LJ comments import: reloaded Security & Risk Analysis

wordpress.org/plugins/lj-comments-import-reloaded

Automatically synchronizes comments from Your LiveJournal blog with Your stand-alone Wordpress-based blog.

10 active installs v0.97.1 PHP + WP 2.3+ Updated Mar 3, 2011
commentscrosspostimportlivejournalsynchronize
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LJ comments import: reloaded Safe to Use in 2026?

Generally Safe

Score 85/100

LJ comments import: reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "lj-comments-import-reloaded" plugin version 0.97.1 presents a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded for this plugin, and the static analysis indicates a limited attack surface with no direct entry points for malicious users like AJAX handlers, REST API routes, or shortcodes. Furthermore, all SQL queries appear to be properly prepared, mitigating risks of SQL injection. However, a significant concern arises from the output escaping analysis, where 100% of outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also revealed one flow with unsanitized paths, which, while not classified as critical or high, still warrants attention and investigation as it could potentially lead to unexpected behavior or security issues if exploited. The absence of nonce and capability checks on any identified entry points, though the entry points are zero, suggests a potential lack of robust security implementation in areas that might be added in future updates or that are not directly exposed by the current version. This plugin's strengths lie in its lack of known vulnerabilities and its secure database interactions, but the unescaped output is a critical weakness that needs immediate remediation.

Key Concerns

  • 0% of outputs are properly escaped
  • 1 flow with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

LJ comments import: reloaded Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LJ comments import: reloaded Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

LJ comments import: reloaded Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<lj_comments_import_js> (lj_comments_import_js.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LJ comments import: reloaded Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

LJ comments import: reloaded Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedMar 3, 2011
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

LJ comments import: reloaded Developer Profile

etspring

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LJ comments import: reloaded

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lj-comments-import-reloaded/lj_comments_import_js.php
Script Paths
/wp-content/plugins/lj-comments-import-reloaded/lj_comments_import_js.php

HTML / DOM Fingerprints

HTML Comments
<!-- Added by LJ Comments Import plugin -->
JS Globals
lj_comments_call_sync
FAQ

Frequently Asked Questions about LJ comments import: reloaded