
Migrate Guru – Site Migration & Cloning Security & Risk Analysis
wordpress.org/plugins/migrate-guruEffortlessly migrate, clone, or transfer your WordPress site to over 5,000 web hosts with Migrate Guru, trusted by Cloudways, Pantheon, and Dreamhost.
Is Migrate Guru – Site Migration & Cloning Safe to Use in 2026?
Generally Safe
Score 100/100Migrate Guru – Site Migration & Cloning has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'migrate-guru' v6.28 plugin exhibits a mixed security posture. While the absence of known CVEs and a strong percentage of properly escaped outputs and prepared SQL statements are positive indicators, the plugin presents significant risks due to its unprotected entry points. The static analysis reveals a considerable attack surface composed entirely of AJAX handlers that lack authentication checks. This means any user, regardless of their role or privileges, could potentially trigger these functions, leading to unauthorized actions. The taint analysis showing zero flows is a good sign, suggesting that even if an attacker could reach these entry points, there might not be immediate opportunities for critical code execution or data manipulation. However, the lack of nonce checks and capability checks on these AJAX handlers significantly lowers the security bar and represents a fundamental oversight in securing sensitive operations. The plugin's vulnerability history is clean, which is encouraging, but it doesn't negate the current structural weaknesses identified in the code analysis. A balanced conclusion would be that while the plugin may not have a history of exploitable vulnerabilities, its current implementation introduces a high risk of unauthorized access and potential misuse due to its exposed AJAX endpoints. Robust security practices would necessitate immediate implementation of authentication and authorization checks for all AJAX handlers.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- AJAX handlers without capability checks
- Large attack surface without auth
Migrate Guru – Site Migration & Cloning Security Vulnerabilities
Migrate Guru – Site Migration & Cloning Code Analysis
SQL Query Safety
Output Escaping
Migrate Guru – Site Migration & Cloning Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
Migrate Guru – Site Migration & Cloning Maintenance & Trust
Maintenance Signals
Community Trust
Migrate Guru – Site Migration & Cloning Alternatives
Prime Mover – Migrate WordPress Website & Backups
prime-mover
The simplest all-around WordPress migration tool/backup plugin. These support multisite backup/migration or clone WP site/multisite subsite.
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin
everest-backup
Everest Backup is a modern tool that will take care of your website's backups, restoration, migration, and cloning.
WP Synchro – The Ultimate WordPress Migration Tool
wpsynchro
WordPress migration plugin to easily migrate, clone, backup, and synchronize your WordPress site, including database, media, plugins, themes, and file …
Migrate to WordPress.com
wpcom-migration
A WordPress plugin that helps users to migrate their sites to WordPress.com
Transferito: WP Migration
transferito
The easiest 1-Click WordPress Migration plugin that will migrate, clone, transfer and move your WordPress site to any host in seconds.
Migrate Guru – Site Migration & Cloning Developer Profile
1 plugin · 200K total installs
How We Detect Migrate Guru – Site Migration & Cloning
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/migrate-guru/css/custom.css/wp-content/plugins/migrate-guru/css/normalize.css/wp-content/plugins/migrate-guru/css/bootstrap.min.css/wp-content/plugins/migrate-guru/css/bootstrap-theme.min.css/wp-content/plugins/migrate-guru/css/bootstrap-datetimepicker.min.css/wp-content/plugins/migrate-guru/css/font-awesome.min.css/wp-content/plugins/migrate-guru/css/jquery.growl.css/wp-content/plugins/migrate-guru/css/jquery-ui.css+1 more/wp-content/plugins/migrate-guru/js/custom.js/wp-content/plugins/migrate-guru/js/bootstrap.min.js/wp-content/plugins/migrate-guru/js/bootstrap-datetimepicker.js/wp-content/plugins/migrate-guru/js/moment.min.js/wp-content/plugins/migrate-guru/js/jquery.growl.js/wp-content/plugins/migrate-guru/js/jquery-ui.js+1 moremigrate-guru/css/custom.css?ver=migrate-guru/css/normalize.css?ver=migrate-guru/css/bootstrap.min.css?ver=migrate-guru/css/bootstrap-theme.min.css?ver=migrate-guru/css/bootstrap-datetimepicker.min.css?ver=migrate-guru/css/font-awesome.min.css?ver=migrate-guru/css/jquery.growl.css?ver=migrate-guru/css/jquery-ui.css?ver=migrate-guru/css/style.css?ver=migrate-guru/js/custom.js?ver=migrate-guru/js/bootstrap.min.js?ver=migrate-guru/js/bootstrap-datetimepicker.js?ver=migrate-guru/js/moment.min.js?ver=migrate-guru/js/jquery.growl.js?ver=migrate-guru/js/jquery-ui.js?ver=migrate-guru/js/bootstrap-filestyle.min.js?ver=HTML / DOM Fingerprints
mg-input-labelmg-custom-inputmg-login-helpmg-loader-wrappermg-loadermg-alertmg-site-list-tablemg-migrate-button+6 moreCopyright 2017 Migrate GuruThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+6 moredata-targetdata-toggledata-containerdata-contentdata-triggerdata-placement+3 moreMGWPSettingsMGWPSiteInfoMGWPDbMGWPAPIMGInfoMGWPAction+8 more