Migrate away from Envira Gallery Security & Risk Analysis

wordpress.org/plugins/modula-envira-migrator

Migrate away from Envira is the official migrator from Envira Gallery to Modula Gallery

100 active installs v1.0.0 PHP 5.6+ WP 5.2+ Updated Dec 2, 2025
envira-gallery-migratorgallery-migratormigrate-from-envira-gallerymigrate-to-modula
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Migrate away from Envira Gallery Safe to Use in 2026?

Generally Safe

Score 100/100

Migrate away from Envira Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The modula-envira-migrator plugin v1.0.0 exhibits a generally strong security posture with several good practices in place. The absence of known CVEs and a clean vulnerability history are positive indicators. Furthermore, the plugin demonstrates a commendable use of prepared statements for SQL queries and proper output escaping, with 80% and 90% respectively. Nonce checks are also implemented on the two identified AJAX entry points, and there are no obvious file operations or external HTTP requests that could be exploited.

However, the static analysis did reveal some concerning findings. Specifically, the taint analysis identified two critical severity flows with unsanitized paths. This suggests that there might be ways to inject malicious code or data through user-supplied input that is not adequately cleaned before being processed, potentially leading to arbitrary code execution or other severe impacts. While the overall attack surface is small and all entry points have some form of protection, these critical taint flows represent the most significant immediate risk. The lack of capability checks on AJAX handlers, while not directly leading to a deduction due to the presence of nonces, could be a secondary concern if nonce protections were ever bypassed.

In conclusion, the plugin has built a solid foundation of secure coding practices. The absence of historical vulnerabilities is reassuring. Nevertheless, the critical severity taint flows are a serious red flag that require immediate attention. Addressing these specific unsanitized paths should be the top priority to mitigate potential risks. Future development should also consider implementing capability checks for all AJAX handlers to further harden the plugin's defenses.

Key Concerns

  • Critical taint flow with unsanitized path
  • Critical taint flow with unsanitized path
Vulnerabilities
None known

Migrate away from Envira Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Migrate away from Envira Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
8 prepared
Unescaped Output
3
28 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

80% prepared10 total queries

Output Escaping

90% escaped31 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
envira_gallery_import (includes\class-modula-envira-migrator.php:136)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Migrate away from Envira Gallery Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_modula_importer_envira_gallery_importincludes\class-modula-envira-migrator.php:40
authwp_ajax_modula_importer_envira_gallery_imported_updateincludes\class-modula-envira-migrator.php:41
WordPress Hooks 5
actionadmin_noticesincludes\class-modula-envira-migrator.php:34
filtermodula_migrator_sourcesincludes\class-modula-envira-migrator.php:47
filtermodula_source_galleries_enviraincludes\class-modula-envira-migrator.php:48
filtermodula_g_gallery_enviraincludes\class-modula-envira-migrator.php:49
filtermodula_migrator_images_enviraincludes\class-modula-envira-migrator.php:50
Maintenance & Trust

Migrate away from Envira Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version5.6
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Migrate away from Envira Gallery Developer Profile

WP Chill

29 plugins · 440K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
608 days
View full developer profile
Detection Fingerprints

How We Detect Migrate away from Envira Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/modula-envira-migrator/assets/css/install-lite.css

HTML / DOM Fingerprints

CSS Classes
modula-install-litenotice
Data Attributes
data-action
REST Endpoints
/wp-json/modula-envira-migrator
FAQ

Frequently Asked Questions about Migrate away from Envira Gallery