Plugin Pulse
← Pulse

Media Library Assistant

by David Lingren · Media

Enhances the Media Library; powerful gallery and list shortcodes, full taxonomy support, IPTC/EXIF/XMP/PDF processing, bulk/quick edit.

How scoring works →
91 Health · A
Maintenance 100/100
Rating quality 95/100
Support 70/100

91 health vs 59 average across 2,206 Media plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

99 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 93/100
Listing tuning 100/100
Support resolution 100/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

+0% vs prior 30d
1.3KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

37.4K

now · peak 80.8K

37.3K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Media Library Assist · #616 you Cache Images · #6228 Media Cleaner: Clean · #480 Crop-Thumbnails · #808

Rating trend

Star average over time · dips mark rough releases

4.8Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

533per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

11

releases in the last 12 months

2mo ago

latest release · v3.39

124

tagged releases on record

Recent releases

3.39 · 2mo ago3.38 · 3mo ago3.37 · 3mo ago3.36 · 3mo ago3.35 · 5mo ago3.34 · 6mo ago3.33 · 6mo ago3.32 · 7mo ago3.31 · 7mo ago3.30 · 10mo ago3.29 · 11mo ago3.28 · 1.0y ago3.27 · 1.1y ago3.26 · 1.4y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v3.39 28%
v3.38 9.4%
Older / other versions 62%

Estimated active installs

The public count shows “70K+”. Our estimate pins where the real number sits.

modeled estimate
70K–80K ≈77K

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2015-03-02 · 1,484 observations

70KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
3.40
Last updated
8d ago
Added
2012-08-13 · 14 yrs old
Requires WP
5.3.0
Tested up to
7.0.4
Requires PHP
7.4

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 3.39 New: Shortcode material in the Settings/Media Library Assistant Documentation tab has been reorganized and improved. New: For the [mla_archive_list] shortcode, new shortcode parameters have been added. New: For the [mla_ 3.39
  2. Version 3.38 New: For the [mla_custom_list] shortcode, new output formats and pagination options have been added. Fix: IMPORTANT: For WP 7.0, Media Library Grid mode and MMMW popup window toolbar formatting defects have been correcte 3.38
  3. Version 3.37 Fix: IMPORTANT: For pagination shortcodes, a URL formatting defect introduced in MLA v3.36 has been corrected. Fix: IMPORTANT: For the Media/Assistant submenu table, an SQL Injection security risk has been mitigated. Fix 3.37
  4. Version 3.36 Fix: IMPORTANT: For pagination shortcodes, a Cross Site Scripting security risk (Patchstack 31064) has been mitigated. Fix: IMPORTANT: For the [mla_archive_list] shortcode, an SQL Injection security risk (Patchstack 3049 3.36
  5. Version 3.30 3.35 – IMPORTANT: Two security fixes and WP 7.0 updates. Media/Assistant “Thumbnail” (generation) Bulk action enhancements. MP3 metadata extraction fixes. One enhancement and six fixes in all. 3.34 – IMPORTANT: Security 3.30
  6. Version 3.00 3.29 – IMPORTANT: Security mitigation in all four shortcodes. Media Manager Modal (popup) and Media/Assistant submenu table fixes. Four fixes in all. 3.28 – IMPORTANT: Security mitigation and [mla_term_list] critical err 3.00

Known vulnerabilities

via Wordfence Intelligence

37 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-24 CVE-2026-16959 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.40 Patched in 3.40
  2. 2026-08-19 CVE-2026-66600 Unrestricted Upload of File with Dangerous Type Affects <= 3.39 Patched in 3.40
  3. 2026-08-19 CVE-2026-66601 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.39 Patched in 3.40
  4. 2026-08-18 CVE-2026-66591 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.39 Patched in 3.40
  5. 2026-08-04 CVE-2026-61963 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.38 Patched in 3.39
  6. 2026-06-18 CVE-2026-56012 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.35 Patched in 3.36
  7. 2026-06-15 CVE-2026-54198 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.35 Patched in 3.36
  8. 2026-05-28 CVE-2026-6075 Cross-Site Request Forgery (CSRF) Affects <= 3.35 Patched in 3.36
  9. 2026-04-06 CVE-2026-34885 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.34 Patched in 3.35
  10. 2026-04-06 CVE-2026-34897 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.34 Patched in 3.35
  11. 2026-03-04 CVE-2026-3072 Missing Authorization Affects <= 3.33 Patched in 3.34
  12. 2026-02-20 CVE-2026-32399 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.32 Patched in 3.33
  13. 2025-10-17 CVE-2025-11738 External Control of File Name or Path Affects <= 3.29 Patched in 3.30
  14. 2025-10-09 CVE-2025-63065 Missing Authorization Affects <= 3.29 Patched in 3.30
  15. 2025-09-22 CVE-2025-59590 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.28 Patched in 3.29
  16. 2025-08-18 CVE-2025-8357 Missing Authorization Affects <= 3.27 Patched in 3.28
  17. 2025-07-15 CVE-2025-7035 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.26 Patched in 3.27
  18. 2025-03-31 CVE-2025-31627 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.24 Patched in 3.25
  19. 2025-01-03 CVE-2024-11974 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.23 Patched in 3.24
  20. 2024-11-01 CVE-2024-51661 Improper Control of Generation of Code ('Code Injection') Affects <= 3.19 Patched in 3.20
  21. 2024-08-12 CVE-2024-6823 Unrestricted Upload of File with Dangerous Type Affects <= 3.18 Patched in 3.19
  22. 2024-07-01 CVE-2024-5544 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.17 Patched in 3.18
  23. 2024-06-19 CVE-2024-5605 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.16 Patched in 3.17
  24. 2024-05-21 CVE-2024-3519 Improper Neutralization of Alternate XSS Syntax Affects <= 3.15 Patched in 3.16
  25. 2024-05-21 CVE-2024-3518 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.15 Patched in 3.16
  26. 2024-03-28 CVE-2024-2475 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.13 Patched in 3.14
  27. 2024-03-25 CVE-2024-2871 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.13 Patched in 3.14
  28. 2023-10-02 CVE-2023-24385 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.11 Patched in 3.12
  29. 2023-09-21 CVE-2023-4716 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10 Patched in 3.11
  30. 2023-09-05 CVE-2023-4634 External Control of File Name or Path Affects <= 3.09 Patched in 3.10
  31. 2023-07-12 CVE-2023-34010 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.7 Patched in 3.0.8
  32. 2023-02-16 CVE-2023-0279 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.05 Patched in 3.06
  33. 2022-09-29 CVE-2022-41618 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.00 Patched in 3.01
  34. 2019-12-15 CVE-2020-11928 Improper Control of Generation of Code ('Code Injection') Affects <= 2.81 Patched in 2.82
  35. 2019-12-15 CVE-2020-11731 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.82 Patched in 2.82
  36. 2019-12-15 CVE-2020-11732 External Control of File Name or Path Affects <= 2.81 Patched in 2.82
  37. 2018-05-28 CVE-2018-20982 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.7.4 Patched in 2.74

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 67 languages, 1 at 90% or more

Czech 91%
Dutch 64%
Finnish 60%
Italian 51%
Japanese 36%
Swedish 33%
Russian 29%
German 20%
French (France) 16%
Icelandic 16%
Romanian 12%
English (Canada) 9%
English (UK) 9%
Cebuano 8%
English (Australia) 8%
English (South Africa) 8%
Ukrainian 8%
Azerbaijani 7%
Dutch (Formal) 7%
English (New Zealand) 7%
Spanish (Spain) 7%
Esperanto 6%
German (Formal) 6%
Hebrew 6%

Plus 43 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

No tier crossings observed yet.

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Media Library Assistant into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/media-library-assistant" width="480" height="300" style="border:0" loading="lazy" title="Media Library Assistant — Plugin Pulse"></iframe>
Preview card ↗

Media Library Assistant: 70K+ active installs, 4.8★ (201 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/media-library-assistant