Media Usage Tracker Security & Risk Analysis
wordpress.org/plugins/oo-media-usage-trackerExtends the WordPress media library by adding an admin column showing where each image is used.
Is Media Usage Tracker Safe to Use in 2026?
Generally Safe
Score 100/100Media Usage Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "oo-media-usage-tracker" v1.0.0 plugin exhibits a mixed security posture. While the absence of known CVEs and a history of unpatched vulnerabilities is a positive sign, the static analysis reveals several concerning areas. A significant portion of the attack surface, specifically all three identified AJAX handlers, lack proper authentication checks. This presents a substantial risk, as unauthorized users could potentially trigger these functions, leading to unintended actions or information disclosure.
The code also signals potential risks with the presence of the `unserialize` function, which can be dangerous if used with untrusted input. Although taint analysis found no critical or high-severity issues, this function warrants careful scrutiny. The moderate use of prepared statements for SQL queries is good, but 60% is still a substantial amount that might be vulnerable if input is not properly sanitized before being used in raw queries. The 75% output escaping is also decent, but it implies that 25% of outputs are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities.
Overall, the plugin has strengths in its lack of historical vulnerabilities and some good practices like nonces and capability checks for certain entry points. However, the unauthenticated AJAX handlers and the use of `unserialize` are critical weaknesses that significantly elevate the risk profile. Future development should prioritize securing these entry points and carefully reviewing the usage of dangerous functions.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function (unserialize) present
- SQL queries not using prepared statements
- Outputs not properly escaped
Media Usage Tracker Security Vulnerabilities
Media Usage Tracker Release Timeline
Media Usage Tracker Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Media Usage Tracker Attack Surface
AJAX Handlers 3
WordPress Hooks 8
Scheduled Events 5
Maintenance & Trust
Media Usage Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Media Usage Tracker Alternatives
Alter Media – Image Alt Tag and Caption Detector
alter-media
Enhance your WordPress media library with powerful filtering and management tools for image alt text and captions.
Media Export & Clean
media-export-clean
Export your entire WordPress Media Library to a ZIP file and safely clean unused files from your uploads directory.
Mediapapa – Your WordPress Media Library Manager & Copilot
mediapapa
WordPress media library manager: track usage, find duplicates, remove unused files, fix metadata and optimize images. Free.
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Media Usage Tracker Developer Profile
1 plugin · 10 total installs
How We Detect Media Usage Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oo-media-usage-tracker/css/style.css/wp-content/plugins/oo-media-usage-tracker/js/oo-media-usage-tracker.jsoo-media-usage-tracker/css/style.css?ver=oo-media-usage-tracker/js/oo-media-usage-tracker.js?ver=