
Ultimate media cleaner Security & Risk Analysis
wordpress.org/plugins/ultimate-media-cleanerFind used medias from you from the database and/or your upload folder and give the way to delete them the ones "unused"
Is Ultimate media cleaner Safe to Use in 2026?
Generally Safe
Score 85/100Ultimate media cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "ultimate-media-cleaner" v2.6.1 reveals a plugin with a generally strong security foundation. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant positive. Furthermore, all observed SQL queries utilize prepared statements, a crucial practice for preventing SQL injection. The plugin also demonstrates a robust use of capability checks.
However, a critical concern arises from the "Output escaping" signal, indicating that 100% of observed outputs are not properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be injected and executed in the browser. The lack of taint analysis results is either due to the analysis tool's limitations or the plugin's code structure not presenting obvious taint flows, which doesn't negate the XSS risk highlighted by the unescaped output. The absence of any recorded vulnerabilities in its history is a positive trend but does not eliminate the risk of newly discovered or emerging threats.
In conclusion, while the plugin excels in preventing common web vulnerabilities like SQL injection and offers a minimal attack surface, the lack of output escaping is a serious flaw that requires immediate attention. This weakness significantly undermines the plugin's overall security posture and makes it susceptible to XSS attacks. Developers should prioritize implementing proper output escaping mechanisms to mitigate this risk.
Key Concerns
- Output escaping: 100% not properly escaped
Ultimate media cleaner Security Vulnerabilities
Ultimate media cleaner Code Analysis
SQL Query Safety
Output Escaping
Ultimate media cleaner Attack Surface
WordPress Hooks 8
Maintenance & Trust
Ultimate media cleaner Maintenance & Trust
Maintenance Signals
Community Trust
Ultimate media cleaner Alternatives
Media Cleaner: Clean your WordPress!
media-cleaner
Clean your WordPress! Eliminate unused and broken media files. For a faster, and better website.
Media Tracker
media-tracker
Media Tracker is a WordPress plugin to find and remove unused media files, manage duplicates, and optimize your media library for better performance.
Media Sweep – WordPress Media Cleaner
media-sweep
Clean up your WordPress Media Library by finding and removing unused files. Safely scan, preview, and sweep away orphaned media to keep your site fast …
Smart Bulk Delete & Content Cleaner for WordPress
smart-bulk-content-remover
Safely bulk delete posts, pages, media, and comments with flexible filters and a clean interface.
Unused Media Cleaner
unused-media-cleaner
Unused Media Cleaner scans your WordPress site to find and remove unused media files, freeing storage and improving site speed and performance.
Ultimate media cleaner Developer Profile
1 plugin · 300 total installs
How We Detect Ultimate media cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultimate-media-cleaner/js/runtime.js/wp-content/plugins/ultimate-media-cleaner/js/polyfills.js/wp-content/plugins/ultimate-media-cleaner/js/styles.css/wp-content/plugins/ultimate-media-cleaner/js/main.js/wp-content/plugins/ultimate-media-cleaner/js/runtime.js/wp-content/plugins/ultimate-media-cleaner/js/polyfills.js/wp-content/plugins/ultimate-media-cleaner/js/main.jsultimate-media-cleaner/js/runtime.js?ver=ultimate-media-cleaner/js/polyfills.js?ver=ultimate-media-cleaner/js/styles.css?ver=ultimate-media-cleaner/js/main.js?ver=HTML / DOM Fingerprints
nonce/wp-json/ultimate-media-cleaner/v1/attachments/count//wp-json/ultimate-media-cleaner/v1/attachments/directories/wp-json/ultimate-media-cleaner/v1/attachments/directory/files/wp-json/ultimate-media-cleaner/v1/attachments/directory/file/id/wp-json/ultimate-media-cleaner/v1/attachment/wp-json/ultimate-media-cleaner/v1/attachments/wp-json/ultimate-media-cleaner/v1/attachment/verify/wp-json/ultimate-media-cleaner/v1/attachment/delete/wp-json/ultimate-media-cleaner/v1/attachment/delete/child<umc-root