
Unused Media Checker Security & Risk Analysis
wordpress.org/plugins/unused-media-checkerIdentify, inspect and delete unused media files in your media library, including integrations for Advanced Ads and Photo Gallery (10Web).
Is Unused Media Checker Safe to Use in 2026?
Generally Safe
Score 100/100Unused Media Checker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The unused-media-checker plugin v1.3.7 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, external HTTP requests, and a very high percentage of SQL queries utilizing prepared statements are all positive indicators. Furthermore, the plugin includes a respectable number of nonce and capability checks, suggesting an effort to protect its functionalities. The lack of any recorded vulnerabilities, including critical or high severity issues, and no previously unpatched CVEs, further reinforces this positive assessment, implying a mature and well-maintained codebase.
However, the static analysis does highlight areas for potential concern. While the attack surface is zero, meaning no direct entry points were detected, the analysis of output escaping shows that only 70% of outputs are properly escaped. This leaves room for potential cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient sanitization in the remaining 30% of outputs. The taint analysis revealing zero flows with unsanitized paths is a positive sign, but it's crucial to remember that taint analysis is not always exhaustive. The low number of nonce and capability checks, while present, could be expanded to cover more areas of the plugin's functionality for enhanced security.
In conclusion, unused-media-checker v1.3.7 appears to be a relatively secure plugin with a history of no known vulnerabilities and good coding practices in place, particularly regarding SQL query preparation. The primary area for improvement lies in ensuring all outputs are consistently and properly escaped to mitigate potential XSS risks. The overall security is good, but attention to output sanitization would strengthen it further.
Key Concerns
- Output escaping is not consistently proper
Unused Media Checker Security Vulnerabilities
Unused Media Checker Code Analysis
SQL Query Safety
Output Escaping
Unused Media Checker Attack Surface
WordPress Hooks 17
Maintenance & Trust
Unused Media Checker Maintenance & Trust
Maintenance Signals
Community Trust
Unused Media Checker Alternatives
Media Gallery Cleaner
media-gallery-cleaner
Scans your website and identifies unused media files for cleanup.
Quick Media Inspect
quick-media-inspect
Detect unused images across your entire WordPress site, clean up your Media Library safely, and generate alt text from filenames.
Thumbnail Remover and Size Manager
thumbnail-remover
Safely analyze, preview, trash, restore, regenerate, and manage WordPress thumbnails and image sizes.
Media Wipe
media-wipe
AI-powered WordPress media management with intelligent unused media detection and enterprise security. Transform your cleanup workflow!
Media Sifter
media-sifter
Find and remove unused/orphan media files safely. Dry-run scan, preview, and bulk-delete to reclaim storage.
Unused Media Checker Developer Profile
1 plugin · 100 total installs
How We Detect Unused Media Checker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unused-media-checker/assets/css/admin.css/wp-content/plugins/unused-media-checker/assets/js/admin.js/wp-content/plugins/unused-media-checker/assets/js/admin.jsunused-media-checker/assets/css/admin.css?ver=unused-media-checker/assets/js/admin.js?ver=HTML / DOM Fingerprints
umc-noticeumc-settings-pageumc-scan-resultsumc-scan-detailsumc-help-modalumc-media-thumbnailumc-media-titleumc-media-used-in<!-- BEGIN UMC: Advanced Ads Integration --><!-- END UMC: Advanced Ads Integration --><!-- BEGIN UMC: Photo Gallery (10Web) Integration --><!-- END UMC: Photo Gallery (10Web) Integration -->+8 moredata-umc-media-iddata-umc-delete-noncedata-umc-actionUMCAdmin