Moving Users Security & Risk Analysis

wordpress.org/plugins/moving-users

Supports the transfer of Users between servers.

50 active installs v1.11 PHP 8.0+ WP 4.6+ Updated Nov 25, 2025
movinguserusers
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 16, 2025
Safety Verdict

Is Moving Users Safe to Use in 2026?

Generally Safe

Score 99/100

Moving Users has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 16, 2025Updated 4mo ago
Risk Assessment

The static analysis for the "moving-users" plugin v1.11 reveals a generally good security posture concerning its direct attack surface and output handling. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly minimizing the plugin's exposure points. Furthermore, all identified output operations are properly escaped, and no dangerous functions, file operations, or external HTTP requests were detected. The absence of taint analysis issues is also a positive sign, indicating no immediate concerns with unsanitized data flows within the analyzed code.

However, the plugin's vulnerability history is a significant concern. With one known medium-severity CVE categorized as 'Exposure of Sensitive Information to an Unauthorized Actor', even though it's currently patched, it highlights a past weakness in how sensitive information was handled. The fact that this is the *only* vulnerability but of this nature suggests a potential blind spot in the plugin's security, particularly around data protection. The absence of any capability checks or nonce checks in the code analysis, combined with the past sensitive information exposure, raises a flag about the robustness of authorization and session validation, even if the current attack surface is small.

In conclusion, while the current version of "moving-users" v1.11 demonstrates strong adherence to secure coding practices for its visible attack surface and output handling, the historical vulnerability regarding sensitive information exposure, coupled with the lack of explicit capability and nonce checks, warrants caution. This indicates that while the immediate risks may be low due to the limited entry points, the plugin's underlying mechanisms for data protection and authorization might not be as robust as desired, suggesting a moderate overall risk. It's crucial for users to remain vigilant and ensure the plugin is always updated to the latest version to benefit from past vulnerability fixes.

Key Concerns

  • One medium CVE for sensitive info exposure
  • No nonce checks on entry points
  • No capability checks on entry points
  • 1 SQL query not using prepared statements
Vulnerabilities
1

Moving Users Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12637medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Moving Users <= 1.05 - Unauthenticated Sensitive Information Exposure

Jan 16, 2025 Patched in 1.10 (1d)
Code Analysis
Analyzed Mar 16, 2026

Moving Users Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries
Attack Surface

Moving Users Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Moving Users Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 25, 2025
PHP min version8.0
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Moving Users Developer Profile

Katsushi Kawamori

52 plugins · 56K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
190 days
View full developer profile
Detection Fingerprints

How We Detect Moving Users

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/moving-users/asset/css/moving-users.css/wp-content/plugins/moving-users/asset/js/moving-users.js/wp-content/plugins/moving-users/asset/js/moving-users-admin.js
Script Paths
/wp-content/plugins/moving-users/asset/js/moving-users.js/wp-content/plugins/moving-users/asset/js/moving-users-admin.js
Version Parameters
moving-users/asset/css/moving-users.css?ver=moving-users/asset/js/moving-users.js?ver=moving-users/asset/js/moving-users-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
moving-users-wrapmoving-users-notice
Data Attributes
data-movingusers-id
FAQ

Frequently Asked Questions about Moving Users