
WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts Security & Risk Analysis
wordpress.org/plugins/wpsqr-site-cleanerSite Cleaner instantly finds and removes duplicate posts, pages, and custom post types to free up database space, boost site speed.
Is WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts Safe to Use in 2026?
Generally Safe
Score 100/100WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpsqr-site-cleaner" plugin version 1.0.2 exhibits a concerning security posture primarily due to a large number of unprotected AJAX endpoints. With 9 AJAX handlers and none of them featuring authentication or capability checks, any unauthenticated user could potentially trigger these actions, presenting a significant attack surface. While the code signals indicate a lack of dangerous functions, file operations, and external HTTP requests, the absence of proper authorization on these entry points is a critical weakness.
The plugin's SQL query practices are moderately secure, with 73% using prepared statements, but the remaining 27% could be susceptible to SQL injection if not handled carefully. Similarly, output escaping is not consistently applied, with only 67% of outputs properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities. The single nonce check is a positive sign, but its effectiveness is diminished by the lack of broader authorization on the AJAX handlers it might protect.
The vulnerability history being entirely clear, with zero known CVEs, is a strong positive indicator. This suggests that the plugin has either not been a target for vulnerability discovery or has historically been well-maintained. However, the current code analysis reveals significant weaknesses that could be exploited regardless of past history. In conclusion, while the lack of historical vulnerabilities is encouraging, the current state of the plugin, particularly its unprotected AJAX endpoints and inconsistent output escaping, poses a high risk that needs immediate attention.
Key Concerns
- Unprotected AJAX endpoints
- Inconsistent output escaping
- SQL queries without prepared statements
WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts Security Vulnerabilities
WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts Code Analysis
SQL Query Safety
Output Escaping
WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts Attack Surface
AJAX Handlers 9
WordPress Hooks 7
Maintenance & Trust
WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts Maintenance & Trust
Maintenance Signals
Community Trust
WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts Alternatives
Product Redirection for WooCommerce
product-redirection-for-woocommerce
Instead of deleting products which is bad for SEO, redirect them to their parent category or a custom url.
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
seo-by-rank-math
Rank Math SEO is the best WordPress SEO plugin with the features of many SEO and AI SEO tools in a single package to help multiply your SEO traffic.
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1-click: compress images, convert to WebP & AVIF, resize, and boost your site with the easiest WordPress image optimization plugin!
Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN
wp-smushit
Optimize and compress images with lossless and lossy compression, lazy load, WebP & AVIF conversion, and global image CDN.
WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts Developer Profile
6 plugins · 430 total installs
How We Detect WPSQR Site Cleaner – Optimize WordPress by Removing Duplicate Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpsqr-site-cleaner/inc/assets/icons/icon-style.css/wp-content/plugins/wpsqr-site-cleaner/inc/assets/css/style.css/wp-content/plugins/wpsqr-site-cleaner/inc/assets/css/slimselect.css/wp-content/plugins/wpsqr-site-cleaner/inc/assets/js/script.js/wp-content/plugins/wpsqr-site-cleaner/inc/assets/js/slimselect.min.js/wp-content/plugins/wpsqr-site-cleaner/inc/assets/js/script.js/wp-content/plugins/wpsqr-site-cleaner/inc/assets/js/slimselect.min.jswpsqr-site-cleaner/inc/assets/icons/icon-style.css?ver=wpsqr-site-cleaner/inc/assets/css/style.css?ver=wpsqr-site-cleaner/inc/assets/css/slimselect.css?ver=wpsqr-site-cleaner/inc/assets/js/script.js?ver=wpsqr-site-cleaner/inc/assets/js/slimselect.min.js?ver=HTML / DOM Fingerprints
wpsqsicl__page__configrationwpsqsicl_ajax_object