
DotClear Importer Security & Risk Analysis
wordpress.org/plugins/dotclear-importerImport categories, users, posts, comments, and links from a DotClear blog.
Is DotClear Importer Safe to Use in 2026?
Generally Safe
Score 85/100DotClear Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The dotclear-importer plugin v0.2 exhibits a generally positive security posture with no known vulnerabilities or critical security signals. The absence of any recorded CVEs and the low number of external code signals, such as file operations or external HTTP requests, are encouraging. Furthermore, the presence of a nonce check, even with no other capability checks, indicates a basic level of awareness for security best practices.
However, a significant concern arises from the output escaping. With 32 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users, if not properly sanitized, could be manipulated to inject malicious scripts. Additionally, while the number of SQL queries is moderate, 56% of them are not using prepared statements, which introduces a risk of SQL injection. The total absence of identified taint flows is good, but the unescaped output and raw SQL queries are critical blind spots that need immediate attention.
Key Concerns
- No proper output escaping
- SQL queries without prepared statements
DotClear Importer Security Vulnerabilities
DotClear Importer Code Analysis
SQL Query Safety
Output Escaping
DotClear Importer Attack Surface
WordPress Hooks 1
Maintenance & Trust
DotClear Importer Maintenance & Trust
Maintenance Signals
Community Trust
DotClear Importer Alternatives
WordPress Importer
wordpress-importer
Import posts, pages, comments, custom fields, categories, tags and more from a WordPress export file.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
Import and export users and customers
import-users-from-csv-with-meta
Import and export users and customers including user meta, roles, and other. Compatible with many plugins. Do it from the front end or using cron.
Starter Templates & Sites Pack by ThemeGrill
themegrill-demo-importer
Premium starter sites and website templates by ThemeGrill. Import demo content, widgets, and theme settings with one click.
Blogger Importer
blogger-importer
Imports posts, images, comments, and categories (blogger tags) from a Blogger blog then migrates authors to WordPress users.
DotClear Importer Developer Profile
11 plugins · 113K total installs
How We Detect DotClear Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapnarrowscreen_icon()