Indexhibit 2 Importer Security & Risk Analysis

wordpress.org/plugins/indexhibit2-importer

Import exhibits and media files from an Indexhibit 2 site.

0 active installs v1.0.7 PHP 5.6+ WP 4.0+ Updated Unknown
importerindexhibit
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Indexhibit 2 Importer Safe to Use in 2026?

Generally Safe

Score 100/100

Indexhibit 2 Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The indexhibit2-importer plugin v1.0.7 presents a generally positive security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the lack of any recorded vulnerabilities, including critical and high-severity ones, suggests a history of responsible development or effective patching. The code signals also show some good practices, such as a high percentage of SQL queries using prepared statements. However, there are areas for concern. A notable weakness is the low percentage of properly escaped output (41%), which could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. Additionally, the absence of capability checks for its entry points, although currently theoretical due to no entry points being identified, is a general best practice that is missing. The zero taint flows are encouraging but do not fully negate the risk associated with unescaped output. Overall, the plugin appears relatively secure due to its limited attack surface and lack of historical vulnerabilities, but the unescaped output is a specific area that requires attention and improvement.

Key Concerns

  • Low percentage of properly escaped output
  • No capability checks for entry points
Vulnerabilities
None known

Indexhibit 2 Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Indexhibit 2 Importer Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Indexhibit 2 Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
13
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
4
External Requests
2
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

41% escaped22 total outputs
Attack Surface

Indexhibit 2 Importer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitindexhibit2-importer.php:636
Maintenance & Trust

Indexhibit 2 Importer Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedUnknown
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Indexhibit 2 Importer Developer Profile

leemon

3 plugins · 600 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Indexhibit 2 Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/indexhibit2-importer/css/style.css
Script Paths
/wp-content/plugins/indexhibit2-importer/js/script.js
Version Parameters
indexhibit2-importer/css/style.css?ver=indexhibit2-importer/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrapnarrowform-table
Data Attributes
data-ix2-dbdata-ix2-userdata-ix2-passdata-ix2-hostdata-ix2-prefixdata-ix2-url
JS Globals
Ix2_Import
FAQ

Frequently Asked Questions about Indexhibit 2 Importer