a recurring tendency to introduce critical security flaws. The last reported vulnerability was in September 2025, suggesting potential for new issues to arise.
In conclusion, while the plugin demonstrates some good practices like extensive output escaping and no reported critical taint flows, the unprotected AJAX handler and the consistent history of high-severity vulnerabilities, particularly those related to authorization and path traversal, present a considerable risk. Users should exercise caution and ensure the plugin is kept up-to-date, and actively monitor for any new security advisories.
Key Concerns
- AJAX handler without authentication
- SQL queries without prepared statements
- Two high severity past CVEs
- One medium severity past CVE
- Vulnerability history: Missing Authorization
- Vulnerability history: Absolute Path Traversal
- Vulnerability history: CSRF
LWS Cleaner Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
LWS Cleaner <= 2.4.1.3 - Authenticated (Administrator+) Arbitrary File Deletion via 'lws_cl_delete_file'
LWS Cleaner <= 2.3.0 - Cross-Site Request Forgery
LWS Plugins <= (Various Versions) - Missing Authorization Checks
LWS Cleaner Release Timeline
LWS Cleaner Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LWS Cleaner Attack Surface
AJAX Handlers 16
WordPress Hooks 9
Maintenance & Trust
LWS Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
LWS Cleaner Alternatives
LWS Tools
lws-tools
Optimize and modify your website's parameters
Assetbroom – Unused Media & Duplicate Image Cleaner
assetbroom-media-cleaner
Detect unused images, duplicate media files, and safely clean your WordPress media library without breaking your website.
LWS Hide Login
lws-hide-login
Secure your access to the admin page with this plugin !
PhastPress
phastpress
PhastPress automatically optimizes your site for the best possible performance.
LWSCache
lwscache
This plugin lets you manage and automatically purge your hosting's LWSCache whenever you edit your website's content
LWS Cleaner Developer Profile
6 plugins · 78K total installs
How We Detect LWS Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lws-cleaner/css/lws_cl_style.css/wp-content/plugins/lws-cleaner/css/lws_cl_style_out.cssHTML / DOM Fingerprints
lwscl_review_block_generallws_cl_circlelwscl_review_block_imagelwscl_review_block_titlelwscl_review_block_desclwscl_button_rate_pluginlwscl_review_button_secondaryid="lws_cl_review_notice"action: "lws_cleaner_reminder_ajax"action: "lws_cleaner_donotask_ajax"lws_cl_remind_melws_cl_do_not_bother_me