EnvoThemes Demo Importer for KingComposer Security & Risk Analysis

wordpress.org/plugins/envothemes-importer-kingcomposer

Import the Envo Business demo layouts with one click.

400 active installs v1.0.4 PHP + WP 4.0+ Updated Jan 25, 2018
contentdatademoimportlayouts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is EnvoThemes Demo Importer for KingComposer Safe to Use in 2026?

Generally Safe

Score 85/100

EnvoThemes Demo Importer for KingComposer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "envothemes-importer-kingcomposer" v1.0.4 exhibits a generally positive security posture, primarily due to the absence of known vulnerabilities and a well-structured approach to handling SQL queries and output escaping. The static analysis reveals a minimal attack surface with no direct entry points like AJAX handlers, REST API routes, or shortcodes, which is a significant strength. Furthermore, the plugin avoids making external HTTP requests and does not bundle any libraries, reducing the risk of chain vulnerabilities from external dependencies.

However, the presence of the `unserialize` function is a notable concern. While there are no immediate taint flows indicating a current exploit, the use of `unserialize` without proper input validation or sanitization can open the door to PHP Object Injection vulnerabilities if the serialized data originates from an untrusted source. The lack of capability checks and nonce checks, coupled with no observed taint flows or unescaped outputs for the analyzed flows, suggests that the identified `unserialize` usage might be internal or well-protected, but this is not definitively proven by the provided data.

Given the zero known CVEs and no past vulnerability history, the plugin appears to have been maintained with security in mind. Nevertheless, the single instance of a dangerous function like `unserialize` warrants attention. The plugin's strengths lie in its limited attack surface and secure SQL handling, but the potential risk associated with `unserialize` remains a weakness that could be mitigated by more robust input validation.

Key Concerns

  • Use of dangerous function unserialize
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

EnvoThemes Demo Importer for KingComposer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EnvoThemes Demo Importer for KingComposer Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
3
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$values = unserialize( $value[ 'value' ] );inc\admin-page.php:181

Output Escaping

82% escaped17 total outputs
Attack Surface

EnvoThemes Demo Importer for KingComposer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedenvothemes-importer-kingcomposer.php:19
actionadmin_enqueue_scriptsenvothemes-importer-kingcomposer.php:32
actionplugins_loadedenvothemes-importer-kingcomposer.php:34
actionadmin_noticesenvothemes-importer-kingcomposer.php:48
filterplugin_action_linksenvothemes-importer-kingcomposer.php:66
filterplugin_row_metaenvothemes-importer-kingcomposer.php:81
actionadmin_noticesenvothemes-importer-kingcomposer.php:119
actionadmin_menuinc\admin-page.php:26
actionadmin_initinc\admin-page.php:27
actionadmin_noticesinc\welcome.php:6
actionadmin_initinc\welcome.php:19
Maintenance & Trust

EnvoThemes Demo Importer for KingComposer Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 25, 2018
PHP min version
Downloads45K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

EnvoThemes Demo Importer for KingComposer Developer Profile

EnvoThemes

16 plugins · 90K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
27 days
View full developer profile
Detection Fingerprints

How We Detect EnvoThemes Demo Importer for KingComposer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/envothemes-importer-kingcomposer/css/style.css

HTML / DOM Fingerprints

CSS Classes
my-ebdi-kc-noticeet-import-data
Data Attributes
aria-label
FAQ

Frequently Asked Questions about EnvoThemes Demo Importer for KingComposer