
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@datocms/cli-plugin-wordpress
Advanced tools
DatoCMS CLI plugin to import a WordPress site into a DatoCMS project.
npm install -g datocms
datocms plugins:install @datocms/cli-plugin-wordpress
datocms wordpress:import --help
@datocms/cli-plugin-wordpress wordpress:importImports a WordPress site into a DatoCMS project
USAGE
$ @datocms/cli-plugin-wordpress wordpress:import --wp-username <value> --wp-password <value> [--json] [--config-file
<value>] [--profile <value>] [--api-token <value>] [--log-level NONE|BASIC|BODY|BODY_AND_HEADERS] [--log-mode
stdout|file|directory] [--wp-json-api-url <value> | --wp-url <value>] [--autoconfirm] [--ignore-errors]
[--concurrency <value>]
FLAGS
--autoconfirm Automatically enters the affirmative response to all confirmation prompts, enabling the
command to execute without waiting for user confirmation. Forces the destroy of existing
"wp_*" models.
--concurrency=<value> [default: 15] Maximum number of operations to be run concurrently
--ignore-errors Try to ignore errors encountered during import
--wp-json-api-url=<value> The endpoint for your WordPress install (ex. https://www.wordpress-website.com/wp-json)
--wp-password=<value> (required) WordPress password
--wp-url=<value> A URL within a WordPress REST API-enabled site (ex. https://www.wordpress-website.com)
--wp-username=<value> (required) WordPress username
GLOBAL FLAGS
--api-token=<value> Specify a custom API key to access a DatoCMS project
--config-file=<value> [default: ./datocms.config.json, env: DATOCMS_CONFIG_FILE] Specify a custom config file path
--json Format output as json.
--log-level=<option> Level of logging for performed API calls
<options: NONE|BASIC|BODY|BODY_AND_HEADERS>
--log-mode=<option> Where logged output should be written to
<options: stdout|file|directory>
--profile=<value> [env: DATOCMS_PROFILE] Use settings of profile in datocms.config.js
DESCRIPTION
Imports a WordPress site into a DatoCMS project
See code: lib/commands/wordpress/import.js
Tests require a working WordPress instance with specific data in it, and will import content in a newly created DatoCMS project.
You can launch the WP instance with:
docker compose up
You can then run tests with:
npm test
To save a new dump:
docker compose exec db mysqldump -uwordpress -pwordpress wordpress > wp_test_data/mysql/dump.sql
FAQs
DatoCMS CLI plugin to import WordPress sites
We found that @datocms/cli-plugin-wordpress demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.