Media Tracker Security & Risk Analysis
wordpress.org/plugins/media-trackerMedia Tracker is a WordPress plugin to find and remove unused media files, manage duplicates, and optimize your media library for better performance.
Is Media Tracker Safe to Use in 2026?
Generally Safe
Score 100/100Media Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'media-tracker' plugin v1.3.5 exhibits a generally good security posture, with a low overall risk. The static analysis reveals strong adherence to secure coding practices, as evidenced by the high percentage of prepared SQL statements and properly escaped output. Furthermore, the absence of known vulnerabilities (CVEs) and a clean vulnerability history suggests a well-maintained and secure codebase. The plugin also implements a good number of nonce and capability checks, indicating an awareness of common WordPress security mechanisms.
However, there are a few specific areas that introduce minor risks. The presence of the `unserialize` function, while not inherently a vulnerability, is a function that can lead to security issues if the serialized data is not properly validated or comes from untrusted sources. More importantly, one AJAX handler is identified as lacking authentication checks. This represents a direct attack vector that could potentially be exploited if an attacker can trigger this handler. The single taint flow with an unsanitized path, though not classified as critical or high severity, also warrants attention as it indicates a potential for unexpected data handling. The plugin's attack surface, while moderate, has a single exposed entry point.
In conclusion, 'media-tracker' v1.3.5 is a relatively secure plugin, with its strengths lying in its robust implementation of prepared statements, output escaping, and lack of historical vulnerabilities. The primary weaknesses lie in the single unauthenticated AJAX handler and the use of `unserialize`. Addressing these specific points would further enhance the plugin's security.
Key Concerns
- AJAX handler without auth checks
- Flow with unsanitized path (taint analysis)
- Dangerous function: unserialize
Media Tracker Security Vulnerabilities
Media Tracker Release Timeline
Media Tracker Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Media Tracker Attack Surface
AJAX Handlers 16
WordPress Hooks 19
Scheduled Events 2
Maintenance & Trust
Media Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Media Tracker Alternatives
PixRem – Unused Image Cleaner
pixrem
Find and delete unused images in your Media Library. Backup, restore, whitelist, and scan support for all major page builders.
Mediapapa – Your WordPress Media Library Manager & Copilot
mediapapa
WordPress media library manager: track usage, find duplicates, remove unused files, fix metadata and optimize images. Free.
Unused Media Cleaner
unused-media-cleaner
Unused Media Cleaner scans your WordPress site to find and remove unused media files, freeing storage and improving site speed and performance.
Unattached Media Manager
unattached-media-manager
Fix the WordPress Unattached media filter. Automatically attach used media files to their posts so you can safely clean up your library.
Media Cleaner and Database Optimizer by ITPath
itpathsolutions-media-cleaner-and-database-optimizer
The most powerful tool for clearing unused media from your website and optimizing your database to boost site performance
Media Tracker Developer Profile
3 plugins · 1K total installs
How We Detect Media Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-tracker/assets/dist/css/mt-admin.css/wp-content/plugins/media-tracker/assets/dist/js/mt-admin.js/wp-content/plugins/media-tracker/assets/dist/js/tab.js/wp-content/plugins/media-tracker/assets/dist/css/pro-lock.css/wp-content/plugins/media-tracker/assets/dist/js/mt-admin.js/wp-content/plugins/media-tracker/assets/dist/js/tab.jsmedia-tracker/assets/dist/css/mt-admin.css?ver=media-tracker/assets/dist/js/mt-admin.js?ver=media-tracker/assets/dist/js/tab.js?ver=media-tracker/assets/dist/css/pro-lock.css?ver=HTML / DOM Fingerprints
mediaTracker