
Orphanix Media Cleanup Security & Risk Analysis
wordpress.org/plugins/orphanix-media-cleanupSmart WordPress media library cleanup. Detect unused, orphaned & broken media safely with advanced live scanning.
Is Orphanix Media Cleanup Safe to Use in 2026?
Generally Safe
Score 100/100Orphanix Media Cleanup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The orphanix-media-cleanup v1.0.0 plugin demonstrates a generally strong security posture, with several positive indicators. The complete absence of raw SQL queries and the strict adherence to output escaping for all outputs are commendable practices that significantly reduce common attack vectors like SQL injection and cross-site scripting. Furthermore, the presence of numerous nonce and capability checks on its AJAX handlers, coupled with no direct entry points lacking authentication, suggests a good understanding of WordPress security principles. The plugin also has no recorded vulnerability history, indicating past stability and developer diligence.
However, the taint analysis reveals a notable concern: 10 out of 18 analyzed flows involve unsanitized paths, with 6 of these being of high severity. This indicates a potential for path traversal or arbitrary file access vulnerabilities, even if they haven't manifested as exploitable issues yet. While the static analysis didn't directly flag file operations as malicious or unescaped, the presence of unsanitized paths in taint flows is a significant red flag that requires further investigation. The existence of 4 external HTTP requests, while not inherently problematic, also warrants attention to ensure these requests are made securely and are not susceptible to man-in-the-middle attacks or other network-based threats.
In conclusion, orphanix-media-cleanup v1.0.0 has a solid foundation in secure coding practices, particularly in data handling and output sanitization. The lack of known CVEs further bolsters confidence. The primary area of concern lies within the taint analysis related to unsanitized paths, which presents a potential risk that should be addressed to achieve a truly robust security profile. Addressing these taint flow issues would elevate the plugin's security from good to excellent.
Key Concerns
- High severity taint flows with unsanitized paths
- Unsanitized paths in taint analysis (10 flows)
Orphanix Media Cleanup Security Vulnerabilities
Orphanix Media Cleanup Release Timeline
Orphanix Media Cleanup Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Orphanix Media Cleanup Attack Surface
AJAX Handlers 12
WordPress Hooks 6
Scheduled Events 1
Maintenance & Trust
Orphanix Media Cleanup Maintenance & Trust
Maintenance Signals
Community Trust
Orphanix Media Cleanup Alternatives
Remove Broken Images
remove-broken-images
Very simply, uses JavaScript to remove broken images from page display.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Media Library Assistant
media-library-assistant
Enhances the Media Library; powerful gallery and list shortcodes, full taxonomy support, IPTC/EXIF/XMP/PDF processing, bulk/quick edit.
Quick Featured Images
quick-featured-images
The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.
Crop-Thumbnails
crop-thumbnails
"Crop Thumbnails" made it easy to get exacly that specific image-detail you want to show in your featured image or gallery image.
Orphanix Media Cleanup Developer Profile
2 plugins · 10 total installs
How We Detect Orphanix Media Cleanup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orphanix-media-cleanup/assets/css/admin.css/wp-content/plugins/orphanix-media-cleanup/assets/js/admin.jsadmin.jsorphanix-media-cleanup/assets/css/admin.css?ver=orphanix-media-cleanup/assets/js/admin.js?ver=