
REST API Posts Importer Security & Risk Analysis
wordpress.org/plugins/rest-api-posts-importerImport posts from any WordPress site's REST API with categories, tags, and featured images.
Is REST API Posts Importer Safe to Use in 2026?
Generally Safe
Score 100/100REST API Posts Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rest-api-posts-importer" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. It impressively utilizes prepared statements for all SQL queries and correctly escapes all identified outputs, mitigating common vulnerabilities like SQL injection and cross-site scripting. The absence of known CVEs and a clean vulnerability history further contribute to its good standing. The plugin also incorporates a nonce check, indicating an awareness of typical WordPress security practices.
However, there are a few areas that warrant attention. The presence of three "flows with unsanitized paths" in the taint analysis, despite being categorized as low severity, suggests potential areas where user-supplied data might not be adequately validated or sanitized before being used in certain operations. Furthermore, the plugin performs an external HTTP request, which, if not implemented carefully, could expose the site to risks such as SSRF attacks if the target URL is controllable by an unauthenticated user or is not properly validated.
Overall, the plugin is well-constructed with robust defense mechanisms for SQL and output handling. The primary areas for improvement lie in ensuring thorough sanitization for all data flows and careful management of external HTTP requests. The lack of any recorded vulnerabilities in its history is a positive indicator of its current stability and developer diligence.
Key Concerns
- Flows with unsanitized paths (3)
- External HTTP requests (1)
REST API Posts Importer Security Vulnerabilities
REST API Posts Importer Release Timeline
REST API Posts Importer Code Analysis
Output Escaping
Data Flow Analysis
REST API Posts Importer Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
REST API Posts Importer Maintenance & Trust
Maintenance Signals
Community Trust
REST API Posts Importer Alternatives
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies
postpage-import-export-with-custom-fields-taxonomies
Export and import WordPress posts & pages as JSON files with full support for custom fields, taxonomies, ACF fields, and featured images.
Armandi Content Sync
armandi-content-sync
Import published posts from another WordPress site using the REST API or a standard WordPress export XML file.
AutoFetch Content Migration
autofetch-content-migration
Migrate posts, pages, custom post types, images, categories, and tags from one WordPress site to another via the WordPress REST API.
Own Your Memories
own-your-memories
Import posts and media from an Instagram "Download Your Information" ZIP export into WordPress — with full control over how your content lands.
Post & Page Migrator
post-page-migrator
Easily migrate posts and pages from this site to another target WordPress site using the WP REST API.
REST API Posts Importer Developer Profile
3 plugins · 10 total installs
How We Detect REST API Posts Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rest-api-posts-importer/assets/css/plugin.css/wp-content/plugins/rest-api-posts-importer/assets/js/plugin.js/wp-content/plugins/rest-api-posts-importer/assets/js/plugin.jsrest-api-posts-importer/assets/css/plugin.css?ver=1.1.0rest-api-posts-importer/assets/js/plugin.js?ver=1.1.0HTML / DOM Fingerprints
restapipoImporterAjaxObj/wp-json/wp/v2/posts//wp-json/wp/v2/categories//wp-json/wp/v2/tags/