
Media Library Tools – Rename, Clean & CSV Import/Export Security & Risk Analysis
wordpress.org/plugins/media-library-toolsMedia Rename, CSV export import, find unused media, search rubbish files, support SVG, bulk edit titles, ALT tags, captions & descriptions
Is Media Library Tools – Rename, Clean & CSV Import/Export Safe to Use in 2026?
Generally Safe
Score 98/100Media Library Tools – Rename, Clean & CSV Import/Export has a strong security track record. Known vulnerabilities have been patched promptly.
The "media-library-tools" v2.1.0 plugin presents a mixed security posture. While it demonstrates strong practices in its use of prepared statements for SQL queries and excellent output escaping, significant concerns arise from its attack surface. A large number of AJAX handlers (17 out of 19) lack authentication checks, creating potential entry points for unauthorized actions. The absence of critical or high severity taint flows is a positive sign, suggesting that current data processing might be more secure. However, the vulnerability history, with two known medium severity CVEs related to SQL Injection and Cross-site Scripting, indicates past weaknesses that users should be aware of. Although these are currently patched, the pattern suggests a need for continued vigilance and robust security practices within the plugin's development.
Overall, the plugin has strengths in its internal code sanitization and data handling. However, the exposed AJAX endpoints without proper authentication are a critical concern that could be exploited. The historical vulnerabilities, even if medium severity, highlight that past issues have been present and that the plugin is not immune to common web vulnerabilities. The developers should prioritize addressing the unauthenticated AJAX handlers to significantly improve the plugin's security profile. Future development should focus on maintaining the current code quality while ensuring all entry points are adequately protected.
Key Concerns
- Unprotected AJAX handlers
- Medium severity CVEs in history
- Limited nonce checks
- Limited capability checks
Media Library Tools – Rename, Clean & CSV Import/Export Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Media Library Tools <= 1.6.15 - Authenticated (Author+) SQL Injection
Media Library Tools <= 1.4.0 - Authenticated (Author+) Stored Cross-Site Scripting
Media Library Tools – Rename, Clean & CSV Import/Export Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Media Library Tools – Rename, Clean & CSV Import/Export Attack Surface
AJAX Handlers 19
Shortcodes 1
WordPress Hooks 39
Maintenance & Trust
Media Library Tools – Rename, Clean & CSV Import/Export Maintenance & Trust
Maintenance Signals
Community Trust
Media Library Tools – Rename, Clean & CSV Import/Export Alternatives
Export Media URLs
export-media-urls
An efficient media information extraction utility with CSV export option, suitable for several use-cases including migration and SEO.
Export/Import Media
calliope-media-import-export
The ultimate tool to migrate your media library. Export to CSV with Advanced Filters and Import securely with Drag & Drop (images, videos, audio a …
Media CSV Export (with filters)
media-csv-export-with-filters
Exports WordPress media files to a CSV file with filters by type, user, and date.
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
Product Import Export for WooCommerce – Import Export Product CSV Suite
product-import-export-for-woo
Easily import/export WooCommerce products (simple, grouped, external/affiliate) via CSV. Transfer product data, including images, reviews, categories, …
Media Library Tools – Rename, Clean & CSV Import/Export Developer Profile
2 plugins · 1K total installs
How We Detect Media Library Tools – Rename, Clean & CSV Import/Export
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-library-tools/app/Abs/../assets/css/styles.css/wp-content/plugins/media-library-tools/app/Abs/../assets/js/scripts.js/wp-content/plugins/media-library-tools/app/Abs/../assets/js/scripts.jsmedia-library-tools/app/Abs/../assets/css/styles.css?ver=media-library-tools/app/Abs/../assets/js/scripts.js?ver=HTML / DOM Fingerprints
tsmlt-offer-noticedata-tsmltdismissable="tsmlt_offer"tsmlt