
Import VK Security & Risk Analysis
wordpress.org/plugins/import-vkImporting VKontakte (vk.com) posts into your WordPress site.
Is Import VK Safe to Use in 2026?
Generally Safe
Score 92/100Import VK has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "import-vk" plugin v1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping a significant portion of its output. The absence of known CVEs and vulnerability history also suggests a generally well-maintained codebase. However, a critical concern arises from the presence of a single unprotected AJAX handler. This represents a direct entry point into the plugin's functionality that lacks any authentication or authorization checks, making it susceptible to abuse by unauthenticated users. The plugin also lacks nonce checks on its entry points, further increasing the risk associated with the unprotected AJAX handler. While taint analysis and file operations show no immediate issues, the unprotected AJAX endpoint is a significant security weakness that needs immediate attention.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and unescaped output, the unprotected AJAX handler presents a clear and present danger. This single vulnerability could allow attackers to trigger plugin functionality without proper verification, potentially leading to unintended consequences or exploitation if the handler's functionality itself is vulnerable to other issues not apparent in the provided static analysis. The lack of nonce checks exacerbates this risk. Addressing this unprotected entry point should be the highest priority.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks on AJAX
- Limited output escaping (29% not properly escaped)
Import VK Security Vulnerabilities
Import VK Code Analysis
Output Escaping
Import VK Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Import VK Maintenance & Trust
Maintenance Signals
Community Trust
Import VK Alternatives
Skylark VKontakte Group Wall Publisher
vkontakte-group-wall-publisher
Автоматическая публикация обновлений блога на стене группы ВКонтакте.
Events Tracker for Elementor
events-tracker-for-elementor
Track Click or Submit events and conversions for any Elementor widget with Google Analytics, Facebook, Yandex Metrika, Vkontakte.
Meks Easy Social Share
meks-easy-social-share
Easily display social share buttons for your posts, pages and custom post types. Supports Facebook, Twitter, Reddit, Pinterest, Email, Google+, Linked …
Social Comments by Heateor
heateor-social-comments
Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website
VKontakte
vkontakte
The plugin adds a wide range of VKontakte functionality to your site.
Import VK Developer Profile
2 plugins · 310 total installs
How We Detect Import VK
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-vk/inc/css/jquery-ui.min.css/wp-content/plugins/import-vk/inc/css/jquery-ui-slider-pips.css/wp-content/plugins/import-vk/inc/css/bootstrap-datetimepicker.min.css/wp-content/plugins/import-vk/inc/css/bootstrap.min.css/wp-content/plugins/import-vk/inc/css/main.css/wp-content/plugins/import-vk/inc/js/bootstrap.min.js/wp-content/plugins/import-vk/inc/js/jquery-ui-slider-pips.js/wp-content/plugins/import-vk/inc/js/moment-with-locales.min.js+2 moreHTML / DOM Fingerprints
glyphicon-musicglyphicon-fileglyphicon-filmembed-responsiveembed-responsive-16by9embed-responsive-itemdata-targetdata-toggledata-parentscriptParams/wp-json/import-vk/v1