
EnvoThemes Demo Importer for KingComposer Security & Risk Analysis
wordpress.org/plugins/envothemes-importer-kingcomposerImport the Envo Business demo layouts with one click.
Is EnvoThemes Demo Importer for KingComposer Safe to Use in 2026?
Generally Safe
Score 85/100EnvoThemes Demo Importer for KingComposer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "envothemes-importer-kingcomposer" v1.0.4 exhibits a generally positive security posture, primarily due to the absence of known vulnerabilities and a well-structured approach to handling SQL queries and output escaping. The static analysis reveals a minimal attack surface with no direct entry points like AJAX handlers, REST API routes, or shortcodes, which is a significant strength. Furthermore, the plugin avoids making external HTTP requests and does not bundle any libraries, reducing the risk of chain vulnerabilities from external dependencies.
However, the presence of the `unserialize` function is a notable concern. While there are no immediate taint flows indicating a current exploit, the use of `unserialize` without proper input validation or sanitization can open the door to PHP Object Injection vulnerabilities if the serialized data originates from an untrusted source. The lack of capability checks and nonce checks, coupled with no observed taint flows or unescaped outputs for the analyzed flows, suggests that the identified `unserialize` usage might be internal or well-protected, but this is not definitively proven by the provided data.
Given the zero known CVEs and no past vulnerability history, the plugin appears to have been maintained with security in mind. Nevertheless, the single instance of a dangerous function like `unserialize` warrants attention. The plugin's strengths lie in its limited attack surface and secure SQL handling, but the potential risk associated with `unserialize` remains a weakness that could be mitigated by more robust input validation.
Key Concerns
- Use of dangerous function unserialize
- Missing nonce checks
- Missing capability checks
EnvoThemes Demo Importer for KingComposer Security Vulnerabilities
EnvoThemes Demo Importer for KingComposer Code Analysis
Dangerous Functions Found
Output Escaping
EnvoThemes Demo Importer for KingComposer Attack Surface
WordPress Hooks 11
Maintenance & Trust
EnvoThemes Demo Importer for KingComposer Maintenance & Trust
Maintenance Signals
Community Trust
EnvoThemes Demo Importer for KingComposer Alternatives
Rara One Click Demo Import
rara-one-click-demo-import
Make your website look like the live demo of the theme with a click!
TutorMate
tutormate
TutorMate is a Tutor Starter theme companion plugin to import predesigned stylish demo pages to eLearning sites powered by Tutor LMS plugin.
SKT Themes Demo Import
skt-themes-demo-importer
Live demo content can be imported quickly in just one click including all widgets and settings.
Theme Demo Import
theme-demo-import
Quickly import demo content, widgets and settings in one click. Made for theme authors to simplify importing demo content for their users.
Fable Extra
fable-extra
Used for WP Fable Themes.
EnvoThemes Demo Importer for KingComposer Developer Profile
16 plugins · 90K total installs
How We Detect EnvoThemes Demo Importer for KingComposer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envothemes-importer-kingcomposer/css/style.cssHTML / DOM Fingerprints
my-ebdi-kc-noticeet-import-dataaria-label