
Content Runner Importer Security & Risk Analysis
wordpress.org/plugins/content-runner-importerContent Runner Importer allows for the quick and easy transfer of contentrunner.com articles into WordPress.
Is Content Runner Importer Safe to Use in 2026?
Generally Safe
Score 85/100Content Runner Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'content-runner-importer' plugin version 1.0.2 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and its static analysis reveals a limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. It also avoids the use of dangerous functions and external HTTP requests are not utilized in a way that would immediately indicate risk. Furthermore, it does not bundle external libraries, which can often introduce vulnerabilities.
However, there are significant concerns highlighted by the code signals. The fact that 100% of outputs are not properly escaped is a critical vulnerability. This means that any data displayed to users could potentially be manipulated to inject malicious scripts (Cross-Site Scripting). Additionally, half of the SQL queries are not using prepared statements, posing a risk of SQL injection if user-supplied data is directly incorporated into these queries. The absence of nonce and capability checks, combined with four taint flows involving unsanitized paths, further exacerbates these risks, suggesting that user-controlled data is not being adequately validated before being used, potentially leading to unauthorized actions or data manipulation. The vulnerability history being clean is a good sign, but it doesn't negate the critical weaknesses identified in the current codebase.
Key Concerns
- 100% of outputs not properly escaped
- 50% of SQL queries not using prepared statements
- No nonce checks
- No capability checks
- Taint flows with unsanitized paths (4 total)
Content Runner Importer Security Vulnerabilities
Content Runner Importer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Content Runner Importer Attack Surface
WordPress Hooks 7
Maintenance & Trust
Content Runner Importer Maintenance & Trust
Maintenance Signals
Community Trust
Content Runner Importer Alternatives
GetAutoSEO AI Tool
getautoseo-ai-content-publisher
Automate your SEO content creation and publishing with AI-powered tools. Generate high-quality articles and publish directly to WordPress.
Kafkai – AI Writer Plugin
kafkai
Plugin to generate and import articles from Kafkai. Learn more in the Help Article
Content Craft AI: SEO & AI Article Generator
content-craft-ai
Generate human-like SEO articles that bypass AI detectors like GPTZero and Originality.ai using our advanced WordPress plugin.
Fluxserp – AI Content Writer & SEO on Autopilot
fluxserp-ai-content-writer-seo-on-autopilot
Automatically publish AI-generated SEO articles from Fluxserp to your WordPress site.
Launchmind Blog
launchmind-blog
Display AI-powered Launchmind blog content on your WordPress site.
Content Runner Importer Developer Profile
2 plugins · 20 total installs
How We Detect Content Runner Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/content-runner-importer/css/admin.css/wp-content/plugins/content-runner-importer/js/plugin.js/wp-content/plugins/content-runner-importer/js/plugin.jscontent-runner-importer/css/admin.css?ver=content-runner-importer/js/plugin.js?ver=HTML / DOM Fingerprints
Copyright 2013 Damien Smith, Matt Peters, and Larry FiedlerThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+9 morePLUGIN_FOLDER