

Overview: view Media Library and Disk Storage cleanup opportunities, storage totals, and scan actions.
DevDome Safe Media Cleaner is a WordPress media cleaner and image cleaner that finds unused images, orphan files, and missing media in your Media Library and uploads folder. Review the results, move selected files to a protected Recycle Bin, and check your site before restoring files or permanently deleting them.
Scan your Media Library for images with no detected reference on your website. The scanner checks common WordPress content and settings before marking an image as unused.
A disk scan finds orphan images and files in the uploads folder that have no matching Media Library record. These can accumulate after migrations, deleted plugins, failed uploads, manual file transfers, or years of website changes.
Review orphan media individually or in bulk. The disk scan covers images, including thumbnails left behind by deleted images; other file types are left alone.
Image cleanup starts with a review, followed by a move to the Recycle Bin. You choose when to delete unused images permanently.
The plugin includes these safeguards: The media recycle bin lets you restore cleaned files to their original locations.
No scanner can detect every custom or hard-coded image reference. Review the results and check your website while the cleaned files can still be restored.
Use the plugin for media-library maintenance when you need to clean up images and review storage use.
Nothing is removed until you review the results and choose what to clean. Scheduled scans do not automatically delete media.
The plugin provides a media manager for cleanup review, with a visual grid or list of scan results.
You can:
Sort unused images and orphan files by size to find those consuming the most disk space. The dashboard shows the storage represented by flagged files.
To bulk delete images, review your selection, move it to the Recycle Bin, and confirm permanent deletion after checking your site. The same review-first process applies when you bulk delete media identified by the scanner.
The scanner checks these common reference locations:
srcset, responsive images, and lazy-loading attributes.Generated thumbnail sizes, scaled images, and edited copies are matched to their original Media Library attachment.
The scanner checks data used by these WordPress tools:
Media libraries can contain thousands of images. Scans run in small, resumable background batches to reduce memory usage and timeout risk. Pause and resume a scan without starting over.
Scans, cleanups, backups, and restores run on the server and continue after you close the tab. Reopen the plugin page to see progress.
On WordPress multisite, each site keeps its own scans, Recycle Bin, backups, and settings.
These features are free and unlimited:
Settings include scheduled scans, retention, protection rules, and optional DevDome Monitoring. No DevDome account is required to scan, review, report on, back up, remove, restore, or delete unused media.
Connect a free DevDome account and enable Monitoring if you want to track media-library growth across connected WordPress sites.
After each scan, aggregate media statistics can be sent to DevDome. Monitoring tracks changes and sends alerts when unused media exceeds a threshold you choose.
No media files, filenames, image URLs, or visitor data are sent.
On WordPress 6.9 and newer, DevDome Safe Media Cleaner registers WordPress Abilities covering the whole plugin:
Compatible AI agents and MCP clients, for example through the official WordPress MCP Adapter, run the same code as the plugin screens under the same capability checks. Irreversible actions need an explicit confirmation.
Plugin catalog (devdome.com). The DevDome Dashboard inside wp-admin fetches the list of DevDome plugins (names, descriptions, logos, links, WordPress.org slugs) from https://devdome.com/wp-plugins/catalog.json at most once every 12 hours, so the list stays current. Only the bundled core version is sent in the request; no site or visitor data. Service provider: DevDome. Terms: https://devdome.com/terms-of-service Privacy policy: https://devdome.com/privacy-policy
All scanning, classification, Recycle Bin, backup, and restore features run on your own server. Account connection and Monitoring require explicit opt-in. The plugin catalog fetch and manually submitted error reports are described separately here.
devdome.com, api.devdome.com and analytics.devdome.com) – optional.Connecting an account is required only for optional DevDome Monitoring. When you start the connection, devdome.com opens in your browser. After approval, the plugin stores your public DevDome Account ID and a site token, then sends the site token to api.devdome.com to verify the connection; the connection handshake itself (start and claim) talks to analytics.devdome.com. The service returns the account email displayed in the plugin settings.
The Account ID, site domain, and site token are transmitted. If you disconnect, the site domain and site token are sent once to unlink the site. When you connect from the DevDome Tools dashboard, whose Connect card states this before you press the button, those account checks also carry the slug and version of each active DevDome plugin on the site plus the bundled DevDome library, WordPress and PHP versions, so your DevDome account can show your sites and their DevDome plugins for support and update notices. Nothing about other plugins, users, email addresses, content or visitors is included. Sites connected before this was introduced, and sites connected from a button that does not show that text, do not send the list. Disconnecting stops the plugin list.
No media files, filenames, private image URLs, or visitor data are sent.
Service provider: DevDome
Terms: https://devdome.com/terms-of-service
Privacy policy: https://devdome.com/privacy-policy
api.devdome.com) – optional and opt-in.When Monitoring is enabled, the plugin sends aggregate scan statistics after each scan: site domain, site token, total media count and size, unused media count and size, orphaned file count, alert threshold, selected email frequency, and the link to this plugin’s wp-admin screen.
DevDome stores this history, displays it in the media-health dashboard, tracks changes across scans and connected sites, and sends alert emails when the chosen threshold is exceeded.
No media files, filenames, image URLs, or visitor data are sent.
Service provider: DevDome
Terms: https://devdome.com/terms-of-service
Privacy policy: https://devdome.com/privacy-policy
Dormant endpoints in the bundled DevDome core
The bundled shared library references these endpoints, but they are disabled and are not contacted by the WordPress.org build:
https://api.devdome.com/plugin-updates/ – used by the self-hosted DevDome suite installer. Updates and installs for this build come only from WordPress.org.https://api.devdome.com/media-cleaner/metrics – used by the DevDome-distributed build for aggregate product metrics. It does not run in the WordPress.org build.Beyond the plugin catalog fetch and the error reports described below, no outbound request is made unless you explicitly connect a DevDome account. Monitoring statistics are sent only after you also enable DevDome Monitoring.
devdome.com) – only when you press Report this error. The button on an error message sends the error text, the plugin, WordPress and PHP versions, the screen you were on, your site address and your admin email (so support can reply) to https://devdome.com/api/plugin/error-report. Nothing is sent unless you press it. Terms: https://devdome.com/terms-of-service Privacy: https://devdome.com/privacy-policy/wp-content/uploads/devdome-safe-trash/, protected against public access by the bundled .htaccess (Apache) and web.config (IIS) rules; on nginx add a deny rule for that folder yourself.