
ForumConverter Security & Risk Analysis
wordpress.org/plugins/forumconverterMigrates a phpBB forum into a bbPress forum.
Is ForumConverter Safe to Use in 2026?
Generally Safe
Score 85/100ForumConverter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "forumconverter" v1.11 plugin reveals significant security concerns, primarily related to its handling of SQL queries and data sanitization. While the plugin has no known CVEs, which is a positive indicator, the code itself presents considerable risks. A striking 100% of SQL queries are not using prepared statements, making the plugin highly vulnerable to SQL injection attacks. Furthermore, all analyzed taint flows (9 out of 9) have unsanitized paths, with 9 of them being of high severity. This indicates a substantial risk of attackers being able to manipulate data or execute unintended operations by injecting malicious input. The lack of nonce checks and capability checks on potential entry points (though the attack surface is reported as zero, the taint analysis suggests otherwise) is also a major concern, as it leaves the plugin open to cross-site request forgery (CSRF) and unauthorized actions. The plugin's history of no vulnerabilities is commendable, but it does not mitigate the serious risks identified in the current code analysis. The absence of proper output escaping on a majority of outputs (only 29% properly escaped) further compounds the risk, potentially leading to cross-site scripting (XSS) vulnerabilities.
Key Concerns
- 100% of SQL queries not using prepared statements
- 9 high severity unsanitized taint flows
- 71% of output not properly escaped
- No nonce checks
- No capability checks
ForumConverter Security Vulnerabilities
ForumConverter Release Timeline
ForumConverter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ForumConverter Attack Surface
WordPress Hooks 14
Maintenance & Trust
ForumConverter Maintenance & Trust
Maintenance Signals
Community Trust
ForumConverter Alternatives
wpForo Forum
wpforo
Number one WordPress forum plugin with AI features. Full-fledged forum solution with modern forum design. Community builder WordPress forum plugin.
bbp style pack
bbp-style-pack
For bbPress - Lets you style bbPress, and add display features
bbPress Notify (No-Spam)
bbpress-notify-nospam
Powerful, customizable email notifications for bbPress and BuddyBoss forums — without the spam.
Private groups
bbp-private-groups
For bbPress - Creates private forum groups
bbPress WP Tweaks
bbpress-wp-tweaks
Adds bbPress forum specific sidebar, wrapper, widgets, user columns, login links and other tweaks.
ForumConverter Developer Profile
1 plugin · 10 total installs
How We Detect ForumConverter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/forumconverter/wp-pass-ex.phpHTML / DOM Fingerprints
labelscreen-reader-textname="forum_password"id="forum_password"name="forum_id"jQuery