Media Library Assistant
by David Lingren · Media
Enhances the Media Library; powerful gallery and list shortcodes, full taxonomy support, IPTC/EXIF/XMP/PDF processing, bulk/quick edit.
91 health vs 59 average across 2,206 Media plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
37.4K
now · peak 80.8K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
11
releases in the last 12 months
2mo ago
latest release · v3.39
124
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “70K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-02 · 1,484 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 3.39 New: Shortcode material in the Settings/Media Library Assistant Documentation tab has been reorganized and improved. New: For the [mla_archive_list] shortcode, new shortcode parameters have been added. New: For the [mla_ 3.39
- — Version 3.38 New: For the [mla_custom_list] shortcode, new output formats and pagination options have been added. Fix: IMPORTANT: For WP 7.0, Media Library Grid mode and MMMW popup window toolbar formatting defects have been correcte 3.38
- — Version 3.37 Fix: IMPORTANT: For pagination shortcodes, a URL formatting defect introduced in MLA v3.36 has been corrected. Fix: IMPORTANT: For the Media/Assistant submenu table, an SQL Injection security risk has been mitigated. Fix 3.37
- — Version 3.36 Fix: IMPORTANT: For pagination shortcodes, a Cross Site Scripting security risk (Patchstack 31064) has been mitigated. Fix: IMPORTANT: For the [mla_archive_list] shortcode, an SQL Injection security risk (Patchstack 3049 3.36
- — Version 3.30 3.35 – IMPORTANT: Two security fixes and WP 7.0 updates. Media/Assistant “Thumbnail” (generation) Bulk action enhancements. MP3 metadata extraction fixes. One enhancement and six fixes in all. 3.34 – IMPORTANT: Security 3.30
- — Version 3.00 3.29 – IMPORTANT: Security mitigation in all four shortcodes. Media Manager Modal (popup) and Media/Assistant submenu table fixes. Four fixes in all. 3.28 – IMPORTANT: Security mitigation and [mla_term_list] critical err 3.00
Known vulnerabilities
via Wordfence Intelligence37 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-24 CVE-2026-16959 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.40 Patched in 3.40
- 2026-08-19 CVE-2026-66600 Unrestricted Upload of File with Dangerous Type Affects <= 3.39 Patched in 3.40
- Medium · 6.4 Media Library Assistant <= 3.39 - Authenticated (Subscriber+) Stored Cross-Site Scripting ↗2026-08-19 CVE-2026-66601 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.39 Patched in 3.40
- Medium · 6.4 Media Library Assistant <= 3.39 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2026-08-18 CVE-2026-66591 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.39 Patched in 3.40
- 2026-08-04 CVE-2026-61963 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.38 Patched in 3.39
- 2026-06-18 CVE-2026-56012 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.35 Patched in 3.36
- 2026-06-15 CVE-2026-54198 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.35 Patched in 3.36
- 2026-04-06 CVE-2026-34885 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.34 Patched in 3.35
- Medium · 6.4 Media Library Assistant <= 3.34 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2026-04-06 CVE-2026-34897 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.34 Patched in 3.35
- 2026-02-20 CVE-2026-32399 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.32 Patched in 3.33
- Medium · 6.4 Media Library Assistant <= 3.28 - Authenticated (Author+) Stored Cross-Site Scripting ↗2025-09-22 CVE-2025-59590 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.28 Patched in 3.29
- 2025-07-15 CVE-2025-7035 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.26 Patched in 3.27
- Medium · 4.4 Media Library Assistant <= 3.24 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2025-03-31 CVE-2025-31627 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.24 Patched in 3.25
- 2025-01-03 CVE-2024-11974 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.23 Patched in 3.24
- 2024-11-01 CVE-2024-51661 Improper Control of Generation of Code ('Code Injection') Affects <= 3.19 Patched in 3.20
- 2024-08-12 CVE-2024-6823 Unrestricted Upload of File with Dangerous Type Affects <= 3.18 Patched in 3.19
- 2024-07-01 CVE-2024-5544 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.17 Patched in 3.18
- High · 8.8 Media Library Assistant <= 3.16 - Authenticated (Contributor+) SQL Injection via order Parameter ↗2024-06-19 CVE-2024-5605 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.16 Patched in 3.17
- 2024-05-21 CVE-2024-3519 Improper Neutralization of Alternate XSS Syntax Affects <= 3.15 Patched in 3.16
- High · 8.8 Media Library Assistant <= 3.15 - Authenticated (Contributor+) SQL Injection via Shortcode ↗2024-05-21 CVE-2024-3518 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.15 Patched in 3.16
- 2024-03-28 CVE-2024-2475 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.13 Patched in 3.14
- Medium · 6.4 Media Library Assistant <= 3.13 - Authenticated (Contributor+) SQL Injection via Shortcode ↗2024-03-25 CVE-2024-2871 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.13 Patched in 3.14
- Medium · 6.4 Media Library Assistant <= 3.11 - Authenticated (Author+) Stored Cross-Site Scripting ↗2023-10-02 CVE-2023-24385 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.11 Patched in 3.12
- Medium · 6.4 Media Library Assistant <= 3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2023-09-21 CVE-2023-4716 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10 Patched in 3.11
- 2023-07-12 CVE-2023-34010 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.7 Patched in 3.0.8
- 2023-02-16 CVE-2023-0279 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.05 Patched in 3.06
- 2022-09-29 CVE-2022-41618 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.00 Patched in 3.01
- Critical · 9.8 Media Library Assistant <= 2.81 - Remote Code Execution via tax_query, meta_query, date_query Parameters ↗2019-12-15 CVE-2020-11928 Improper Control of Generation of Code ('Code Injection') Affects <= 2.81 Patched in 2.82
- 2019-12-15 CVE-2020-11731 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.82 Patched in 2.82
- 2018-05-28 CVE-2018-20982 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.7.4 Patched in 2.74
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 67 languages, 1 at 90% or more
Plus 43 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
- C Cache Images 1K+ installs · 3.9★ · 3 shared tags D
-
Media Cleaner: Clean your WordPress! 90K+ installs · 4.6★ · 2 shared tags A -
Crop-Thumbnails 40K+ installs · 4.5★ · 2 shared tags B
-
Clean Image Filenames 30K+ installs · 4.3★ · 2 shared tags B -
Media Library Categories 20K+ installs · 4.2★ · 2 shared tags A - P Post Tags and Categories for Pages 20K+ installs · 4.5★ · 2 shared tags B
Embed this report card
Drop a live Pulse card for Media Library Assistant into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/media-library-assistant" width="480" height="300" style="border:0" loading="lazy" title="Media Library Assistant — Plugin Pulse"></iframe> Media Library Assistant: 70K+ active installs, 4.8★ (201 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/media-library-assistant