Airi Demo Importer Security & Risk Analysis

wordpress.org/plugins/airi-demo-importer

Registers custom post types and custom fields for the Sydney theme

1K active installs v1.0.3 PHP 5.2.4+ WP 4.0+ Updated Jun 23, 2020
demo-content
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Airi Demo Importer Safe to Use in 2026?

Generally Safe

Score 85/100

Airi Demo Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the 'airi-demo-importer' plugin version 1.0.3 appears to have a very strong security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals are all positive, indicating no dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. The lack of file operations, external HTTP requests, nonce checks, and capability checks, while potentially indicating a lack of complex functionality, also means there are fewer avenues for attack if these features are not core to the plugin's purpose.

The taint analysis reveals no flows with unsanitized paths, further reinforcing the impression of secure coding practices. The vulnerability history being entirely clear of any CVEs, across all severity levels and types, suggests a history of diligent security maintenance or a lack of discovered vulnerabilities over time. This combination of a minimal attack surface, robust internal code security, and a clean vulnerability record points to a plugin that is currently very secure. However, the complete lack of certain security mechanisms like nonce and capability checks might suggest a plugin that is very simplistic in its functionality or relies entirely on external mechanisms for security, which could be a concern if its intended use case involves more complex interactions.

Vulnerabilities
None known

Airi Demo Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Airi Demo Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Airi Demo Importer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterpt-ocdi/import_filesairi-demo-importer.php:58
actionpt-ocdi/after_importairi-demo-importer.php:84
filterpt-ocdi/disable_pt_brandingairi-demo-importer.php:89
Maintenance & Trust

Airi Demo Importer Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 23, 2020
PHP min version5.2.4
Downloads51K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

Airi Demo Importer Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect Airi Demo Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/airi-demo-importer/demo-content/airi-dc-agency.xml/wp-content/plugins/airi-demo-importer/demo-content/airi-dc-startup.xml/wp-content/plugins/airi-demo-importer/demo-content/airi-dc-business2.xml/wp-content/plugins/airi-demo-importer/demo-content/airi-dc-health.xml/wp-content/plugins/airi-demo-importer/demo-content/airi-dc-lawyer.xml/wp-content/plugins/airi-demo-importer/demo-content/airi-dc-photography.xml/wp-content/plugins/airi-demo-importer/demo-content/airi-w-agency.wie/wp-content/plugins/airi-demo-importer/demo-content/airi-w-startup.wie+16 more

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Airi Demo Importer