
Media Export & Clean Security & Risk Analysis
wordpress.org/plugins/media-export-cleanExport your entire WordPress Media Library to a ZIP file and safely clean unused files from your uploads directory.
Is Media Export & Clean Safe to Use in 2026?
Generally Safe
Score 100/100Media Export & Clean has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The media-export-clean plugin v1.2.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. All identified AJAX entry points have nonces and capability checks, indicating proper authorization handling for these potentially sensitive operations. The plugin also demonstrates excellent practice by using prepared statements for all SQL queries and properly escaping all output, mitigating common injection and cross-site scripting (XSS) vulnerabilities. The absence of known CVEs and historical vulnerabilities further strengthens this positive assessment, suggesting a well-maintained and secure codebase.
However, there are two areas that warrant attention. The taint analysis revealed two flows with unsanitized paths. While no critical or high-severity issues were flagged from these flows, unsanitized paths are a common precursor to file inclusion or path traversal vulnerabilities if not handled with extreme care. The presence of file operations, while not inherently risky, combined with these unsanitized path flows, creates a potential area for exploitation if the file operations themselves are not rigorously validated against user-supplied input that influences the path.
In conclusion, media-export-clean v1.2.2 is commendably secure in its handling of user input for SQL and output to the browser, and its authentication mechanisms are robust. The primary concern lies with the identified unsanitized paths, which, despite not resulting in critical findings in this analysis, represent a latent risk that should be addressed to ensure complete security.
Key Concerns
- Flows with unsanitized paths detected
Media Export & Clean Security Vulnerabilities
Media Export & Clean Release Timeline
Media Export & Clean Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Media Export & Clean Attack Surface
AJAX Handlers 9
WordPress Hooks 2
Maintenance & Trust
Media Export & Clean Maintenance & Trust
Maintenance Signals
Community Trust
Media Export & Clean Alternatives
Export Media Library
export-media-library
Allows users to export media library files as a compressed zip archive. Links Website Support
Media Library Organizer – WordPress Media Library Folders & File Manager
media-library-organizer
Create unlimited Media Library folders and subfolders to organize your files. Export Media Library folders, set default attributes & more.
Media Library File Download
media-download
A lightweight plugin that adds one-click download and export functionality to your Media Library.
Export Media as ZIP
export-media-as-zip
Export images from your WordPress media library as a ZIP file — filter by year and image size before downloading.
Upload Media by Zip
upload-media-by-zip
Upload a zip archive and let WP unzip it and attach everything to a page/post (or not).
Media Export & Clean Developer Profile
1 plugin · 0 total installs
How We Detect Media Export & Clean
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-export-clean/css/admin.css/wp-content/plugins/media-export-clean/js/admin.js/wp-content/plugins/media-export-clean/js/admin.jsmedia-export-clean/css/admin.css?ver=media-export-clean/js/admin.js?ver=HTML / DOM Fingerprints
mediexcl-dashboarddata-hook="mediexcl-dashboard"mediexcl_vars