FG OpenCart to WooCommerce Security & Risk Analysis

wordpress.org/plugins/fg-opencart-to-woocommerce

A plugin to migrate OpenCart e-commerce solution to WooCommerce

300 active installs v1.48.0 PHP 5.6+ WP 4.5+ Updated Feb 9, 2026
converterimportermigratoropencartwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FG OpenCart to WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

FG OpenCart to WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "fg-opencart-to-woocommerce" v1.48.0 exhibits a generally good security posture in many areas, particularly with its extensive use of prepared statements for SQL queries and a high percentage of properly escaped outputs. The absence of known vulnerabilities and dangerous functions is a positive indicator of its maintenance and development quality.

However, a significant concern is the presence of one unprotected AJAX handler, representing a clear entry point into the plugin's functionality without proper authentication or authorization checks. While the taint analysis did not reveal critical or high severity issues, the identified flows with unsanitized paths warrant attention, even if their severity is not explicitly stated as critical. The plugin also has a moderate number of file operations and external HTTP requests, which could potentially be leveraged if the unprotected AJAX handler is exploited.

Overall, the plugin demonstrates strengths in secure coding practices for common web vulnerabilities. The main weakness lies in the unprotected AJAX endpoint, which presents a tangible risk of unauthorized access or actions. The vulnerability history being clear of any past issues is reassuring, suggesting a history of stable and relatively secure releases. The plugin's security could be significantly improved by securing its entry points and ensuring all user-facing operations are properly authenticated and authorized.

Key Concerns

  • 1 unprotected AJAX handler
  • 2 flows with unsanitized paths
  • 0 Capability checks
Vulnerabilities
None known

FG OpenCart to WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FG OpenCart to WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
40 prepared
Unescaped Output
13
72 escaped
Nonce Checks
9
Capability Checks
0
File Operations
11
External Requests
2
Bundled Libraries
0

SQL Query Safety

98% prepared41 total queries

Output Escaping

85% escaped85 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
display (admin\class-fg-opencart-to-woocommerce-debug-info.php:21)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

FG OpenCart to WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_fgoc2wc_importincludes\class-fg-opencart-to-woocommerce.php:191
WordPress Hooks 20
filterwoocommerce_mail_callbackadmin\class-fg-opencart-to-woocommerce-admin.php:1491
actionbefore_woocommerce_initfg-opencart-to-woocommerce.php:60
actioninitfg-opencart-to-woocommerce.php:85
filterplugin_action_links_fg-opencart-to-woocommerce/fg-opencart-to-woocommerce.phpincludes\class-fg-opencart-to-woocommerce.php:173
actionadmin_initincludes\class-fg-opencart-to-woocommerce.php:184
filterfgoc2wc_sql_pre_queryincludes\class-fg-opencart-to-woocommerce.php:185
actionfgoc2wc_post_test_database_connectionincludes\class-fg-opencart-to-woocommerce.php:186
actionfgoc2wc_post_empty_databaseincludes\class-fg-opencart-to-woocommerce.php:187
actionload-importer-fgoc2wcincludes\class-fg-opencart-to-woocommerce.php:188
actionfgoc2wc_import_noticesincludes\class-fg-opencart-to-woocommerce.php:189
actionadmin_footerincludes\class-fg-opencart-to-woocommerce.php:190
filterfgoc2wc_pre_import_checkincludes\class-fg-opencart-to-woocommerce.php:192
filterfgoc2wc_get_option_namesincludes\class-fg-opencart-to-woocommerce.php:193
filterfgoc2wc_get_product_tagsincludes\class-fg-opencart-to-woocommerce.php:194
actionfgoc2wc_pre_importincludes\class-fg-opencart-to-woocommerce.php:195
actionfgoc2wc_post_test_database_connectionincludes\class-fg-opencart-to-woocommerce.php:201
filterfgoc2wc_post_display_settings_optionsincludes\class-fg-opencart-to-woocommerce.php:207
filterfgoc2wc_post_save_plugin_optionsincludes\class-fg-opencart-to-woocommerce.php:208
actionfgoc2wc_dispatchincludes\class-fg-opencart-to-woocommerce.php:209
filterfgoc2wc_get_option_namesincludes\class-fg-opencart-to-woocommerce.php:210
Maintenance & Trust

FG OpenCart to WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version5.6
Downloads18K

Community Trust

Rating100/100
Number of ratings14
Active installs300
Developer Profile

FG OpenCart to WooCommerce Developer Profile

Kerfred

9 plugins · 10K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
674 days
View full developer profile
Detection Fingerprints

How We Detect FG OpenCart to WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fg-opencart-to-woocommerce/css/fg-opencart-to-woocommerce-admin.css/wp-content/plugins/fg-opencart-to-woocommerce/js/fg-opencart-to-woocommerce-admin.js
Script Paths
/wp-content/plugins/fg-opencart-to-woocommerce/js/fg-opencart-to-woocommerce-admin.js
Version Parameters
fg-opencart-to-woocommerce/css/fg-opencart-to-woocommerce-admin.css?ver=fg-opencart-to-woocommerce/js/fg-opencart-to-woocommerce-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
objectL10n
FAQ

Frequently Asked Questions about FG OpenCart to WooCommerce