IntenseDebate XML Importer (Blogger to WordPress) Security & Risk Analysis

wordpress.org/plugins/intensedebate-xml-importer-blogger-to-wordpress

Import all comments from Blogger Intense Debate account to WordPress.

10 active installs v1.0.5 PHP + WP 2.8+ Updated Aug 13, 2010
bloggerimportimporterintense-debate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is IntenseDebate XML Importer (Blogger to WordPress) Safe to Use in 2026?

Generally Safe

Score 85/100

IntenseDebate XML Importer (Blogger to WordPress) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The security posture of the "intensedebate-xml-importer-blogger-to-wordpress" plugin v1.0.5 appears to be relatively strong based on the provided static analysis. The absence of any known CVEs and the clean vulnerability history suggest a well-maintained or less targeted plugin. Notably, there are no dangerous functions, external HTTP requests, file operations, or raw SQL queries detected, which are common sources of vulnerabilities. The presence of prepared statements for all SQL queries is a significant positive security practice.

However, a major concern is the extremely low rate of proper output escaping (7%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or data processed by the plugin could be outputted to the browser without adequate sanitization, potentially allowing malicious scripts to execute. While the attack surface is reported as zero entry points, this could be misleading if the low escaping rate allows for XSS through other means not explicitly categorized as direct entry points. The lack of capability checks and nonce checks on any potential (even if not explicitly reported) AJAX or REST API handlers also introduces a risk of unauthorized actions if such handlers exist but were not identified.

In conclusion, while the plugin excels in avoiding many common vulnerability vectors and boasts a clean history, the critical lack of proper output escaping presents a significant and immediate security risk. This weakness significantly undermines the overall security of the plugin and should be a primary focus for improvement. The potential for insecure handlers without proper checks further contributes to the risk.

Key Concerns

  • Low output escaping rate (7%)
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

IntenseDebate XML Importer (Blogger to WordPress) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

IntenseDebate XML Importer (Blogger to WordPress) Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

IntenseDebate XML Importer (Blogger to WordPress) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
14
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

7% escaped15 total outputs
Attack Surface

IntenseDebate XML Importer (Blogger to WordPress) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuid_import_blg_wp.php:267
Maintenance & Trust

IntenseDebate XML Importer (Blogger to WordPress) Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedAug 13, 2010
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

IntenseDebate XML Importer (Blogger to WordPress) Developer Profile

Swashata Ghosh

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IntenseDebate XML Importer (Blogger to WordPress)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
intensedebate-xml-importer-blogger-to-wordpress/style.css?ver=intensedebate-xml-importer-blogger-to-wordpress/js/id-xml-importer-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wraperrorfade
HTML Comments
Copyright 2010 Swashata (email : swashata4u@gmail.com) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License, version 2, as published by the Free Software Foundation.+20 more
Data Attributes
id="id_xml"name="id_xml"type="file"id="id_xml_sim"name="id_xml_sim"value="1"+3 more
FAQ

Frequently Asked Questions about IntenseDebate XML Importer (Blogger to WordPress)