
Substack Importer Security & Risk Analysis
wordpress.org/plugins/substack-importerThe Substack Importer allows you to import content from a Substack newsletter into your WordPress site.
Is Substack Importer Safe to Use in 2026?
Generally Safe
Score 92/100Substack Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The substack-importer plugin version 1.1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, has no known CVEs, and includes nonce and capability checks for at least one entry point. However, significant concerns arise from the attack surface analysis. The plugin has one AJAX handler that lacks authentication checks, making it a potential entry point for unauthorized actions. Furthermore, the taint analysis reveals two flows with unsanitized paths, although these are not categorized as critical or high severity. The lack of proper escaping for 60% of output also presents a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting diligent maintenance, but it does not negate the current risks identified in the code analysis.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- Insufficient output escaping
Substack Importer Security Vulnerabilities
Substack Importer Code Analysis
Output Escaping
Data Flow Analysis
Substack Importer Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Scheduled Events 1
Maintenance & Trust
Substack Importer Maintenance & Trust
Maintenance Signals
Community Trust
Substack Importer Alternatives
WordPress Importer
wordpress-importer
Import posts, pages, comments, custom fields, categories, tags and more from a WordPress export file.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
Import and export users and customers
import-users-from-csv-with-meta
Import and export users and customers including user meta, roles, and other. Compatible with many plugins. Do it from the front end or using cron.
Starter Templates & Sites Pack by ThemeGrill
themegrill-demo-importer
Premium starter sites and website templates by ThemeGrill. Import demo content, widgets, and theme settings with one click.
Blogger Importer
blogger-importer
Imports posts, images, comments, and categories (blogger tags) from a Blogger blog then migrates authors to WordPress users.
Substack Importer Developer Profile
34 plugins · 14.9M total installs
How We Detect Substack Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/substack-importer/css/index.css/wp-content/plugins/substack-importer/js/index.js/wp-content/plugins/substack-importer/js/index.jssubstack-importer/js/index.js?ver=substack-importer/css/index.css?ver=