
UnfoldWP Import Companion Security & Risk Analysis
wordpress.org/plugins/unfoldwp-import-companionUnfoldWP Import Companion eases the process of one click importing starter templates for UnfoldWP themes. Needs One Click Demo Import to work.
Is UnfoldWP Import Companion Safe to Use in 2026?
Generally Safe
Score 92/100UnfoldWP Import Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'unfoldwp-import-companion' plugin version 1.2.7 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, unsanitized taint flows, raw SQL queries, and the proper handling of all output through escaping are significant strengths. The plugin also demonstrates good practices by performing all SQL queries using prepared statements and avoiding file operations. The presence of a single external HTTP request warrants careful review but is not inherently a vulnerability. Furthermore, the lack of any recorded vulnerabilities, critical or otherwise, indicates a history of secure development or diligent patching by the developers.
However, the static analysis reveals a complete lack of nonces and capability checks across all entry points. While the current analysis reports zero unprotected entry points, this absence of security controls is a significant concern. If new entry points are introduced or the current ones are ever exposed without proper authentication or authorization, it could lead to severe security flaws. The plugin also has no recorded vulnerabilities, which is positive, but it's important to recognize that this could also be due to limited exposure or testing. The single external HTTP request should be monitored for potential issues related to data transmission or server-side request forgery if it interacts with user-supplied data.
In conclusion, 'unfoldwp-import-companion' v1.2.7 has excellent foundations in secure coding practices concerning data handling and SQL injection prevention. Its vulnerability history is clean, which is a major positive. The primary weakness lies in the complete absence of nonce and capability checks, creating a potential security gap that needs addressing to achieve a truly robust security profile. The single external HTTP request is a minor point of attention.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- Single external HTTP request
UnfoldWP Import Companion Security Vulnerabilities
UnfoldWP Import Companion Code Analysis
Output Escaping
UnfoldWP Import Companion Attack Surface
WordPress Hooks 14
Maintenance & Trust
UnfoldWP Import Companion Maintenance & Trust
Maintenance Signals
Community Trust
UnfoldWP Import Companion Alternatives
Advanced Import: One-Click Demo Import for WordPress
advanced-import
Advanced Import simplifies importing demo data for WordPress sites, enabling users to import posts, pages, media, widgets, customizer settings, and Gu …
ThemeinWP Import Companion
themeinwp-import-companion
The plugin simply store data to import.
Demo Importer Companion
demo-importer-companion
A powerful tool designed to streamline and enhance the process of importing and setting up demo content for your WordPress website.
Keon Toolset
keon-toolset
Import dummy data for themes developed by Keon Themes.
Ibtana – WordPress Website Builder
ibtana-visual-editor
Build your dream WordPress website with Ibtana, a powerful website builder with customizable templates and drag-and-drop elements for customization.
UnfoldWP Import Companion Developer Profile
21 plugins · 4K total installs
How We Detect UnfoldWP Import Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unfoldwp-import-companion/assets/css/uf-import-companion.css/wp-content/plugins/unfoldwp-import-companion/assets/js/uf-import-companion.js/wp-content/plugins/unfoldwp-import-companion/assets/js/uf-import-companion.jsunfoldwp-import-companion/assets/css/uf-import-companion.css?ver=unfoldwp-import-companion/assets/js/uf-import-companion.js?ver=HTML / DOM Fingerprints
uf-companion<!-- Require One Click Demo Import Plugin -->UF_IC_VERSIONUF_IC_URLUF_IC_DIR