
Moving Contents Security & Risk Analysis
wordpress.org/plugins/moving-contentsSupports the transfer of Contents between servers.
Is Moving Contents Safe to Use in 2026?
Generally Safe
Score 100/100Moving Contents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "moving-contents" plugin v1.13 presents a seemingly strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unescaped output, file operations, external HTTP requests, or taint flows suggests a well-written codebase with good practices for input sanitization and output encoding. Furthermore, the plugin's limited attack surface, with zero identified entry points for AJAX, REST API, shortcodes, or cron events, significantly reduces its potential for exploitation.
The vulnerability history is also exceptionally clean, with no recorded CVEs, which is a positive indicator. This lack of past vulnerabilities, combined with the current analysis, suggests a plugin that has historically been maintained with security in mind. However, a notable concern is the presence of a single SQL query that is not using prepared statements. While the attack surface is minimal, this unparameterized query, if ever exposed to user input in a future update or if the attack surface is misreported, could become a vector for SQL injection.
In conclusion, the "moving-contents" plugin v1.13 demonstrates good security development practices, particularly in its minimal attack surface and diligent output escaping. The lack of historical vulnerabilities is a strong positive. The primary weakness lies in the single, unparameterized SQL query, which, despite the current lack of exploitable context, is a deviation from best practices and should be addressed.
Key Concerns
- SQL query not using prepared statements
Moving Contents Security Vulnerabilities
Moving Contents Release Timeline
Moving Contents Code Analysis
SQL Query Safety
Moving Contents Attack Surface
Maintenance & Trust
Moving Contents Maintenance & Trust
Maintenance Signals
Community Trust
Moving Contents Alternatives
Smart Bulk Delete & Content Cleaner for WordPress
smart-bulk-content-remover
Safely bulk delete posts, pages, media, and comments with flexible filters and a clean interface.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Bulk Datetime Change
bulk-datetime-change
Bulk change date/time for posts.
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
Simple Menu Order Column
simple-menu-order-column
Expose menu order column on your dashboard listings.
Moving Contents Developer Profile
54 plugins · 56K total installs
How We Detect Moving Contents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/moving-contents/assets/js/scripts.js/wp-content/plugins/moving-contents/assets/css/styles.css/wp-content/plugins/moving-contents/assets/js/scripts.jsmoving-contents/assets/js/scripts.js?ver=moving-contents/assets/css/styles.css?ver=HTML / DOM Fingerprints
moving-contents-wrappermc-content-block<!-- Start Moving Contents Widget --><!-- End Moving Contents Widget -->data-moving-content-iddata-moving-content-targetmovingContentsGlobal[moving_contents][moving_contents_widget]