
Cloudways WordPress Migrator Security & Risk Analysis
wordpress.org/plugins/bv-cloudways-automated-migrationThe easiest way to migrate your site to Cloudways
Is Cloudways WordPress Migrator Safe to Use in 2026?
Generally Safe
Score 100/100Cloudways WordPress Migrator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bv-cloudways-automated-migration' plugin version 5.88 exhibits a mixed security posture. On the positive side, it shows good practices in areas like SQL query sanitization, with 70% using prepared statements, and a high percentage of properly escaped output (94%). The absence of known CVEs and a clean vulnerability history is also a significant strength, suggesting a generally well-maintained codebase.
However, the plugin has critical security concerns related to its attack surface. The static analysis reveals two AJAX handlers, both of which lack authentication checks. This creates a significant risk of unauthorized actions being performed if these handlers can be triggered by unauthenticated users. The complete absence of nonce checks on these AJAX endpoints further exacerbates this risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks.
Despite the positive indicators like well-escaped output and a lack of known vulnerabilities, the presence of two unprotected AJAX endpoints represents a substantial security weakness. These entry points could allow attackers to perform sensitive operations without any authorization, potentially leading to data breaches or system compromise. While the absence of taint analysis findings is good, it does not negate the inherent risk posed by exposed AJAX handlers. Therefore, while the plugin has some strengths, the unprotected AJAX endpoints are a serious concern requiring immediate attention.
Key Concerns
- AJAX handlers without authentication checks
- Missing nonce checks on AJAX handlers
- Large attack surface without auth checks
Cloudways WordPress Migrator Security Vulnerabilities
Cloudways WordPress Migrator Code Analysis
SQL Query Safety
Output Escaping
Cloudways WordPress Migrator Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Cloudways WordPress Migrator Maintenance & Trust
Maintenance Signals
Community Trust
Cloudways WordPress Migrator Alternatives
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
Migrate Guru – Site Migration & Cloning
migrate-guru
Effortlessly migrate, clone, or transfer your WordPress site to over 5,000 web hosts with Migrate Guru, trusted by Cloudways, Pantheon, and Dreamhost.
Backup Migration
backup-backup
Backup Migration
WP STAGING – WordPress Backup, Restore & Migration
wp-staging
Backup, restore, staging, and migration for WordPress. Create full-site backups and test updates safely.
Cloudways WordPress Migrator Developer Profile
3 plugins · 421K total installs
How We Detect Cloudways WordPress Migrator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bv-cloudways-automated-migration/css/style.css/wp-content/plugins/bv-cloudways-automated-migration/css/bootstrap.min.css/wp-content/plugins/bv-cloudways-automated-migration/js/bv_migration.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_helper.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_site_info.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_account.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_api.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_admin.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_migration.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_helper.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_site_info.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_account.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_api.js/wp-content/plugins/bv-cloudways-automated-migration/js/bv_admin.jsbv-cloudways-automated-migration/style.css?ver=bv-cloudways-automated-migration/bootstrap.min.css?ver=bv-cloudways-automated-migration/bv_migration.js?ver=bv-cloudways-automated-migration/bv_helper.js?ver=bv-cloudways-automated-migration/bv_site_info.js?ver=bv-cloudways-automated-migration/bv_account.js?ver=bv-cloudways-automated-migration/bv_api.js?ver=bv-cloudways-automated-migration/bv_admin.js?ver=HTML / DOM Fingerprints
bv_migration_wrapperbv_migration_headerbv_migration_bodybv_migration_footerbv_migration_stepbv_migration_step_activebv_migration_step_completedbv_migration_step_error+12 moreCopyright 2017 Cloudways MigrateThis program is free softwareThis program is distributed in the hope that it will be usefulYou should have received a copy of the GNU General Public License+15 moredata-bv-migration-stepdata-bv-migration-idbv_migration_varsbv_migration_configbv_migration_databv_migration_ajaxurl/wp-json/bv-cloudways-automated-migration/v1/settings/wp-json/bv-cloudways-automated-migration/v1/migrate/wp-json/bv-cloudways-automated-migration/v1/status