
JVH Import Security & Risk Analysis
wordpress.org/plugins/jvh-importImport elements from JVH feed, such as Fluent Forms forms. Used internally within JVH webbouw.
Is JVH Import Safe to Use in 2026?
Generally Safe
Score 85/100JVH Import has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The jvh-import plugin v1.2.3 exhibits a generally strong security posture regarding its attack surface and known vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with protection issues suggests a well-contained design, minimizing external entry points. Furthermore, the plugin has no recorded CVEs, indicating a history of security stability and likely responsible development. The code signals also show a good percentage of output escaping (81%) and no external HTTP requests or bundled libraries, which are positive security indicators.
However, the analysis does reveal some areas for concern. Notably, 100% of the SQL queries are not using prepared statements, posing a significant risk of SQL injection vulnerabilities. This is further highlighted by a taint analysis flow with unsanitized paths, although it's not classified as critical or high severity, it warrants attention. The presence of file operations (8) without clear context from the static analysis also adds a layer of potential risk, as improper handling of file operations can lead to various vulnerabilities.
In conclusion, while jvh-import has a clean vulnerability history and a small attack surface, the lack of prepared statements in SQL queries and the identified unsanitized path flow are critical weaknesses that need immediate remediation. Addressing these specific code concerns will significantly improve the plugin's overall security.
Key Concerns
- SQL queries do not use prepared statements
- Taint analysis flow with unsanitized paths
- No nonce checks detected
- No capability checks detected
JVH Import Security Vulnerabilities
JVH Import Release Timeline
JVH Import Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
JVH Import Attack Surface
WordPress Hooks 6
Maintenance & Trust
JVH Import Maintenance & Trust
Maintenance Signals
Community Trust
JVH Import Alternatives
JVH Easy login
jvh-easy-login
This plugin can only be used by JVH webbouw employees.
JVH Gridbuilder WPBakery VC Element
jvh-gridbuilder-wpbakery-vc-element
This plugin adds a WPBakery (VC) element for WP Gridbuilder.
JVH Woody Snippets helper
jvh-woody-snippets-helper
This plugin extends the Woody Snippets plugin. It will add the ability to add images to snippets and all library snippets will be on one page for easy …
JVH CSS Classes
jvh-css-classes
This plugin adds a new CSS Classes Custom Post Type for WPBakery elements. This let you create classes and apply them on WPBakery elements.
JVH VC Templates Essentials
jvh-vc-templates-essentials
This plugin adds the ability to create custom VC Templates for the Essentials theme.
JVH Import Developer Profile
8 plugins · 470 total installs
How We Detect JVH Import
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jvh-import/assets/js/export-vc-templates.js/wp-content/plugins/jvh-import/assets/css/vc-templates.css/wp-content/plugins/jvh-import/assets/js/export-vc-templates.jsexport-vc-templates.js?ver=1.0.0HTML / DOM Fingerprints
jvh_export_buttonexport_vc_snippetsdata-jvh-import-keyexportData/wp-json/jvh-import/v1/get-css-classes/wp-json/jvh-import/v1/import-css-class