
Smart Bulk Delete & Content Cleaner for WordPress Security & Risk Analysis
wordpress.org/plugins/smart-bulk-content-removerSafely bulk delete posts, pages, media, and comments with flexible filters and a clean interface.
Is Smart Bulk Delete & Content Cleaner for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Smart Bulk Delete & Content Cleaner for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smart-bulk-content-remover" v1.1 plugin exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and the taint analysis shows no critical or high severity issues with unsanitized paths. The code also demonstrates good practices with a high percentage of SQL queries using prepared statements and a good rate of output escaping.
However, a significant concern arises from the large attack surface exposed through AJAX handlers, with a substantial number (9 out of 34) lacking authentication checks. This presents a direct entry point for potential attackers to trigger plugin functionality without proper authorization. While no dangerous functions were identified and no external HTTP requests are made, the lack of robust authentication on several AJAX endpoints is a notable weakness that could be exploited if the functionality they trigger is sensitive.
Given the absence of historical vulnerabilities, it suggests that the plugin may have been developed with security in mind, but the identified unprotected AJAX handlers represent a tangible risk that needs immediate attention. The plugin's strengths lie in its use of prepared statements and output escaping, but these are undermined by the easily accessible unprotected entry points.
Key Concerns
- Unprotected AJAX handlers
Smart Bulk Delete & Content Cleaner for WordPress Security Vulnerabilities
Smart Bulk Delete & Content Cleaner for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Smart Bulk Delete & Content Cleaner for WordPress Attack Surface
AJAX Handlers 34
WordPress Hooks 5
Scheduled Events 1
Maintenance & Trust
Smart Bulk Delete & Content Cleaner for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Smart Bulk Delete & Content Cleaner for WordPress Alternatives
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Delete Posts automatically
delete-old-posts-programmatically
The Delete Posts Automatically plugin keeps your website clean by programmatically deleting posts using a wide range of powerful filters.
Delete Posts By URL
delete-posts-by-url
Advanced bulk deletion of WordPress posts with multiple filtering options and powerful features for content management.
Bulk Clean
easy-clean
Bulk clean allow you to delete unwanted posts, pages, custom post etc with a single click.
Smart Bulk Delete & Content Cleaner for WordPress Developer Profile
13 plugins · 120 total installs
How We Detect Smart Bulk Delete & Content Cleaner for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-bulk-content-remover/assets/js/jquery.validate.min.js/wp-content/plugins/smart-bulk-content-remover/assets/js/custom.js/wp-content/plugins/smart-bulk-content-remover/assets/css/custom.csswp-content/plugins/smart-bulk-content-remover/assets/js/jquery.validate.min.jswp-content/plugins/smart-bulk-content-remover/assets/js/custom.jssmart-bulk-content-remover/assets/js/jquery.validate.min.js?ver=smart-bulk-content-remover/assets/js/custom.js?ver=smart-bulk-content-remover/assets/css/custom.css?ver=HTML / DOM Fingerprints
abdfw_ajax_object