WING Website Migrator Security & Risk Analysis

wordpress.org/plugins/wing-migrator

A website migration plugin for ConoHa WING hosting service.

300 active installs v2.0.3 PHP 7.4+ WP 6.2+ Updated Apr 10, 2026
backupmigrationrestorewing
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 30, 2025
Safety Verdict

Is WING Website Migrator Safe to Use in 2026?

Generally Safe

Score 99/100

WING Website Migrator has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 30, 2025Updated 1mo ago
Risk Assessment

The wing-migrator plugin v2.0.3 demonstrates a generally strong security posture with good practices in several key areas. Notably, all SQL queries utilize prepared statements, output escaping is consistently applied, and there are no identified taint flows or unsanitized paths. The absence of a large attack surface, particularly unprotected entry points, is also a positive sign. However, the presence of 'ini_set' and 'set_time_limit' functions raises concerns about potential misuse for resource exhaustion attacks or bypassing server configurations, even though their immediate exploitability isn't detailed in the static analysis. The vulnerability history, while currently showing no unpatched CVEs, indicates a past medium-severity issue, specifically a Cross-Site Request Forgery (CSRF). This suggests that while the current version might be clean, the plugin has had security flaws in the past, warranting continued vigilance and timely updates. The plugin's strengths lie in its sanitization and permission checks, but the use of dangerous functions and historical vulnerability warrant careful consideration.

Key Concerns

  • Presence of dangerous functions (ini_set, set_time_limit)
  • Past medium severity CSRF vulnerability
Vulnerabilities
1 published

WING Website Migrator Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-52835medium · 4.3Cross-Site Request Forgery (CSRF)

WING WordPress Migrator <= 1.2.0 - Cross-Site Request Forgery

Dec 30, 2025 Patched in 2.0.0 (107d)
Version History

WING Website Migrator Release Timeline

v2.0.3Current
v2.0.2
v2.0.1
v2.0.0
v1.2.01 CVE
v1.1.91 CVE
v1.1.81 CVE
v1.1.71 CVE
v1.1.61 CVE
v1.1.51 CVE
v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.11 CVE
v1.0.11 CVE
Code Analysis
Analyzed Apr 16, 2026

WING Website Migrator Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
21 prepared
Unescaped Output
0
2 escaped
Nonce Checks
1
Capability Checks
2
File Operations
35
External Requests
4
Bundled Libraries
0

Dangerous Functions Found

ini_set@ini_set( 'memory_limit', '1024M' );includes/migration-core/Jobs/AbstractJob.php:463
set_time_limit@set_time_limit( 0 );includes/migration-core/Jobs/AbstractJob.php:467

SQL Query Safety

100% prepared21 total queries

Output Escaping

100% escaped2 total outputs
Attack Surface

WING Website Migrator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionrest_api_initwing-migrator.php:56
Maintenance & Trust

WING Website Migrator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 10, 2026
PHP min version7.4
Downloads58K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

WING Website Migrator Developer Profile

ConoHa by GMO

2 plugins · 10K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
604 days
View full developer profile
Detection Fingerprints

How We Detect WING Website Migrator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wing-migrator/assets/css/main.css/wp-content/plugins/wing-migrator/assets/js/main.js
Script Paths
/wp-content/plugins/wing-migrator/assets/js/main.js
Version Parameters
wing-migrator/assets/css/main.css?ver=wing-migrator/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
wing-migrator
HTML Comments
<!-- WING Website Migrator -->
Data Attributes
data-wp-migration-nonce
JS Globals
wingMigration
REST Endpoints
/wp-json/wing_mig/v1/nonce/wp-json/wing_mig/v1/wp-info/wp-json/wing_mig/v1/backup/wp-json/wing_mig/v1/backup/.+/wp-json/wing_mig/v1/backup/.+/log/wp-json/wing_mig/v1/backup/.+/delete/wp-json/wing_mig/v1/restore/wp-json/wing_mig/v1/restore/.+/wp-json/wing_mig/v1/restore/.+/log/wp-json/wing_mig/v1/restore/.+/delete/wp-json/wing_mig/v1/ssl-challenge/wp-json/wing_mig/v1/ssl-challenge/.+
FAQ

Frequently Asked Questions about WING Website Migrator