Media Tracker Security & Risk Analysis
wordpress.org/plugins/media-trackerMedia Tracker is a WordPress plugin to find and remove unused media files, manage duplicates, and optimize your media library for better performance.
Is Media Tracker Safe to Use in 2026?
Generally Safe
Score 100/100Media Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'media-tracker' plugin v1.3.5 exhibits a generally good security posture, with a low overall risk. The static analysis reveals strong adherence to secure coding practices, as evidenced by the high percentage of prepared SQL statements and properly escaped output. Furthermore, the absence of known vulnerabilities (CVEs) and a clean vulnerability history suggests a well-maintained and secure codebase. The plugin also implements a good number of nonce and capability checks, indicating an awareness of common WordPress security mechanisms.
However, there are a few specific areas that introduce minor risks. The presence of the `unserialize` function, while not inherently a vulnerability, is a function that can lead to security issues if the serialized data is not properly validated or comes from untrusted sources. More importantly, one AJAX handler is identified as lacking authentication checks. This represents a direct attack vector that could potentially be exploited if an attacker can trigger this handler. The single taint flow with an unsanitized path, though not classified as critical or high severity, also warrants attention as it indicates a potential for unexpected data handling. The plugin's attack surface, while moderate, has a single exposed entry point.
In conclusion, 'media-tracker' v1.3.5 is a relatively secure plugin, with its strengths lying in its robust implementation of prepared statements, output escaping, and lack of historical vulnerabilities. The primary weaknesses lie in the single unauthenticated AJAX handler and the use of `unserialize`. Addressing these specific points would further enhance the plugin's security.
Key Concerns
- AJAX handler without auth checks
- Flow with unsanitized path (taint analysis)
- Dangerous function: unserialize
Media Tracker Security Vulnerabilities
Media Tracker Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Media Tracker Attack Surface
AJAX Handlers 16
WordPress Hooks 19
Scheduled Events 2
Maintenance & Trust
Media Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Media Tracker Alternatives
PixRem – Unused Image Cleaner
pixrem
Find and delete unused images in your Media Library. Backup, restore, whitelist, and scan support for all major page builders.
Unused Media Cleaner
unused-media-cleaner
Unused Media Cleaner scans your WordPress site to find and remove unused media files, freeing storage and improving site speed and performance.
Media Cleaner and Database Optimizer by ITPath
itpathsolutions-media-cleaner-and-database-optimizer
The most powerful tool for clearing unused media from your website and optimizing your database to boost site performance
Assetbroom – Unused Media & Duplicate Image Cleaner
assetbroom-media-cleaner
Detect unused images, duplicate media files, and safely clean your WordPress media library without breaking your website.
Media Gallery Cleaner
media-gallery-cleaner
Scans your website and identifies unused media files for cleanup.
Media Tracker Developer Profile
3 plugins · 1K total installs
How We Detect Media Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-tracker/assets/dist/css/mt-admin.css/wp-content/plugins/media-tracker/assets/dist/js/mt-admin.js/wp-content/plugins/media-tracker/assets/dist/js/tab.js/wp-content/plugins/media-tracker/assets/dist/css/pro-lock.css/wp-content/plugins/media-tracker/assets/dist/js/mt-admin.js/wp-content/plugins/media-tracker/assets/dist/js/tab.jsmedia-tracker/assets/dist/css/mt-admin.css?ver=media-tracker/assets/dist/js/mt-admin.js?ver=media-tracker/assets/dist/js/tab.js?ver=media-tracker/assets/dist/css/pro-lock.css?ver=HTML / DOM Fingerprints
mediaTracker