DevDome Safe Media Cleaner – Remove Unused & Orphaned Images
DevDome Safe Media Cleaner helps you find and safely remove unused images, orphaned files, duplicate media, and missing files from your WordPress media library and uploads folder.
Selected files move to a protected Recycle Bin first. Review the results, restore cleaned files with one click, and permanently delete them only when you are ready.
Clean your WordPress media library
- Find unused images that are not referenced by posts, pages, builders, widgets, or settings.
- Detect orphaned files stored in the uploads folder without a Media Library record.
- Find exact duplicate images and choose which copy to keep.
- Flag Media Library entries whose original file is missing from disk.
- Sort by file size to reclaim disk space and reduce backup size.
Safer media cleanup
- Recycle Bin first. Selected files are moved, not permanently deleted.
- Last-second re-check. Each file is checked again immediately before it moves.
- Protected by default. Recent uploads and uncertain files are not selected automatically.
- Clear review labels. Results are marked Safe to remove, Needs manual review, or Protected, with the reason shown.
- Optional ZIP backups. Create, download, upload, and restore media backups before cleaning.
How it works
- Scan: Scan the Media Library and uploads folder in background batches.
- Review: Search, filter, sort, and inspect every flagged file before selecting it.
- Clean: Move selected files to the protected Recycle Bin.
- Restore or delete: Restore cleaned files with one click, or permanently delete them after checking your site.
Detailed review tools
Review results in a visual grid or list. Search by filename, filter by status, sort by file size, dimensions, or age, and select files individually or in bulk. Each result shows its thumbnail, size, dimensions, upload date, status, and the reason it was flagged. Results can also be exported to CSV.
Checks common WordPress image references
The scanner checks post content, custom post types, revisions, reusable blocks, featured images, galleries, Gutenberg blocks, srcset, lazy-loading attributes, CSS backgrounds, widgets, menus, the site logo, the site icon, and WordPress options.
It also checks data used by:
- Page builders: Elementor, Divi, Beaver Builder, WPBakery, Bricks, Oxygen, Kadence, GenerateBlocks, Spectra, SeedProd, and Thrive.
- WooCommerce: product images, galleries, variations, and category images.
- Custom fields and SEO plugins: ACF, Meta Box, Yoast SEO, Rank Math, and AIOSEO.
- Generated files: thumbnail sizes, scaled images, and edited copies matched to their original attachment.
Built for larger media libraries
Scans run in small, resumable background batches to reduce memory use and timeout risk. You can pause and resume a scan without restarting it.
Free features
Scanning, review, duplicate detection, reports, the Recycle Bin, restore, media backups, scheduled scans, CSV export, and WP-CLI commands are free and unlimited.
No DevDome account is required for scanning or cleanup.
Optional DevDome Monitoring
You can optionally connect a free DevDome account and enable Monitoring. After each scan, aggregate media statistics are sent to DevDome so you can view media growth across connected sites and receive email alerts when unused media exceeds a threshold you choose.
No media files, filenames, image URLs, or visitor data are sent.
External services
All scanning, classification, Recycle Bin, backup, and restore features run on your own server. The plugin connects to DevDome only after explicit opt-in.
- DevDome account connection (
devdome.comandapi.devdome.com) — optional.
Connecting an account is required only for optional DevDome Monitoring. When you start the connection, devdome.com opens in your browser. After approval, the plugin stores your public DevDome Account ID and a site token, then sends the site token to api.devdome.com to verify the connection. The service returns the account email displayed in the plugin settings.
The Account ID, site domain, and site token are transmitted. If you disconnect, the site domain and site token are sent once to unlink the site.
No media files, filenames, private image URLs, or visitor data are sent.
Service provider: DevDome Terms: https://devdome.com/terms-of-service Privacy policy: https://devdome.com/privacy-policy
- DevDome Monitoring (
api.devdome.com) — optional and opt-in.
When Monitoring is enabled, the plugin sends aggregate scan statistics after each scan: site domain, site token, total media count and size, unused media count and size, orphaned file count, alert threshold, and selected email frequency.
DevDome stores this history, displays it in the media-health dashboard, tracks changes across scans and connected sites, and sends alert emails when the chosen threshold is exceeded.
No media files, filenames, image URLs, or visitor data are sent.
Service provider: DevDome Terms: https://devdome.com/terms-of-service Privacy policy: https://devdome.com/privacy-policy
Dormant endpoints in the bundled DevDome core
The bundled shared library references these endpoints, but they are disabled and are not contacted by the WordPress.org build:
https://api.devdome.com/plugin-updates/— used by the self-hosted DevDome suite installer. Updates and installs for this build come only from WordPress.org.https://api.devdome.com/media-cleaner/metrics— used by the DevDome-distributed build for aggregate product metrics. It does not run in the WordPress.org build.
No outbound request is made unless you explicitly connect a DevDome account. Monitoring statistics are sent only after you also enable DevDome Monitoring.
Privacy
- Media files stay local. Scanning, classification, cleanup, backup, and restore run on your server.
- Recycle Bin files stay local. They are stored in
/wp-content/uploads/devdome-safe-trash/, which is protected against public access during the review period. - No cookies are set by the plugin.
- No product metrics are sent by the WordPress.org build.
- Optional Monitoring sends only the aggregate statistics listed in the External services section after explicit opt-in.
