{"id":347232,"date":"2026-08-01T07:46:48","date_gmt":"2026-08-01T07:46:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/safe-media\/"},"modified":"2026-08-01T07:46:27","modified_gmt":"2026-08-01T07:46:27","slug":"mediaref-cleanup-auditor","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/mediaref-cleanup-auditor\/","author":15411242,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.2","stable_tag":"1.2.2","tested":"7.0.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"MediaRef Cleanup Auditor","header_author":"Chintan Acharya","header_description":"Free, open-source, resumable media analysis and safety-first cleanup for WordPress.","assets_banners_color":"2e59ae","last_updated":"2026-08-01 07:46:27","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/profiles.wordpress.org\/chintan238\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":36,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.2":{"tag":"1.2.2","author":"chintan238","date":"2026-08-01 07:46:27"}},"upgrade_notice":{"1.2.2":"<p>Speeds up large-library scans with bulk inventory writes, batched matching, indexed cursors, and reusable fingerprints.<\/p>","1.2.1":"<p>Adds storage analysis and durable, usage-aware cleanup jobs with reversible quarantine.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3630707,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3630707,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3630707,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3630707,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3630707,"resolution":"1","location":"assets","locale":"","width":1440,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3630707,"resolution":"2","location":"assets","locale":"","width":1440,"height":900},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3630707,"resolution":"3","location":"assets","locale":"","width":1440,"height":900},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3630707,"resolution":"4","location":"assets","locale":"","width":1440,"height":900},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3630707,"resolution":"5","location":"assets","locale":"","width":1440,"height":900}},"screenshots":{"1":"Overview and capability report with durable scan controls and current job progress.","2":"Storage Explorer for upload-year, file-type, generated-size, and large-image analysis.","3":"Results review with references, confidence language, protection, and cleanup actions.","4":"Exact duplicate groups with usage-aware keep recommendations.","5":"Quarantine manager with restoration records and explicit permanent-delete controls."}},"plugin_section":[],"plugin_tags":[1346,238093,227565,2956,219749],"plugin_category":[50],"plugin_contributors":[168289],"plugin_business_model":[],"class_list":["post-347232","plugin","type-plugin","status-publish","hentry","plugin_tags-attachments","plugin_tags-duplicate-images","plugin_tags-media-cleaner","plugin_tags-thumbnails","plugin_tags-unused-media","plugin_category-media","plugin_contributors-chintan238","plugin_committers-chintan238"],"banners":{"banner":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/banner-772x250.png?rev=3630707","banner_2x":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/banner-1544x500.png?rev=3630707","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/icon-128x128.png?rev=3630707","icon_2x":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/icon-256x256.png?rev=3630707","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/screenshot-1.png?rev=3630707","caption":"Overview and capability report with durable scan controls and current job progress."},{"src":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/screenshot-2.png?rev=3630707","caption":"Storage Explorer for upload-year, file-type, generated-size, and large-image analysis."},{"src":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/screenshot-3.png?rev=3630707","caption":"Results review with references, confidence language, protection, and cleanup actions."},{"src":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/screenshot-4.png?rev=3630707","caption":"Exact duplicate groups with usage-aware keep recommendations."},{"src":"https:\/\/ps.w.org\/mediaref-cleanup-auditor\/assets\/screenshot-5.png?rev=3630707","caption":"Quarantine manager with restoration records and explicit permanent-delete controls."}],"raw_content":"<!--section=description-->\n<p>MediaRef Cleanup Auditor analyses attachment records, content, metadata, and the uploads filesystem using durable,\nbounded jobs. It includes exact duplicate hashing, thumbnail analysis, optional live verification,\nquarantine and restoration, builder and plugin capability reporting, REST workers, and WP-CLI.<\/p>\n\n<p>There is no paid edition, scan limit, license server, advertising gate or required external service.\nAll processing occurs on the WordPress installation. Donations may support development but do not\nchange functionality.<\/p>\n\n<p>Safety language is deliberate: \u201cNo reference detected\u201d is not proof that an item is unused.\nDynamic code, remote consumers and unsupported data stores can create blind spots. Every cleanup\nattempt performs a fresh targeted reference check and verifies file identity.<\/p>\n\n<h4>Built for large and old media libraries<\/h4>\n\n<p>Scans use database-backed jobs, keyset cursors, adaptive bounded batches, staged publishing, and\nexpiring worker locks. A browser refresh does not erase progress, and the same job can be resumed\nwith WP-CLI. The Storage Explorer groups files by year, month, MIME type, attachment ownership, and\nderivative type, making sites with upload folders spanning many years easier to review.<\/p>\n\n<h4>Included without feature locks<\/h4>\n\n<ul>\n<li>Media Library, metadata, options, builder, and filesystem reference analysis.<\/li>\n<li>Durable uploads manifest with missing, unknown, generated, and orphan-file classification.<\/li>\n<li>Exact duplicate groups using file size, MIME type, and SHA-256 fingerprints.<\/li>\n<li>Thumbnail inventory, missing-size analysis, selective cleanup review, and reporting.<\/li>\n<li>Optional same-origin live-page verification, disabled by default.<\/li>\n<li>Storage Explorer and Large Image Analyzer with date, folder, dimension, and size filters.<\/li>\n<li>Protected and ignored media states.<\/li>\n<li>Identity-checked private quarantine, restoration, and separate permanent deletion.<\/li>\n<li>REST dashboard workers and the complete <code>wp mediaref-cleanup-auditor<\/code> WP-CLI command set.<\/li>\n<li>Individual scanner classes for supported builders, galleries, commerce, LMS, membership,\nmultilingual, cache, and custom-field ecosystems.<\/li>\n<\/ul>\n\n<p>There is no Pro edition, image limit, scan limit, remote license validation, or required account.<\/p>\n\n<h3>WP-CLI<\/h3>\n\n<p>Common commands:<\/p>\n\n<pre><code>wp mediaref-cleanup-auditor status\nwp mediaref-cleanup-auditor capabilities --format=json\nwp mediaref-cleanup-auditor scan library --batch-size=250\nwp mediaref-cleanup-auditor scan filesystem\nwp mediaref-cleanup-auditor scan duplicates\nwp mediaref-cleanup-auditor scan thumbnails\nwp mediaref-cleanup-auditor scan live\nwp mediaref-cleanup-auditor scan all\nwp mediaref-cleanup-auditor scan resume --job=123 --batch-size=500\nwp mediaref-cleanup-auditor results --status=potentially_unused --format=csv\nwp mediaref-cleanup-auditor references 1250\nwp mediaref-cleanup-auditor explain 1250\nwp mediaref-cleanup-auditor protect 1250\nwp mediaref-cleanup-auditor unprotect 1250\nwp mediaref-cleanup-auditor ignore 1250\nwp mediaref-cleanup-auditor unignore 1250\nwp mediaref-cleanup-auditor trash 1250 --dry-run\nwp mediaref-cleanup-auditor restore 10\nwp mediaref-cleanup-auditor delete 10 --yes\nwp mediaref-cleanup-auditor empty-trash --older-than=30 --yes\nwp mediaref-cleanup-auditor export --status=potentially_unused --format=csv\nwp mediaref-cleanup-auditor verify 1250\nwp mediaref-cleanup-auditor repair\nwp mediaref-cleanup-auditor cleanup-jobs\n<\/code><\/pre>\n\n<p>Machine-readable result commands support table, JSON, CSV and count formats through WP-CLI.<\/p>\n\n<h3>Security<\/h3>\n\n<p>Live verification is off by default. It accepts only the current site host, resolves and rejects\nprivate\/reserved IPs, validates every redirect, sends no cookies, limits redirects, response bytes\nand time, and parses returned text without executing scripts or submitting forms.<\/p>\n\n<p>Quarantine paths are exact, contained within uploads, and never selected through wildcard matching.\nRemote objects are never deleted by the bundled local storage adapter.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>MediaRef Cleanup Auditor stores scan jobs, cursors, normalized media references, file-manifest data, results,\noperation logs, and quarantine records in this WordPress database. This operational data is used\nonly to perform and audit media analysis and cleanup.<\/p>\n\n<p>The plugin does not send telemetry or site data to the author. Optional live verification makes\nunauthenticated requests only to approved URLs belonging to the current site. It does not execute\nscripts, submit forms, or send administrator cookies.<\/p>\n\n<h3>Support<\/h3>\n\n<p>For support, use the MediaRef Cleanup Auditor support forum on WordPress.org after the plugin is approved.\nBefore reporting a problem, include the WordPress and PHP versions, scan type, job ID, current\nstage, and the sanitized error shown in MediaRef Cleanup Auditor. Never post private server paths or credentials.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>mediaref-cleanup-auditor<\/code> directory to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate MediaRef Cleanup Auditor.<\/li>\n<li>Open Tools \u2192 MediaRef Cleanup Auditor.<\/li>\n<li>Review the capability report before starting a scan.<\/li>\n<li>Back up the site before cleanup, then use quarantine before permanent deletion.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20every%20feature%20free%3F\"><h3>Is every feature free?<\/h3><\/dt>\n<dd><p>Yes. Library and filesystem scans, parsers, duplicate hashing, thumbnail analysis, live verification,\nWP-CLI, quarantine, restoration and export are available without payment or an external connection.<\/p><\/dd>\n<dt id=\"can%20a%20scan%20survive%20a%20closed%20browser%20or%20ssh%20disconnect%3F\"><h3>Can a scan survive a closed browser or SSH disconnect?<\/h3><\/dt>\n<dd><p>Yes. Jobs, locks, stage cursors and staged results are stored in database tables. Resume browser jobs\nwith <code>wp mediaref-cleanup-auditor scan resume --job=&lt;id&gt;<\/code>.<\/p><\/dd>\n<dt id=\"does%20%E2%80%9Cpotentially%20unused%E2%80%9D%20mean%20safe%20to%20delete%3F\"><h3>Does \u201cpotentially unused\u201d mean safe to delete?<\/h3><\/dt>\n<dd><p>No. It means enabled scanners detected no reference. Review blind spots and run the mandatory fresh\nrecheck. Quarantine is reversible; permanent deletion is separate and explicitly confirmed.<\/p><\/dd>\n<dt id=\"does%20it%20support%20multisite%3F\"><h3>Does it support multisite?<\/h3><\/dt>\n<dd><p>Rows are scoped by blog ID and commands respect WP-CLI <code>--url<\/code>. Run and report scans per site.<\/p><\/dd>\n<dt id=\"will%20mediaref%20cleanup%20auditor%20delete%20files%20automatically%20after%20a%20scan%3F\"><h3>Will MediaRef Cleanup Auditor delete files automatically after a scan?<\/h3><\/dt>\n<dd><p>No. Scanning never deletes media. Cleanup is a separate, auditable job. Each item receives a fresh\nusage recheck and file-identity validation before it can be moved to private quarantine. Permanent\ndeletion is another explicit action.<\/p><\/dd>\n<dt id=\"does%20mediaref%20cleanup%20auditor%20contact%20an%20external%20service%3F\"><h3>Does MediaRef Cleanup Auditor contact an external service?<\/h3><\/dt>\n<dd><p>No. The plugin does not require an external service, account, telemetry endpoint, or license server.\nOptional live verification requests only approved URLs on the current site and is disabled by default.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Added bulk filesystem manifest writes and larger adaptive browser batches.<\/li>\n<li>Added cursor indexes for large staged runs.<\/li>\n<li>Reused unchanged duplicate fingerprints from the previous published scan.<\/li>\n<li>Replaced per-file matching and thumbnail queries with joined batch operations.<\/li>\n<li>Deferred expensive image probing and populated dimensions from metadata and derivative filenames.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Added cleanup candidates with age, status, folder, MIME and size filtering.<\/li>\n<li>Added exact duplicate groups with usage-aware keep recommendations.<\/li>\n<li>Added durable dry-run and quarantine jobs with one-item fresh rechecks.<\/li>\n<li>Added a quarantine manager with restoration and confirmed permanent deletion.<\/li>\n<li>Added browser-to-WP-CLI cleanup job continuity.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added a Storage Explorer with year\/month, MIME, original, generated and unmapped totals.<\/li>\n<li>Added a paginated Large Image Analyzer with folder, byte-size and dimension filters.<\/li>\n<li>Added bounded image-dimension probing during filesystem scans.<\/li>\n<li>Added conservative optimization-saving estimates without modifying files.<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>Added WordPress-bundled jQuery for delegated actions and smooth transitions.<\/li>\n<li>Replaced the result notice with a detailed reference dialog.<\/li>\n<li>Added working protect and unprotect actions from the result dialog.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Prevented incomplete job data from rendering immediately after starting a scan.<\/li>\n<li>Kept scan-type controls stable and disabled during job creation.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Rebuilt the administration application in dependency-free vanilla JavaScript.<\/li>\n<li>Added delegated events, cached DOM access, targeted scan updates, and GPU-friendly transitions.<\/li>\n<li>Removed the React and WordPress Components runtime from the admin screen.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Replaced the generic REST parser with an explicit same-origin JSON client.<\/li>\n<li>Improved REST error reporting and environment recommendations.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Rebuilt the administration interface with the native WordPress Components library.<\/li>\n<li>Added a professional overview, scan monitor, results table, environment report, and parser coverage view.<\/li>\n<li>Added responsive, accessible interaction and visual states without external UI services.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fixed scan cursors repeatedly restarting a stage instead of advancing.<\/li>\n<li>Added a no-progress guard and clearer processed-row wording.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Durable staged scan engine and REST\/CLI workers.<\/li>\n<li>Library, metadata, filesystem, duplicate, thumbnail and live scanners.<\/li>\n<li>Capability and parser blind-spot reporting.<\/li>\n<li>Identity-verified quarantine, restoration and permanent deletion.<\/li>\n<\/ul>","raw_excerpt":"Find media references, filesystem orphans, duplicate files, and unused thumbnails with resumable safety-first scans.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/347232","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=347232"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/chintan238"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=347232"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=347232"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=347232"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=347232"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=347232"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=347232"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}