
FG Drupal to WordPress Security & Risk Analysis
wordpress.org/plugins/fg-drupal-to-wpA plugin to migrate articles, stories, pages, categories, tags, images from Drupal to WordPress
Is FG Drupal to WordPress Safe to Use in 2026?
Generally Safe
Score 97/100FG Drupal to WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "fg-drupal-to-wp" plugin version 3.93.1 presents a mixed security posture. While it demonstrates good practices such as high rates of prepared SQL statements and proper output escaping, critical concerns arise from its attack surface and historical vulnerabilities. The presence of a single AJAX handler without authentication checks is a significant entry point for potential exploitation, especially when combined with the dangerous `unserialize` function, which can lead to remote code execution if processing untrusted data. The taint analysis, although limited in scope, shows two flows with unsanitized paths, indicating potential weaknesses in how data is handled before being used in critical operations.
The plugin's vulnerability history reveals a pattern of medium-severity issues, including SSRF, information exposure, and CSRF. The absence of currently unpatched vulnerabilities is a positive sign, but the recurring nature of these types of weaknesses suggests that the development team may struggle with securely handling external data or user input, and a lack of robust permission checks on critical functions. The most recent vulnerability in July 2025, even if patched, highlights ongoing security challenges.
In conclusion, while the plugin benefits from some solid coding practices, the unprotected AJAX endpoint, the use of `unserialize`, and the historical vulnerability patterns create a notable risk. The lack of capability checks on any code paths is also a significant concern. These factors, despite the generally good handling of SQL and output, warrant caution and careful monitoring.
Key Concerns
- Unprotected AJAX handler
- Use of unserialize function
- Flows with unsanitized paths
- No capability checks found
- Medium severity CVEs in history
FG Drupal to WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
FG Drupal to WordPress <= 3.90.0 - Authenticated (Admin+) Server-Side Request Forgery
FG Drupal to WordPress <= 3.70.3 - Sensitive Information Exposure
FG Drupal to WordPress <= 3.67.0 - Cross-Site Request Forgery via ajax_importer
FG Drupal to WordPress Release Timeline
FG Drupal to WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
FG Drupal to WordPress Attack Surface
AJAX Handlers 1
WordPress Hooks 14
Maintenance & Trust
FG Drupal to WordPress Maintenance & Trust
Maintenance Signals
Community Trust
FG Drupal to WordPress Alternatives
Canalblog Importer
canalblog-importer
Fatigué(e) d'avoir à gérer un blog sur Canalblog ? Cette extension va vous permettre de TOUT récupérer en quelques clics.
AlT Import Drupal
alt-import-drupal
"AlT Import Drupal" can transforme the Drupal RSS flux in WordPress articles
Listdom Bridge Addon – Migrate Listings to Listdom
listdom-bridge
Easily migrate listings from popular directory plugins into Listdom.
Migration Drupal to WordPress
migration-drupal-to-wp
Migration Drupal to Wordpress is a tool to move the basic data from databases drupal to wordpress.
Bat Importer for Blogger – Unlimited & Free Blogger Importer
bat-importer-for-blogger
Import public Blogger blogs into WordPress by Blog ID, with optional image download, page import, and redirect support.
FG Drupal to WordPress Developer Profile
10 plugins · 10K total installs
How We Detect FG Drupal to WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fg-drupal-to-wp/admin/css/fg-drupal-to-wp-admin.css/wp-content/plugins/fg-drupal-to-wp/admin/js/fg-drupal-to-wp-admin.js/wp-content/plugins/fg-drupal-to-wp/admin/js/fg-drupal-to-wp-admin.jsfg-drupal-to-wp/admin/css/fg-drupal-to-wp-admin.css?ver=fg-drupal-to-wp/admin/js/fg-drupal-to-wp-admin.js?ver=HTML / DOM Fingerprints
data-importer-id="fgd2wp"objectL10nobjectPlugin