Replies Importer for Mastodon Security & Risk Analysis

wordpress.org/plugins/replies-importer-for-mastodon

Import replies from your Mastodon posts linking to your WordPress site as comments.

10 active installs v0.0.1 PHP 7.2+ WP 5.0+ Updated Jan 15, 2025
commentsimportmastodonsocial-media
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Replies Importer for Mastodon Safe to Use in 2026?

Generally Safe

Score 92/100

Replies Importer for Mastodon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'replies-importer-for-mastodon' plugin v0.0.1 demonstrates a generally good security posture based on the provided static analysis. It boasts no known vulnerabilities, zero critical or high-severity taint flows, and no dangerous functions are used. The plugin also utilizes prepared statements for all its SQL queries and implements nonce checks where appropriate. However, a significant concern is the complete absence of capability checks for any of its functionalities. This means that any user, regardless of their WordPress role, could potentially trigger the cron events, which could lead to unintended or malicious actions if these events are not inherently benign.

Furthermore, while output escaping is generally well-handled, there are a few instances where it's not applied, which could theoretically open the door to XSS vulnerabilities in specific scenarios, especially considering the plugin's interaction with external data through HTTP requests. The plugin makes a notable number of external HTTP requests (7), and the security of these interactions, especially concerning data validation and sanitization of responses, is not explicitly detailed in the provided metrics. Given the plugin is at version 0.0.1, it's also possible that this is an early stage of development, and further security hardening will be implemented. The lack of a comprehensive attack surface (0 entry points) is positive, but the absence of capability checks on the 2 cron events is a notable weakness that needs attention.

Key Concerns

  • No capability checks on cron events
  • Minor output escaping issues
Vulnerabilities
None known

Replies Importer for Mastodon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Replies Importer for Mastodon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
13 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
7
Bundled Libraries
0

Output Escaping

93% escaped14 total outputs
Attack Surface

Replies Importer for Mastodon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuincludes\admin-functions.php:20
actionadmin_initincludes\admin-functions.php:21
actionadmin_initincludes\admin-functions.php:22
actionreplies_importer_for_mastodon_eventincludes\api-functions.php:17
actionplugins_loadedreplies-importer-for-mastodon.php:37

Scheduled Events 2

replies_importer_for_mastodon_event
replies_importer_for_mastodon_event
Maintenance & Trust

Replies Importer for Mastodon Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 15, 2025
PHP min version7.2
Downloads457

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Replies Importer for Mastodon Developer Profile

Donncha O Caoimh (a11n)

12 plugins · 32K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
4657 days
View full developer profile
Detection Fingerprints

How We Detect Replies Importer for Mastodon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/replies-importer-for-mastodon/includes/debug.php/wp-content/plugins/replies-importer-for-mastodon/includes/config.php/wp-content/plugins/replies-importer-for-mastodon/includes/admin-functions.php/wp-content/plugins/replies-importer-for-mastodon/includes/api-functions.php
Version Parameters
replies-importer-for-mastodon/includes/debug.php?ver=0.0.1replies-importer-for-mastodon/includes/config.php?ver=0.0.1replies-importer-for-mastodon/includes/admin-functions.php?ver=0.0.1replies-importer-for-mastodon/includes/api-functions.php?ver=0.0.1

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Replies Importer for Mastodon