
Media Cleaner for WP Security & Risk Analysis
wordpress.org/plugins/media-cleaner-for-wpMedia Cleaner for WordPress is an essential tool designed to streamline your WordPress media library. It efficiently removes unused media files.
Is Media Cleaner for WP Safe to Use in 2026?
Generally Safe
Score 92/100Media Cleaner for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The media-cleaner-for-wp v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding output escaping, with all identified outputs being properly escaped. Furthermore, there's no recorded vulnerability history, suggesting a stable and well-maintained codebase in that regard. The absence of dangerous functions, file operations, and external HTTP requests are also strong security indicators.
However, significant concerns arise from the attack surface analysis. The plugin exposes 6 AJAX handlers, with a concerning 3 of them lacking any authentication checks. This represents a direct entry point for unauthorized actions. While the static analysis did not reveal any dangerous functions or taint flows, the potential for these to be exploited through the unprotected AJAX endpoints cannot be ignored. The SQL query usage is also a point of minor concern, with 44% not using prepared statements, which could be a vector for SQL injection if data originates from untrusted sources and isn't adequately sanitized before reaching these queries.
In conclusion, while the plugin has a clean vulnerability history and good output escaping, the lack of authentication on a substantial portion of its AJAX handlers is a critical security weakness that significantly elevates its risk profile. The SQL practices, while not ideal, are less immediately concerning than the exposed AJAX endpoints. Addressing the unprotected AJAX handlers should be the top priority for improving the security of this plugin.
Key Concerns
- AJAX handlers without auth checks
- SQL queries not using prepared statements
Media Cleaner for WP Security Vulnerabilities
Media Cleaner for WP Code Analysis
SQL Query Safety
Output Escaping
Media Cleaner for WP Attack Surface
AJAX Handlers 6
WordPress Hooks 2
Maintenance & Trust
Media Cleaner for WP Maintenance & Trust
Maintenance Signals
Community Trust
Media Cleaner for WP Alternatives
Media Cleaner: Clean your WordPress!
media-cleaner
Clean your WordPress! Eliminate unused and broken media files. For a faster, and better website.
Clean Image Filenames
clean-image-filenames
This plugin automatically converts language accent characters to non-accent characters in filenames when uploading to the media library.
Media Sweep – WordPress Media Cleaner
media-sweep
Clean up your WordPress Media Library by finding and removing unused files. Safely scan, preview, and sweep away orphaned media to keep your site fast …
File Media Renamer for SEO
file-media-renamer-for-seo
Rename media files with SEO-friendly names, auto-update references, alt/title sync, and 301 redirects — fast and safe.
Cleanup Orphan Images
cleanup-orphan-images
Finds and deletes orphan media files from the uploads directory that are not registered in WordPress.
Media Cleaner for WP Developer Profile
2 plugins · 20 total installs
How We Detect Media Cleaner for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-cleaner-for-wp/assets/css/style.css/wp-content/plugins/media-cleaner-for-wp/assets/js/script.js/wp-content/plugins/media-cleaner-for-wp/assets/js/script.jsmedia-cleaner-for-wp/assets/js/script.js?ver=media-cleaner-for-wp/assets/css/style.css?ver=HTML / DOM Fingerprints
mcfwp_ajax_var/wp-json/media-cleaner-for-wp/