FameTheme Demo Importer Security & Risk Analysis

wordpress.org/plugins/famethemes-demo-importer

FameThemes Demo importer

30K active installs v1.1.11 PHP + WP 4.5+ Updated Apr 16, 2025
demo-datafamethemesimportoneclick
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 26, 2024
Safety Verdict

Is FameTheme Demo Importer Safe to Use in 2026?

Generally Safe

Score 99/100

FameTheme Demo Importer has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 26, 2024Updated 11mo ago
Risk Assessment

The 'famethemes-demo-importer' plugin, version 1.1.11, exhibits a generally strong security posture based on the static analysis results. The plugin demonstrates good practices by implementing nonce checks and capability checks for its entry points, and a high percentage of its SQL queries utilize prepared statements and its outputs are properly escaped. The absence of file operations and bundled libraries further reduces potential attack vectors. However, the presence of one flow with an unsanitized path, even without a critical or high severity rating, warrants attention as it indicates a potential weakness in how data is handled and could be exploited in specific scenarios, though its low severity suggests a limited immediate threat.

The vulnerability history shows one known medium-severity CVE related to Cross-Site Request Forgery (CSRF). While this vulnerability is currently patched (0 unpatched), the pattern of past vulnerabilities, particularly CSRF, suggests a recurring area of concern that the developers need to continue addressing. The fact that it's a medium severity and already patched is positive, but it highlights the need for ongoing vigilance in this area. Overall, the plugin is well-implemented with a low attack surface and good use of security features, but the taint analysis and historical vulnerability pattern indicate areas where meticulous code review and testing should be prioritized to maintain a robust security profile.

Key Concerns

  • Flow with unsanitized path identified
  • Past medium severity CVE (CSRF)
Vulnerabilities
1

FameTheme Demo Importer Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-33679medium · 4.3Cross-Site Request Forgery (CSRF)

FameTheme Demo Importer <= 1.1.5 - Cross-Site Request Forgery

Apr 26, 2024 Patched in 1.1.6 (41d)
Code Analysis
Analyzed Mar 16, 2026

FameTheme Demo Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
5 prepared
Unescaped Output
12
106 escaped
Nonce Checks
6
Capability Checks
17
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

63% prepared8 total queries

Output Escaping

90% escaped118 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
url_exists (famethemes-demo-importer.php:474)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FameTheme Demo Importer Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_demo_contents__importinc\class-progress.php:21
WordPress Hooks 37
actioninitfamethemes-demo-importer.php:47
actionplugins_loadedfamethemes-demo-importer.php:519
actionactivated_pluginfamethemes-demo-importer.php:562
filterupload_mimesfamethemes-demo-importer.php:566
actionadmin_menuinc\class-dashboard.php:19
actionadmin_footerinc\class-dashboard.php:21
actionadmin_enqueue_scriptsinc\class-dashboard.php:23
actiontheme_demo_import_content_tabinc\class-dashboard.php:32
actiontheme_demo_import_content_tabinc\class-dashboard.php:41
actioncurrent_screeninc\class-dashboard.php:42
actionadmin_enqueue_scriptsinc\class-progress.php:22
actioninitinc\class-tgm-plugin-activation.php:268
filterload_textdomain_mofileinc\class-tgm-plugin-activation.php:269
actioninitinc\class-tgm-plugin-activation.php:272
actionadmin_menuinc\class-tgm-plugin-activation.php:421
actionadmin_headinc\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsinc\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsinc\class-tgm-plugin-activation.php:426
actionadmin_noticesinc\class-tgm-plugin-activation.php:429
actionadmin_initinc\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsinc\class-tgm-plugin-activation.php:431
actionload-plugins.phpinc\class-tgm-plugin-activation.php:436
actionswitch_themeinc\class-tgm-plugin-activation.php:439
actionswitch_themeinc\class-tgm-plugin-activation.php:442
actionadmin_initinc\class-tgm-plugin-activation.php:447
actionswitch_themeinc\class-tgm-plugin-activation.php:452
actionload_textdomain_mofileinc\class-tgm-plugin-activation.php:475
filterupgrader_source_selectioninc\class-tgm-plugin-activation.php:889
actionplugins_loadedinc\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemsinc\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectioninc\class-tgm-plugin-activation.php:2977
actionadmin_initinc\class-tgm-plugin-activation.php:3147
actionupgrader_process_completeinc\class-tgm-plugin-activation.php:3242
filterupgrader_post_installinc\class-tgm-plugin-activation.php:3301
filterupgrader_post_installinc\class-tgm-plugin-activation.php:3446
filterhttp_request_timeoutinc\merlin-wp\includes\class-merlin-importer.php:260
actiontgmpa_registerinc\theme-supports.php:3
Maintenance & Trust

FameTheme Demo Importer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 16, 2025
PHP min version
Downloads870K

Community Trust

Rating100/100
Number of ratings1
Active installs30K
Developer Profile

FameTheme Demo Importer Developer Profile

FameThemes

5 plugins · 104K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
23 days
View full developer profile
Detection Fingerprints

How We Detect FameTheme Demo Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/famethemes-demo-importer/assets/css/famethemes-demo-importer.css/wp-content/plugins/famethemes-demo-importer/assets/js/famethemes-demo-importer.js
Script Paths
/wp-content/plugins/famethemes-demo-importer/assets/js/famethemes-demo-importer.js
Version Parameters
famethemes-demo-importer/assets/css/famethemes-demo-importer.css?ver=famethemes-demo-importer/assets/js/famethemes-demo-importer.js?ver=

HTML / DOM Fingerprints

CSS Classes
famethemes-demo-importer-buttonfamethemes-demo-importer-import-formfamethemes-demo-importer-list-item
HTML Comments
<!-- FameThemes Demo Importer --><!-- End FameThemes Demo Importer -->
Data Attributes
data-plugin-path
JS Globals
famethemesDemoImporter
REST Endpoints
/wp-json/famethemes-demo-importer/v1/import
Shortcode Output
[famethemes_demo_importer]
FAQ

Frequently Asked Questions about FameTheme Demo Importer