
MB Toolset Migration Security & Risk Analysis
wordpress.org/plugins/mb-toolset-migrationMigrate custom fields from Toolset to Meta Box.
Is MB Toolset Migration Safe to Use in 2026?
Generally Safe
Score 100/100MB Toolset Migration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mb-toolset-migration" v1.0.7 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates strong secure coding practices regarding database interactions, utilizing prepared statements exclusively for its SQL queries and ensuring all output is properly escaped. The absence of file operations and external HTTP requests also reduces potential attack vectors. Furthermore, there is no recorded vulnerability history, suggesting a generally well-maintained codebase.
However, significant security concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack any authentication checks. This is a critical oversight, as it allows any unauthenticated user to trigger these functionalities, potentially leading to unintended actions or information disclosure. The absence of nonce checks on these AJAX endpoints further exacerbates this risk, as it prevents basic protection against Cross-Site Request Forgery (CSRF) attacks.
In conclusion, while the plugin excels in areas like SQL sanitization and output escaping, the unprotected AJAX endpoints present a substantial and immediate security risk. The lack of any security checks on these entry points is the primary weakness. Until these are properly secured with appropriate authentication and nonce verification, the plugin's overall security posture remains precarious despite its other strengths.
Key Concerns
- Unprotected AJAX handlers present
- Missing nonce checks on AJAX handlers
MB Toolset Migration Security Vulnerabilities
MB Toolset Migration Release Timeline
MB Toolset Migration Code Analysis
SQL Query Safety
Output Escaping
MB Toolset Migration Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
MB Toolset Migration Maintenance & Trust
Maintenance Signals
Community Trust
MB Toolset Migration Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
MB ACF Migration
mb-acf-migration
Migrate custom fields from Advanced Custom Fields to Meta Box.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Sydney Toolbox
sydney-toolbox
Registers custom post types and custom fields for the Sydney theme
Custom Post Types and Custom Fields creator – WCK
wck-custom-fields-and-custom-post-types-creator
A must have tool for creating custom fields, custom post types and taxonomies, fast and without any programming knowledge.
MB Toolset Migration Developer Profile
18 plugins · 84K total installs
How We Detect MB Toolset Migration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mb-toolset-migration/assets/migrate.css/wp-content/plugins/mb-toolset-migration/assets/migrate.js/wp-content/plugins/mb-toolset-migration/assets/migrate.jsmb-toolset-migration/assets/migrate.css?ver=mb-toolset-migration/assets/migrate.js?ver=HTML / DOM Fingerprints
wrapbuttonbutton-primaryid="process"MbTs<div class="wrap"><h1>Toolset Migration</h1><p><button class="button button-primary" id="process">Migrate</button>