Canalblog Importer Security & Risk Analysis

wordpress.org/plugins/canalblog-importer

Fatigué(e) d'avoir à gérer un blog sur Canalblog ? Cette extension va vous permettre de TOUT récupérer en quelques clics.

30 active installs v1.6.5 PHP + WP 5.2+ Updated Aug 2, 2020
admincanalblogimportimportermigration
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Canalblog Importer Safe to Use in 2026?

Generally Safe

Score 85/100

Canalblog Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "canalblog-importer" v1.6.5 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any discovered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the complete absence of dangerous functions and the use of prepared statements for all SQL queries are strong indicators of good coding practices. The lack of file operations, external HTTP requests, and any recorded vulnerabilities in its history are also reassuring.

However, a critical concern arises from the output escaping analysis. With 10 total outputs and 0% properly escaped, this plugin presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed or displayed by this plugin that is not sanitized before output could be exploited by attackers to inject malicious scripts. The absence of capability checks and nonce checks, while not directly indicative of a vulnerability on their own in this specific analysis (due to the lack of entry points), are generally considered important security measures for WordPress plugins.

In conclusion, while the plugin has a minimal attack surface and avoids common pitfalls like raw SQL and dangerous functions, the complete lack of output escaping is a major weakness that significantly increases the risk of XSS attacks. This single area of concern overshadows the otherwise clean analysis, necessitating immediate attention.

Key Concerns

  • 0% output escaping
  • 0 nonce checks
  • 0 capability checks
Vulnerabilities
None known

Canalblog Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Canalblog Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Attack Surface

Canalblog Importer Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Canalblog Importer Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 2, 2020
PHP min version
Downloads9K

Community Trust

Rating60/100
Number of ratings2
Active installs30
Developer Profile

Canalblog Importer Developer Profile

thom4

3 plugins · 10K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
46 days
View full developer profile
Detection Fingerprints

How We Detect Canalblog Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/canalblog-importer/css/admin.css/wp-content/plugins/canalblog-importer/js/admin.js
Script Paths
/wp-content/plugins/canalblog-importer/js/admin.js
Version Parameters
canalblog-importer/css/admin.css?ver=canalblog-importer/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
canalblog-importer-admin-options
JS Globals
CanalblogImporter
FAQ

Frequently Asked Questions about Canalblog Importer