
Media Gallery Cleaner Security & Risk Analysis
wordpress.org/plugins/media-gallery-cleanerScans your website and identifies unused media files for cleanup.
Is Media Gallery Cleaner Safe to Use in 2026?
Generally Safe
Score 100/100Media Gallery Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The media-gallery-cleaner plugin v1.0.0 exhibits a generally good security posture, with several positive indicators. The code employs prepared statements for all SQL queries, a strong practice that mitigates SQL injection risks. Furthermore, over 98% of outputs are properly escaped, significantly reducing the likelihood of Cross-Site Scripting (XSS) vulnerabilities. The absence of critical or high-severity taint flows and a clean vulnerability history with zero known CVEs are also positive signs, suggesting diligent development and a stable codebase.
However, the plugin presents a significant concern due to its attack surface. It exposes two AJAX handlers, one of which lacks proper authentication checks. This unprotected entry point is a direct risk for potential unauthorized actions or information disclosure if not handled with extreme care. While the plugin does include nonce checks and capability checks on some entry points, the unprotected AJAX handler bypasses these crucial security layers. The presence of file operations, though only one, warrants attention in conjunction with the unprotected AJAX handler, as it could potentially be exploited in combination with other vulnerabilities if they were to exist.
In conclusion, the plugin has implemented several strong security practices, particularly concerning database interactions and output sanitization. The lack of historical vulnerabilities is commendable. However, the unprotected AJAX handler creates a critical security gap that significantly elevates the risk profile. Addressing this single, unprotected entry point should be the highest priority to improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handler
- File operation present
Media Gallery Cleaner Security Vulnerabilities
Media Gallery Cleaner Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Media Gallery Cleaner Attack Surface
AJAX Handlers 2
WordPress Hooks 2
Maintenance & Trust
Media Gallery Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
Media Gallery Cleaner Alternatives
Unused Media Cleaner
unused-media-cleaner
Unused Media Cleaner scans your WordPress site to find and remove unused media files, freeing storage and improving site speed and performance.
Unattached Media Manager
unattached-media-manager
Fix the WordPress Unattached media filter. Automatically attach used media files to their posts so you can safely clean up your library.
Media Hygiene: Remove or Delete Unused Images and More!
media-hygiene
The Media Hygiene plugin removes unused media from the WordPress library to free up space, reduce clutter, and improve server performance.
Media Tracker
media-tracker
Media Tracker is a WordPress plugin to find and remove unused media files, manage duplicates, and optimize your media library for better performance.
SpeedSize Image & Video AI-Optimizer
speedsize-ai-image-optimizer
SpeedSize Image & Video AI-Optimizer plugin allows you to easily use SpeedSize's Neuroscience Media Optimization on your WP website.
Media Gallery Cleaner Developer Profile
3 plugins · 20 total installs
How We Detect Media Gallery Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-gallery-cleaner/assets/css/admin.css/wp-content/plugins/media-gallery-cleaner/assets/js/admin.jsadmin.jsmedia-gallery-cleanerHTML / DOM Fingerprints
media-cleaner-cssmedia-cleaner-jsdata-mediaidmediaCleaner