
WPS Cleaner Security & Risk Analysis
wordpress.org/plugins/wps-cleanerWPS Cleaner cleans your WordPress site as well as your database.
Is WPS Cleaner Safe to Use in 2026?
Generally Safe
Score 99/100WPS Cleaner has a strong security track record. Known vulnerabilities have been patched promptly.
The wps-cleaner plugin version 1.6.10.2 presents a mixed security posture. While it shows strengths such as a high percentage of SQL queries using prepared statements and a good number of nonce and capability checks, significant concerns remain. The presence of an unprotected AJAX handler represents a direct entry point for potential attacks that bypass authentication, which is a critical flaw. Furthermore, the taint analysis revealed a flow with unsanitized paths, indicating a risk of path traversal or similar vulnerabilities, even though it was not classified as critical or high. The plugin's vulnerability history, with two known medium-severity CVEs in the past related to authorization bypass and missing authorization, reinforces the concern about input validation and access control. While the lack of currently unpatched vulnerabilities is positive, the past issues suggest a pattern that warrants caution.
Key Concerns
- Unprotected AJAX handler (1 found)
- Flow with unsanitized paths (taint analysis)
- Lower percentage of properly escaped output (46%)
- 2 Medium severity CVEs in history
WPS Cleaner Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WPS Cleaner <= 1.4.4 - Arbitrary Media File Disclosure
WPS Cleaner <= 1.4.4 - Missing Authorization Checks
WPS Cleaner Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPS Cleaner Attack Surface
AJAX Handlers 38
WordPress Hooks 33
Scheduled Events 2
Maintenance & Trust
WPS Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
WPS Cleaner Alternatives
Brozzme DB Prefix & Tools Addons
brozzme-db-prefix-change
Easily change your WordPress DB prefix, save time, increase security.
The Hack Repair Guy's Plugin Archiver
hackrepair-plugin-archiver
Disable Plugins Without Deleting — Archive and Restore in One Click
Keep Backup Daily
keep-backup-daily
Keep Backup Daily backup your wordpress database and email to you daily, weekly, monthly and even yearly according to the settings.
WP Essentials
wp-essentials
All-in-one bundle of essential plugins and functions for all WordPress websites.
Brozzme Change Username
brozzme-change-username
Easily change a WordPress Username, save time, increase security.
WPS Cleaner Developer Profile
9 plugins · 149K total installs
How We Detect WPS Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wps-cleaner/assets/css/main.css/wp-content/plugins/wps-cleaner/assets/css/wps-cleaner.css/wp-content/plugins/wps-cleaner/assets/js/main.js/wp-content/plugins/wps-cleaner/assets/js/wps-cleaner.js/wp-content/plugins/wps-cleaner/assets/js/main.js/wp-content/plugins/wps-cleaner/assets/js/wps-cleaner.jswps-cleaner/assets/css/main.css?ver=wps-cleaner/assets/css/wps-cleaner.css?ver=wps-cleaner/assets/js/main.js?ver=wps-cleaner/assets/js/wps-cleaner.js?ver=HTML / DOM Fingerprints
wps_cleaner_wrapperwps_cleaner_contentwps-cleaner-notice<!-- WPS Cleaner by WPServeur -->data-wps_cleaner_noncewpsCleanerAjax