
Migrate to WordPress.com Security & Risk Analysis
wordpress.org/plugins/wpcom-migrationA WordPress plugin that helps users to migrate their sites to WordPress.com
Is Migrate to WordPress.com Safe to Use in 2026?
Generally Safe
Score 100/100Migrate to WordPress.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpcom-migration plugin v5.88 presents a mixed security posture. On the positive side, it demonstrates good practices by largely utilizing prepared statements for SQL queries and properly escaping output. The absence of known CVEs and recorded vulnerabilities is a strong indicator of a well-maintained codebase in terms of historical security issues. However, the static analysis reveals significant weaknesses that elevate its risk profile. The presence of two AJAX handlers without any authentication checks creates a direct and exploitable attack surface. The complete lack of nonce checks, combined with these unprotected AJAX endpoints, is particularly concerning and opens the door for potential Cross-Site Request Forgery (CSRF) attacks or unauthorized actions by unauthenticated users. While no critical taint flows were detected, the unprotected entry points remain a substantial concern that overshadows the plugin's other positive attributes.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks
Migrate to WordPress.com Security Vulnerabilities
Migrate to WordPress.com Code Analysis
SQL Query Safety
Output Escaping
Migrate to WordPress.com Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Migrate to WordPress.com Maintenance & Trust
Maintenance Signals
Community Trust
Migrate to WordPress.com Alternatives
Transferito: WP Migration
transferito
The easiest 1-Click WordPress Migration plugin that will migrate, clone, transfer and move your WordPress site to any host in seconds.
Migrate Guru – Site Migration & Cloning
migrate-guru
Effortlessly migrate, clone, or transfer your WordPress site to over 5,000 web hosts with Migrate Guru, trusted by Cloudways, Pantheon, and Dreamhost.
W2S – Migrate WooCommerce to Shopify
w2s-migrate-woo-to-shopify
Migrate all products and categories from WooCommerce to Shopify
SitePush
sitepush
Easily move content and code between WordPress sites. Pull your site's DB to a dev site, push new code to a staging site, etc.
Migratico Lite
migratico-lite
The simple and reliable WordPress migration plugin. Quickly backup, migrate, copy, move, or clone your site from one location to another.
Migrate to WordPress.com Developer Profile
213 plugins · 19.2M total installs
How We Detect Migrate to WordPress.com
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcom-migration/asset/js/wpcom-migration-admin.js/wp-content/plugins/wpcom-migration/asset/css/wpcom-migration-admin.css/wp-content/plugins/wpcom-migration/asset/js/wpcom-migration-admin.jswpcom-migration/asset/js/wpcom-migration-admin.js?ver=wpcom-migration/asset/css/wpcom-migration-admin.css?ver=HTML / DOM Fingerprints
wpcom-migration-admin-wrapperwpcom-migration-admin-pageCopyright 2017 Migrate to WordPress.com (email : support@blogvault.net)This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+3 moredata-wpcom-migration-noncewindow.wpcomMigrationAdminConfigvar WPCOM_MIGRATION_AJAX_URLvar WPCOM_MIGRATION_NONCE/wp-json/wpcom-migration/v1/migrate