
Pluginer (formerly Instalist) – WP bulk plugin install & migrate Security & Risk Analysis
wordpress.org/plugins/instalistCreate lists of your favourites plugins, export and import them in any new website to install all plugins in the list with just one single click.
Is Pluginer (formerly Instalist) – WP bulk plugin install & migrate Safe to Use in 2026?
Generally Safe
Score 100/100Pluginer (formerly Instalist) – WP bulk plugin install & migrate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "instalist" plugin version 1.3.2 exhibits a significant security concern due to its large attack surface consisting of 13 AJAX handlers, all of which lack authentication checks. While the code generally follows good practices with a high percentage of properly escaped output and the exclusive use of prepared statements for SQL queries, the absence of authorization for nearly all entry points is a major vulnerability. The plugin also shows no history of known CVEs, which is a positive indicator, but this does not mitigate the immediate risks posed by the unprotected AJAX endpoints.
The taint analysis reveals one flow with unsanitized paths, which, although not classified as critical or high severity, warrants attention. This indicates a potential for privilege escalation or other code execution if an attacker can manipulate the input to this specific flow. The presence of 11 nonce checks and 3 capability checks is positive, but these are overshadowed by the fact that the majority of entry points bypass these crucial security mechanisms.
In conclusion, while "instalist" v1.3.2 demonstrates strengths in SQL handling and output escaping, the widespread lack of authentication on its AJAX handlers presents a substantial risk. This makes it highly susceptible to unauthorized actions and potential exploits. The single unsanitized path, although minor in severity based on the provided data, adds another layer of concern.
Key Concerns
- 13 AJAX handlers without auth checks
- Flow with unsanitized paths
Pluginer (formerly Instalist) – WP bulk plugin install & migrate Security Vulnerabilities
Pluginer (formerly Instalist) – WP bulk plugin install & migrate Release Timeline
Pluginer (formerly Instalist) – WP bulk plugin install & migrate Code Analysis
Output Escaping
Data Flow Analysis
Pluginer (formerly Instalist) – WP bulk plugin install & migrate Attack Surface
AJAX Handlers 13
WordPress Hooks 37
Maintenance & Trust
Pluginer (formerly Instalist) – WP bulk plugin install & migrate Maintenance & Trust
Maintenance Signals
Community Trust
Pluginer (formerly Instalist) – WP bulk plugin install & migrate Alternatives
DazeStack Bulk Plugin Manager
dazestack-bulk-plugin-manager
The most beautiful, native Mac-like bulk plugin manager for WordPress. Import, export, and provision plugin stacks in one streamlined workspace.
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
Migrate Guru – Site Migration & Cloning
migrate-guru
Effortlessly migrate, clone, or transfer your WordPress site to over 5,000 web hosts with Migrate Guru, trusted by Cloudways, Pantheon, and Dreamhost.
WP STAGING – WordPress Backup, Restore & Migration
wp-staging
Backup, restore, staging, and migration for WordPress. Create full-site backups and test updates safely. 100% Unit Tested.
Pluginer (formerly Instalist) – WP bulk plugin install & migrate Developer Profile
3 plugins · 1K total installs
How We Detect Pluginer (formerly Instalist) – WP bulk plugin install & migrate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/instalist/admin/js/pluginer-admin.js/wp-content/plugins/instalist/admin/css/pluginer-admin.css/wp-content/plugins/instalist/admin/js/pluginer-admin.jsinstalist/admin/js/pluginer-admin.js?ver=instalist/admin/css/pluginer-admin.css?ver=HTML / DOM Fingerprints
<!-- Check in repo plugins without icon: maybe they have icon in [2x] item --><!-- if user type in the slug give a automatic name --><!-- if activation fails for one fails for all next plugins in the queue --><!-- AGGIUSTARE JAVASCRIPT PER AGGIUNGERE A DIV E NON A TABLE -->+39 morePLUGINER_VERSIONPLUGINER_ADMIN_JS_URLPLUGINER_URL