
SmartPro Database Optimiser & Cleaner Security & Risk Analysis
wordpress.org/plugins/smartpro-database-optimiser-cleanerSmart, lightweight tool to clean, optimize, and back up your WordPress database for better speed and performance.
Is SmartPro Database Optimiser & Cleaner Safe to Use in 2026?
Generally Safe
Score 100/100SmartPro Database Optimiser & Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smartpro-database-optimiser-cleaner" plugin v1.0 exhibits a generally positive security posture based on the static analysis. A significant strength is the absence of any recorded vulnerabilities (CVEs), which is a strong indicator of a well-maintained and secure codebase over time. The plugin also demonstrates good practices in its attack surface management, with all 8 AJAX handlers having authentication checks and no REST API routes or shortcodes exposed without permission callbacks. The absence of dangerous functions and external HTTP requests further contributes to its security.
However, there are areas for improvement. While the plugin uses prepared statements for a reasonable percentage of its SQL queries (35%), a substantial portion still relies on manual SQL construction, which could be a potential risk if sanitization is not consistently applied. Similarly, the output escaping is only properly handled in 62% of cases, leaving room for potential cross-site scripting (XSS) vulnerabilities if untrusted data is outputted without adequate sanitization. The presence of file operations without specific context also warrants caution, as improper handling of file I/O can lead to security issues.
In conclusion, the plugin appears to be relatively secure due to its lack of historical vulnerabilities and well-managed attack surface. The primary concerns stem from the potential risks associated with non-prepared SQL statements and incomplete output escaping. Addressing these areas would further strengthen its security posture and reduce the attack surface for common web vulnerabilities.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not properly handled
SmartPro Database Optimiser & Cleaner Security Vulnerabilities
SmartPro Database Optimiser & Cleaner Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SmartPro Database Optimiser & Cleaner Attack Surface
AJAX Handlers 8
WordPress Hooks 2
Maintenance & Trust
SmartPro Database Optimiser & Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
SmartPro Database Optimiser & Cleaner Alternatives
Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance
advanced-database-cleaner
Clean database by deleting orphaned data such as 'revisions', 'expired transients', optimize database and more...
Templ Optimizer
templ-optimizer
Optimize your site and improve its performance with a few clicks.
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
Database Cleaner
database-cleaner
User-friendly tool to clean and optimize databases. Efficiently manages large databases, simplifying repair and ensuring peak performance.
Autoload Checker
autoload-checker
Checks the autoloaded data size and lists the top autoloaded data entries sorted by size.
SmartPro Database Optimiser & Cleaner Developer Profile
13 plugins · 120 total installs
How We Detect SmartPro Database Optimiser & Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smartpro-database-optimiser-cleaner/assets/css/admin.css/wp-content/plugins/smartpro-database-optimiser-cleaner/assets/js/admin.js/wp-content/plugins/smartpro-database-optimiser-cleaner/assets/js/admin.jssmartpro-database-optimiser-cleaner/assets/css/admin.css?ver=smartpro-database-optimiser-cleaner/assets/js/admin.js?ver=HTML / DOM Fingerprints
addbc-wrapaddbc-versiondata-nonce="addbc_nonce"addbc_ajax