
Used Media Identifier Security & Risk Analysis
wordpress.org/plugins/used-media-identifierHere is a short description of the plugin. This should be no more than 150 characters. No markup here.
Is Used Media Identifier Safe to Use in 2026?
Generally Safe
Score 85/100Used Media Identifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'used-media-identifier' v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no known vulnerabilities (CVEs) and zero identified dangerous functions. The absence of external HTTP requests and the use of prepared statements for all SQL queries are also significant strengths, indicating a conscious effort to avoid common web attack vectors. However, several areas raise concerns. The limited attack surface is notable, but the complete lack of nonce and capability checks across any entry points is a significant weakness, leaving potential avenues for exploitation if any such points were to be introduced or discovered later. Furthermore, the low percentage of properly escaped output (48%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is involved in these unescaped outputs. The taint analysis revealing flows with unsanitized paths, although not classified as critical or high severity, warrants attention as it points to potential issues with handling file paths. The vulnerability history, while currently clean, could be misleading if the plugin has not been extensively tested or if this is its first release, and therefore its long-term security track record is unproven.
Overall, while the plugin appears to have a solid foundation by avoiding known dangerous practices like raw SQL and external requests, the lack of input validation and output escaping is a notable risk. The unsanitized paths in the taint analysis, coupled with the low output escaping rate, are the most concrete technical risks identified. The complete absence of nonces and capability checks presents a structural weakness that could become critical if the plugin evolves or if new entry points are added without proper security considerations. Given the current state, the primary risks revolve around potential XSS and file manipulation vulnerabilities stemming from inadequate sanitization and escaping.
Key Concerns
- Low proper output escaping rate (48%)
- Taint analysis: Unsantized paths found
- No nonce checks on any entry points
- No capability checks on any entry points
Used Media Identifier Security Vulnerabilities
Used Media Identifier Code Analysis
Output Escaping
Data Flow Analysis
Used Media Identifier Attack Surface
WordPress Hooks 13
Maintenance & Trust
Used Media Identifier Maintenance & Trust
Maintenance Signals
Community Trust
Used Media Identifier Alternatives
Rename Media
rename-media
Rename underlying media files from the WordPress media management interface
Social Media Icons WP – Add Custom Social Icons & Links with Shortcode
social-media-icons-wp
Add social media icons using Font Awesome or custom images. Easily sort, style, and display icons anywhere via shortcode.
Thumbnail Remover and Size Manager
thumbnail-remover
Safely analyze, preview, trash, restore, regenerate, and manage WordPress thumbnails and image sizes.
PixRem – Unused Image Cleaner
pixrem
Find and delete unused images in your Media Library. Backup, restore, whitelist, and scan support for all major page builders.
AMW Clear Upload Folder
amw-clear-upload-folder
Removes unused files from the 'uploads' folder
Used Media Identifier Developer Profile
1 plugin · 10 total installs
How We Detect Used Media Identifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/used-media-identifier/css/used-media-identifier-admin.css/wp-content/plugins/used-media-identifier/js/used-media-identifier-admin.js/wp-content/plugins/used-media-identifier/js/used-media-identifier-admin.jsused-media-identifier-admin.css?ver=used-media-identifier-admin.js?ver=HTML / DOM Fingerprints
media-modalis_badgedateymdwindow.used_media_identifier_admin