Novex Demo Importer Security & Risk Analysis

wordpress.org/plugins/novex-demo-importer

One click demo import for Novex themes — instantly import free & premium Elementor sites to launch a fully designed WordPress site in seconds.

0 active installs v0.0.2 PHP 7.4+ WP 5.6+ Updated Feb 25, 2026
demo-contentdemo-importerelementorone-click-importstarter-sites
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Novex Demo Importer Safe to Use in 2026?

Generally Safe

Score 100/100

Novex Demo Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The novex-demo-importer plugin, version 0.0.2, demonstrates a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers, appear to have appropriate authentication and capability checks, mitigating direct unauthorized access. The code also shows excellent practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of properly escaped output, which significantly reduces the risk of SQL injection and cross-site scripting (XSS) vulnerabilities respectively. The absence of any recorded CVEs further reinforces the plugin's current security standing, suggesting a history of stable and secure development.

However, a few minor areas warrant attention. While the attack surface is small and currently protected, any future additions without adequate checks could introduce risk. The presence of file operations and external HTTP requests, even if not flagged as problematic in the static analysis, are potential areas where vulnerabilities could arise if not meticulously handled. The plugin's limited scope and lack of historical vulnerabilities are positive indicators, but continuous vigilance is always recommended for any active plugin. Overall, the plugin appears to be well-secured, with no immediate critical threats identified.

Key Concerns

  • Potential for future insecure additions to attack surface
  • File operations present, require careful handling
  • External HTTP requests present, require careful handling
Vulnerabilities
None known

Novex Demo Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Novex Demo Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
2
33 escaped
Nonce Checks
4
Capability Checks
4
File Operations
1
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

94% escaped35 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ajax_verify_license (novex-demo-importer.php:379)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Novex Demo Importer Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_novex_demo_importer_verify_licensenovex-demo-importer.php:109
authwp_ajax_novex_demo_importer_deactivate_licensenovex-demo-importer.php:110
authwp_ajax_novex_demo_importer_install_pluginsnovex-demo-importer.php:111
authwp_ajax_novex_demo_importer_run_importnovex-demo-importer.php:112
WordPress Hooks 10
actionadmin_initnovex-demo-importer.php:103
actionadmin_menunovex-demo-importer.php:104
actionadmin_headnovex-demo-importer.php:105
actionadmin_enqueue_scriptsnovex-demo-importer.php:106
actionadmin_noticesnovex-demo-importer.php:107
filterupload_mimesnovex-demo-importer.php:114
filterwp_check_filetype_and_extnovex-demo-importer.php:115
filterwp_import_existing_postnovex-demo-importer.php:937
filterwp_import_post_existsnovex-demo-importer.php:938
filterwp_import_post_data_rawnovex-demo-importer.php:941
Maintenance & Trust

Novex Demo Importer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 25, 2026
PHP min version7.4
Downloads161

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Novex Demo Importer Developer Profile

novexthemes

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Novex Demo Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/novex-demo-importer/assets/img/admin-icon.svg/wp-content/plugins/novex-demo-importer/assets/js/admin.js/wp-content/plugins/novex-demo-importer/assets/css/admin.css
Script Paths
/wp-content/plugins/novex-demo-importer/assets/js/admin.js
Version Parameters
novex-demo-importer/assets/js/admin.js?ver=novex-demo-importer/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
novex-demo-importer-admin-wrap
Data Attributes
data-slug="novex-demo-importer"data-ajaxurl="admin-ajax.php"data-nonce="novex_demo_importer_nonce"
JS Globals
NovexDemoImporterData
FAQ

Frequently Asked Questions about Novex Demo Importer