
Oli Media Cleaner Security & Risk Analysis
wordpress.org/plugins/oli-media-cleanerScan and remove unused media files from your WordPress site to free up disk space.
Is Oli Media Cleaner Safe to Use in 2026?
Generally Safe
Score 100/100Oli Media Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The oli-media-cleaner plugin v1.5.0 exhibits a concerning security posture primarily due to a large number of unprotected AJAX endpoints. While the plugin demonstrates good practices in its use of prepared statements for SQL queries and generally robust output escaping, the 16 AJAX handlers without authentication checks represent a significant attack surface. This means any unauthenticated user could potentially trigger functionality within these handlers, leading to unintended actions or information disclosure.
The taint analysis reveals a high severity flow with unsanitized paths, indicating a potential vulnerability where user-supplied input might not be properly validated before being used in a sensitive operation. Coupled with the presence of the `unserialize` function, which is inherently risky when dealing with untrusted input, this warrants careful investigation and immediate remediation.
The plugin's vulnerability history is clean, with no known CVEs. This is a positive indicator, suggesting the developers may be diligent in addressing security issues as they arise. However, the static analysis findings, particularly the unprotected AJAX endpoints and the identified taint flow, highlight existing weaknesses that could be exploited even without prior known vulnerabilities. The overall assessment is that while the plugin has strengths in some areas, the unprotected attack surface and the taint flow represent significant risks that need to be addressed.
Key Concerns
- 16 AJAX handlers without auth checks
- High severity taint flow with unsanitized paths
- Use of dangerous function: unserialize
- 1 total flow with unsanitized paths
Oli Media Cleaner Security Vulnerabilities
Oli Media Cleaner Release Timeline
Oli Media Cleaner Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Oli Media Cleaner Attack Surface
AJAX Handlers 16
WordPress Hooks 3
Scheduled Events 1
Maintenance & Trust
Oli Media Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
Oli Media Cleaner Alternatives
Unattached Media Manager
unattached-media-manager
Fix the WordPress Unattached media filter. Automatically attach used media files to their posts so you can safely clean up your library.
PixRem – Unused Image Cleaner
pixrem
Find and delete unused images in your Media Library. Backup, restore, whitelist, and scan support for all major page builders.
Media Cleaner and Database Optimizer by ITPath
itpathsolutions-media-cleaner-and-database-optimizer
The most powerful tool for clearing unused media from your website and optimizing your database to boost site performance
MA Smart Image Cleaner
ma-smart-image-cleaner
Safely find and clean unused images in your WordPress Media Library without breaking your website.
Assetbroom – Unused Media & Duplicate Image Cleaner
assetbroom-media-cleaner
Detect unused images, duplicate media files, and safely clean your WordPress media library without breaking your website.
Oli Media Cleaner Developer Profile
3 plugins · 10 total installs
How We Detect Oli Media Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oli-media-cleaner/assets/css/admin.css/wp-content/plugins/oli-media-cleaner/assets/js/admin.jsoli-media-cleaner/assets/css/admin.css?ver=oli-media-cleaner/assets/js/admin.js?ver=HTML / DOM Fingerprints
olimc-statsolimc-scan-btnolimc-progress-wrapolimc-progress-fillolimc-progress-textolimc-unused-countdata-tabolimcObj/wp-json/olimc-api/v1/scan/wp-json/olimc-api/v1/results/wp-json/olimc-api/v1/trash/wp-json/olimc-api/v1/delete/wp-json/olimc-api/v1/whitelist/wp-json/olimc-api/v1/restore/wp-json/olimc-api/v1/cron