Skip to content
WordPress.org

Éwé

  • Themes
  • Plugins
  • About
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Hexloom Upload Metadata Scrubber

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Hexloom Upload Metadata Scrubber

By hexloomlabs
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

When someone uploads a contract, price list or report to your Media Library, the file usually carries more than its content: the author’s name, the person who saved it last, the company, the software used, a revision count, and for photos the GPS position. Visitors can read all of it by downloading the file and opening its properties.

Upload Metadata Scrubber, from Hexloom Labs, removes that metadata from new uploads automatically and keeps a report for each file, so you can see what was removed and what the plugin could not remove. It works on your server: nothing is sent to any other service, and the plugin makes no external requests.

What it cleans

  • Word, Excel and PowerPoint (.docx, .xlsx, .pptx and their macro and template variants): author, last modified by, revision number, last printed date, company, manager and custom document properties.
  • PDF: author, creator, producer, title, subject, keywords and XMP details, where the structure of the file allows a safe change. The report lists what was found, and files that cannot be changed safely are left untouched and marked.
  • JPEG, PNG and WebP images: EXIF (camera, date taken, GPS location), XMP and text chunks, removed without re-compressing the picture. Photo orientation and colour profiles are kept so images still look right.

What you see

Open any file in the Media Library and look for “Metadata scrub”: removed items, items found but not removed, and the reason. The Media Library list has a “Metadata” column with the same summary. By default the report records what kind of data was removed (for example “Author”), not the data itself, so personal details are not copied into your database. You can switch that on in the settings.

What it does not do (read this)

This plugin reduces the identifying metadata in uploads. It is not a guarantee that a file contains no identifying information.

  • Only new uploads are processed. Files already in your Media Library are not touched.
  • Names or details typed into the body of a document, tracked changes, comments, headers, footers or embedded images are not removed. Where the plugin can see them it says so in the report.
  • Password-protected files, old .doc/.xls/.ppt files and unusual file structures are left untouched, and the report says why.
  • PDF: the author, title and similar fields are blanked in place. Creation and modification dates and the document ID stay. PDFs that are digitally signed, or that store their document information in a compressed block, are reported but not changed.
  • If cleaning a file could damage it, the plugin leaves the file as uploaded.
  • Copies of the file kept elsewhere (email, backups, a CDN, other plugins) are not changed.
  • It is not legal or compliance advice.

Requirements

PHP 7.4 or later. Word, Excel and PowerPoint cleaning needs the PHP Zip extension, which most hosts provide; if it is missing, those files are left untouched and the report says so.

Screenshots

The Media Library list has a Metadata column that says, per file, whether data was removed, found but not removed, or not found.
The Media Library list has a Metadata column that says, per file, whether data was removed, found but not removed, or not found.
The report on a cleaned Word file: what was removed, and what was found but left in place.
The report on a cleaned Word file: what was removed, and what was found but left in place.
The settings screen: choose which file types are cleaned, and read the plain-language limits.
The settings screen: choose which file types are cleaned, and read the plain-language limits.
A signed PDF is reported, not changed, so its signature stays valid.
A signed PDF is reported, not changed, so its signature stays valid.

Installation

  1. Install the plugin from Plugins > Add New, or upload the zip.
  2. Activate it. New uploads are cleaned straight away.
  3. Optional: Settings > Metadata Scrubber to switch file types on or off.

FAQ

Does it change files already in my Media Library?

No. Only new uploads are processed.

Does it remove all metadata?

No, and no tool can promise that. It removes the standard author and revision fields listed above and tells you what else it found. Content inside the document is not changed.

Will it damage my files?

The plugin writes a new copy, checks it, and only then replaces the upload. If anything looks wrong the file is left exactly as uploaded. Images are not re-compressed.

Does it send my files anywhere?

No. Everything runs on your server and the plugin makes no external requests.

Does it work with files uploaded through forms or WooCommerce?

It cleans files that go through the standard WordPress upload handling, which includes the Media Library and the block editor. Plugins that store uploads in their own way may bypass it.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Hexloom Upload Metadata Scrubber” is open source software. The following people have contributed to this plugin.

Contributors
  • hexloomlabs

Translate “Hexloom Upload Metadata Scrubber” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

0.1.0

  • First release.

Meta

  • Version 0.1.0
  • Last updated 17 hours ago
  • Active installations Fewer than 10
  • WordPress version 5.8 or higher
  • Tested up to 7.1.3
  • PHP version 7.4 or higher
  • Language
    English (US)
  • Tag
    docx
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • hexloomlabs

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Support
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

Éwé

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry.