Title: Attic — Safe Database Cleanup (Undo-Friendly)
Author: Bishal Shrestha
Published: <strong>August 31, 2026</strong>
Last modified: October 4, 2026

---

Search plugins

![](https://ps.w.org/attic-safe-database-audit/assets/banner-772x250.png?rev=3721616)

![](https://ps.w.org/attic-safe-database-audit/assets/icon-256x256.png?rev=3721616)

# Attic — Safe Database Cleanup (Undo-Friendly)

 By [Bishal Shrestha](https://profiles.wordpress.org/rainynewt/)

[Download](https://downloads.wordpress.org/plugin/attic-safe-database-audit.2.1.1.zip)

 * [Details](https://vec.wordpress.org/plugins/attic-safe-database-audit/#description)
 * [Reviews](https://vec.wordpress.org/plugins/attic-safe-database-audit/#reviews)
 *  [Installation](https://vec.wordpress.org/plugins/attic-safe-database-audit/#installation)
 * [Development](https://vec.wordpress.org/plugins/attic-safe-database-audit/#developers)

 [Support](https://wordpress.org/support/plugin/attic-safe-database-audit/)

## Description

**Site Health says “Autoloaded options could affect performance”? Attic shows you
exactly what’s causing it, and lets you remove it without risking your site.**

Every plugin you’ve ever installed left something behind: oversized options, dead
cron jobs, orphaned database tables, stale transients. Deleting the plugin doesn’t
delete its data. WordPress loads a lot of that leftover data on every single page
request, so years of “uninstalled” plugins quietly slow your site down.

Attic finds it, shows you the evidence, and removes it **the undo-friendly way**:

 * **Nothing is deleted up front.** Tables are renamed, options are backed up. Restore
   anything in one click for 30 days (configurable).
 * **Nothing is guessed.** Before Attic calls something orphaned, it checks that
   the owning plugin’s files are really gone and searches your code for any reference
   to it. Uncertain items stay marked “review”.
 * **Nothing changes until you say so.** The scan is read-only.

#### What Attic finds

 * **Autoloaded option bloat**: oversized options that load on every page, ranked
   by size against Site Health’s 800 KB limit.
 * **Leftovers from deleted plugins**: options, tables and cron jobs whose plugin
   is no longer on disk.
 * **Orphaned tables**: tables no installed plugin claims, with the megabytes you’d
   get back.
 * **Ghost cron events**: scheduled jobs with no code behind them, firing forever
   and doing nothing.
 * **Stranded transients**: expired cache rows that never got cleaned up.
 * **Orphaned meta**: post, comment, user and term meta whose parent row is gone.

#### Every finding shows its evidence

Which rule fired, which plugin the data belongs to, whether that plugin is still
on disk, how many code references were found, and how big it is. A finding you can’t
check is a finding you shouldn’t act on.

#### Who it’s for

 * Site owners who’ve installed and removed a lot of plugins over the years
 * Agencies doing housekeeping on client sites (WP-CLI and scheduled scans included)
 * Anyone whose Site Health page flags autoloaded options and doesn’t know what 
   to do about it

#### Also included

 * **Scheduled scans** (daily, weekly or monthly) with an email digest of new and
   resolved findings
 * **Autoload trend chart** over your last 10 scans, exportable as PNG or CSV
 * **WP-CLI**: `wp attic scan`, `wp attic findings`, `wp attic quarantine`
 * **Multisite** network dashboard with per-site scan status
 * **No outbound requests.** No CDN, no tracking, no account. Everything runs on
   your server.

#### How is this different from WP-Optimize or Advanced Database Cleaner?

Those are established cleanup tools with direct delete/optimize actions. Attic takes
a different default: nothing is permanently deleted up front — flagged tables are
renamed (`wp_attic_quarantined_*`) and options are backed up first, with one-click
restore inside the purge window (default 30 days, configurable). Permanent removal
only happens once a quarantined batch passes the purge window un-restored, or if
you purge it yourself on purpose. Attic also checks plugin files on disk and searches
your code for references before promoting findings to high confidence, so uncertain
items stay at “review.”

#### WP-CLI commands

Run scans from the command line, across client sites or in CI/CD pipelines:

 * `wp attic scan` — run a full database audit
 * `wp attic findings` — list and filter findings
 * `wp attic quarantine` — manage quarantine batches
 * `wp attic status` — check plugin status
 * `wp attic map status` — inspect the bundled attribution map

#### Attribution Map

A curated map of plugin prefixes to their owning plugin, used to attribute
 orphaned
data. The map ships with the plugin and is updated with plugin releases — Attic 
makes no outbound network requests.

 * `wp attic map status` — show the bundled map version and entry count
 * Add your own attributions with the `attic_prefix_map_entries` filter

#### Third-party libraries

Attic bundles Chart.js 4.4.4 (MIT) at `assets/vendor/chart.umd.min.js`, used
 only
to draw the autoload trend chart in the admin. It is served from your own site. 
Attic makes no outbound network requests of any kind.

#### Developer filters

Protecting things from ever being flagged:

 * `attic_protected_options` — additional never-flag option names
 * `attic_protected_cron_hooks` — additional never-flag cron hooks
 * `attic_protected_tables` — additional never-flag tables
 * `attic_protected_transients` — additional never-flag transient names

Attribution and scanning:

 * `attic_prefix_map_entries` — add or override attribution map entries
 * `attic_prefix_map_path` — load the attribution map from a different file
 * `attic_reference_scan_roots` — where the code search looks; for unusual layouts
   and custom content directories
 * `attic_scan_rules` — add or remove detection rules

Behaviour:

 * `attic_manage_capability` — which capability may scan and quarantine (default`
   manage_options`)
 * `attic_purge_after_days` — override the quarantine purge window
 * `attic_tracked_autoload_options` — which options usage tracking watches
 * `attic_track_autoload_usage` — return false to disable usage tracking entirely

## Screenshots

[⌊Scan results: every finding shows its rule, confidence, size and the plugin it
belongs to.⌉⌊Scan results: every finding shows its rule, confidence, size and the
plugin it belongs to.⌉[

Scan results: every finding shows its rule, confidence, size and the plugin it belongs
to.

[⌊Finding evidence: whether the owning plugin is on disk and how many code references
were found.⌉⌊Finding evidence: whether the owning plugin is on disk and how many
code references were found.⌉[

Finding evidence: whether the owning plugin is on disk and how many code references
were found.

[⌊Quarantine: restore a whole batch in one click within the 30-day window.⌉⌊Quarantine:
restore a whole batch in one click within the 30-day window.⌉[

Quarantine: restore a whole batch in one click within the 30-day window.

[⌊Autoload trend chart against Site Health's 800 KB limit.⌉⌊Autoload trend chart
against Site Health's 800 KB limit.⌉[

Autoload trend chart against Site Health’s 800 KB limit.

[⌊Settings: scan thresholds, quarantine purge window and scheduled scans.⌉⌊Settings:
scan thresholds, quarantine purge window and scheduled scans.⌉[

Settings: scan thresholds, quarantine purge window and scheduled scans.

## Installation

 1. Install and activate.
 2. Go to Tools  Attic.
 3. Click Scan.
 4. Review evidence for each finding (confidence, size, code references).
 5. Quarantine what you want gone — recoverable for 30 days by default (configurable)
    if you change your mind.

## FAQ

### How do I fix “Autoloaded options could affect performance” in Site Health?

Install Attic, go to Tools  Attic and run a scan. The autoload findings list every
large autoloaded option by size, with the plugin it belongs to and whether that 
plugin is still installed. Quarantine the ones left behind by plugins you’ve deleted.
Your autoload size drops right away, and anything you remove can be restored for
30 days.

### Will this make my site faster?

If your autoloaded options are large, yes: WordPress loads them on every page request,
so shrinking them cuts work on every page. Orphaned tables and meta mostly cost 
disk space and backup size rather than page speed. Attic shows sizes up front so
you can see what’s worth removing.

### Is it safe to delete leftover plugin tables?

Only if the plugin that created them is really gone and nothing on your site still
reads them. Some plugins share tables, and some keep data you’d want back if you
reinstall. That’s why Attic never drops a table straight away: it renames it to `
wp_attic_quarantined_*`, so your site behaves as if it were deleted. If nothing 
breaks during the purge window, it’s removed for good. If something does break, 
restore it in one click.

### Is this safe?

The scan is read-only. Nothing changes until you take an explicit, confirmed action.
Core options like `siteurl`, `active_plugins` and `cron` can never be flagged, and
neither can anything on your own protected list or the `attic_protected_options`
filter.

### How do I undo something?

Tools  Attic  Quarantine. Every action creates a batch; restore a whole batch in
one click. Batches auto-purge after 30 days (configurable).

### Why does my finding say “review” instead of “high”?

For most rules, high confidence requires the owning plugin to be absent from disk(
or the option to be size-flagged _and_ unread), **and** zero literal **and** zero
prefix references anywhere in your code. Dynamic option names never literal-match,
so even a weak signal keeps a finding at “review”. If your filesystem could not 
be read, everything is marked unverified rather than guessed at.

Two rules are exceptions, because a code search cannot tell you anything useful 
about them: an expired transient and a meta row whose parent is gone are facts about
your database, not guesses about your code. Those are reported as high confidence
on their own evidence.

### Does it work with external object caches?

Yes — when Redis/Memcached is active, transients never touch the options table, 
and Attic says so instead of showing a meaningless clean bill of health.

### Multisite?

Yes. Single-site, subdirectory multisite, and subdomain multisite installs all work.
Network-wide fleet scanning is available via the network admin dashboard.

### Which plugins does Attic work with?

Attic works with **all WordPress plugins** — it’s a read-only cleanup tool that 
doesn’t touch plugin data unless you explicitly quarantine it. The attribution map
helps identify which plugin owns which database entries, but the scan works regardless
of whether a plugin is in the map.

Plugins with known prefixes in the attribution map get named attribution, and the“
leftovers from a deleted plugin” rule relies on the map to know which prefixes belonged
to which plugin.

Data belonging to a plugin that is not in the map is still found by the other rules—
an oversized autoloaded option, an orphaned table or a dead cron event is detected
either way. It just shows its owner as “unknown”. You can add your own entries with
the `attic_prefix_map_entries` filter.

### Does Attic delete plugin data?

No. Attic quarantines data (renames tables, copies options), never deletes. You 
can restore anything from Quarantine within the purge window (default 30 days, configurable).

### What about multisite network-active plugins?

Attic correctly detects network-active plugins and never flags their data as orphaned,
even if they’re deactivated on individual sites.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Attic — Safe Database Cleanup (Undo-Friendly)” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ Bishal Shrestha ](https://profiles.wordpress.org/rainynewt/)

[Translate “Attic — Safe Database Cleanup (Undo-Friendly)” into your language.](https://translate.wordpress.org/projects/wp-plugins/attic-safe-database-audit)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/attic-safe-database-audit/),
check out the [SVN repository](https://plugins.svn.wordpress.org/attic-safe-database-audit/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/attic-safe-database-audit/)
by [RSS](https://plugins.trac.wordpress.org/log/attic-safe-database-audit/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.1.1

 * Improved: Clearer plugin directory tags, so Attic is easier to find when you 
   search for help with autoloaded options or orphaned tables. No code changes.

#### 2.1.0

 * New: Attic now works on older sites too. It needs WordPress 5.6 or newer and 
   PHP 7.4 or newer (before, it needed WordPress 6.5 and PHP 8.1).
 * Improved: Leftover database tables from plugins you’ve deleted, such as Yoast
   SEO or Elementor, are now correctly marked as safe to clean up. Before, Attic
   was being too cautious and asked you to review them. Run a new scan after updating
   to see the difference.
 * Fixed: After quarantining items from the Findings page, you could be left looking
   at a blank screen. Your items were always quarantined safely; now you see the
   confirmation message as you should.
 * Fixed: The `wp attic scan` command (for people who manage sites from the command
   line) could crash while showing its progress bar.
 * Improved: A clearer plugin description, answers to common questions, and a short
   demo video.

#### 2.0.0

 * New: Orphaned meta detection (post, comment, user, term meta with a missing parent
   row).
 * New: Scheduled scans with an email digest, WP-CLI support, and a network dashboard
   for multisite.
 * New: Autoload trend chart, exportable as PNG or CSV.
 * Fix: Several rules were skipping findings they should have caught (stranded transients,
   three of four meta tables). Re-scanning is recommended.
 * Fix: Orphaned-table detection no longer flags other sites on shared multisite/
   database setups.
 * Improved: No more per-page-load database writes; scans and quarantine are unaffected.
 * Improved: No CDN or outbound requests — everything ships with the plugin.

#### 1.0.1

 * Fix: Quarantine action now correctly updates finding state (broken by SQL syntax
   error).
 * Fix: Orphan tables rule no longer flags Attic’s own tables on sites with nested
   table prefixes (e.g. wp_pc_attic_*).
 * Add: Stop scan button to abort long-running scans mid-flight.
 * Fix: Findings page defaults to latest completed scan instead of showing duplicates
   across all scans.
 * Fix: Scan complete state now hides progress bar and stop button cleanly.
 * Fix: Empty quarantine batches are cleaned up automatically.

#### 1.0.0

 * Initial plugin release: read-only database audit with quarantine-based undo, 
   five detection rules, budgeted scan engine, reference scanning, quarantine with
   batch restore, and attribution map.

## Meta

 *  Version **2.1.1**
 *  Last updated **6 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.6 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/attic-safe-database-audit/)
 * Tags
 * [autoloaded options](https://vec.wordpress.org/plugins/tags/autoloaded-options/)
   [cleanup](https://vec.wordpress.org/plugins/tags/cleanup/)[database cleanup](https://vec.wordpress.org/plugins/tags/database-cleanup/)
   [site health](https://vec.wordpress.org/plugins/tags/site-health/)
 *  [Advanced View](https://vec.wordpress.org/plugins/attic-safe-database-audit/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/attic-safe-database-audit/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/attic-safe-database-audit/reviews/)

## Contributors

 *   [ Bishal Shrestha ](https://profiles.wordpress.org/rainynewt/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/attic-safe-database-audit/)