
Import from Ning Security & Risk Analysis
wordpress.org/plugins/import-from-ningImports the contents of a Ning Network Archive into BuddyPress
Is Import from Ning Safe to Use in 2026?
Generally Safe
Score 85/100Import from Ning has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "import-from-ning" v2.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in its database interactions, with 100% of SQL queries utilizing prepared statements, significantly mitigating the risk of SQL injection. Furthermore, there are no known CVEs associated with this plugin, and its attack surface is reported as zero entry points, suggesting a well-contained design in terms of common web vulnerabilities like AJAX handlers, REST API routes, shortcodes, and cron events.
However, several concerns emerge from the static analysis. The low percentage of properly escaped output (38%) is a significant weakness, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Taint analysis also reveals two flows with unsanitized paths, and while no critical or high severity issues were flagged, these unsanitized paths represent potential vectors for malicious code execution or data manipulation if an attacker can control the input leading to these paths. The absence of nonce checks and capability checks across all entry points (which are reported as zero, but the analysis suggests a lack of checks where they might be expected if entry points existed) is concerning, as it implies a lack of authorization and validation on any potential, albeit currently undiscovered, entry points.
Given the lack of vulnerability history and the minimal reported attack surface, the plugin may be relatively safe in its current state. However, the prevalent output escaping issues and unsanitized taint flows are substantial risks that should be addressed to improve its overall security. The developer should prioritize fixing these identified code-level weaknesses.
Key Concerns
- Insufficient output escaping
- Unsanitized paths in taint flows
- Missing nonce checks
- Missing capability checks
Import from Ning Security Vulnerabilities
Import from Ning Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Import from Ning Attack Surface
WordPress Hooks 1
Maintenance & Trust
Import from Ning Maintenance & Trust
Maintenance Signals
Community Trust
Import from Ning Alternatives
LearnPress – Backup & Migration Tool
learnpress-import-export
LearnPress Export/Import bring you feature to export course, lesson, quiz, question from a LearnPress site to back up or bring to another LearnPress s …
BuddyPress for LearnDash
buddypress-learndash
BuddyPress for LearnDash integrates the LearnDash LMS plugin with BuddyPress, so you can add groups, activity, members, and forums to your courses.
BuddyPress Default Data
bp-default-data
Plugin will create lots of users, messages, friends connections, groups, topics, activity items, profile data - useful for testing purpose.
BP Import Blog Activity
bp-import-blog-activity
Updates BuddyPress activity streams with missing blog comments and posts
BuddyPress Groups Import
buddypress-groups-import
Import groups from CSV file into BuddyPress.
Import from Ning Developer Profile
27 plugins · 12K total installs
How We Detect Import from Ning
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-from-ning/style.cssHTML / DOM Fingerprints
WP_CONTENT_DIRBP_AVATAR_UPLOAD_PATH