
FG SPIP to WordPress Security & Risk Analysis
wordpress.org/plugins/fg-spip-to-wpA plugin to migrate categories, articles, news, and images from SPIP to WordPress
Is FG SPIP to WordPress Safe to Use in 2026?
Generally Safe
Score 100/100FG SPIP to WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin exhibits a mixed security posture. On one hand, it demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output. The absence of known vulnerabilities in its history is also a positive indicator. However, significant concerns arise from the static analysis. The presence of an unprotected AJAX handler represents a critical entry point that could be exploited if it handles user-supplied data without proper validation or authorization. The use of the `unserialize` function, while not necessarily a vulnerability on its own, is a known risk factor for object injection vulnerabilities, especially if the serialized data originates from an untrusted source. The taint analysis, while not revealing critical or high severity flows, did identify two flows with unsanitized paths, which warrants further investigation to understand the potential impact. In conclusion, while the plugin has a clean vulnerability history and uses some secure coding practices, the unprotected AJAX handler and the use of `unserialize` introduce notable risks that could be leveraged by attackers.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: unserialize
- Flows with unsanitized paths
FG SPIP to WordPress Security Vulnerabilities
FG SPIP to WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
FG SPIP to WordPress Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
FG SPIP to WordPress Maintenance & Trust
Maintenance Signals
Community Trust
FG SPIP to WordPress Alternatives
Categories to Tags Converter
wpcat2tag-importer
Convert existing categories to tags or tags to categories, selectively.
FG PrestaShop to WooCommerce
fg-prestashop-to-woocommerce
A plugin to migrate PrestaShop e-commerce solution to WooCommerce
Seraphinite Post .DOCX Source
seraphinite-post-docx-source
Save your time by automatically converting from .DOCX to content with all WordPress post attributes.
Taxonomy Converter
taxonomy-converter
Copy or convert terms between taxonomies.
FG OpenCart to WooCommerce
fg-opencart-to-woocommerce
A plugin to migrate OpenCart e-commerce solution to WooCommerce
FG SPIP to WordPress Developer Profile
9 plugins · 10K total installs
How We Detect FG SPIP to WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fg-spip-to-wp/admin/css/fg-spip-to-wp-admin.css/wp-content/plugins/fg-spip-to-wp/admin/js/fg-spip-to-wp-admin.js/wp-content/plugins/fg-spip-to-wp/admin/js/fg-spip-to-wp-admin.jsfg-spip-to-wp/admin/css/fg-spip-to-wp-admin.css?ver=fg-spip-to-wp/admin/js/fg-spip-to-wp-admin.js?ver=HTML / DOM Fingerprints
spip_cat_data-log_file_urlobjectL10nobjectPlugin