
Cheritto's Importer Security & Risk Analysis
wordpress.org/plugins/cherittos-importerSafely import posts, comments, pages, categories, tags and more from Wordpress Export files!
Is Cheritto's Importer Safe to Use in 2026?
Generally Safe
Score 92/100Cheritto's Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cherittos-importer' v1.0.1 plugin exhibits a concerning security posture primarily due to a large number of unprotected AJAX handlers. While the absence of known CVEs and critical taint flows is positive, the static analysis reveals significant weaknesses. With 6 out of 7 AJAX handlers lacking authentication checks, there's a substantial attack surface exposed to unauthenticated users. Furthermore, the low percentage of properly escaped output (13%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The significant number of SQL queries (243) with only 30% using prepared statements indicates a potential for SQL injection, especially when combined with the unprotected AJAX endpoints. The plugin also lacks any nonce checks, which is a critical security measure for AJAX operations. The vulnerability history being clean is a positive indicator, but it doesn't mitigate the immediate risks identified in the code analysis. In conclusion, while the plugin doesn't have a history of known vulnerabilities, its current implementation presents significant security concerns due to the lack of proper authentication and sanitization on its entry points.
Key Concerns
- High number of unprotected AJAX handlers
- Low percentage of properly escaped output
- Significant SQL queries without prepared statements
- Missing nonce checks on AJAX
- Low number of capability checks
Cheritto's Importer Security Vulnerabilities
Cheritto's Importer Code Analysis
SQL Query Safety
Output Escaping
Cheritto's Importer Attack Surface
AJAX Handlers 7
WordPress Hooks 5
Maintenance & Trust
Cheritto's Importer Maintenance & Trust
Maintenance Signals
Community Trust
Cheritto's Importer Alternatives
WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress
wp-ultimate-csv-importer
Effortlessly import, export, and migrate your WordPress data with WP Ultimate CSV Importer. This all-in-one solution supports CSV, XML, and Excel file …
WordPress Importer
wordpress-importer
Import posts, pages, comments, custom fields, categories, tags and more from a WordPress export file.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
wp-all-import
Easily import any file of any size into any plugin, post type, custom field, or taxonomy. Supports WooCommerce, ACF, images, galleries, users, real es …
Import and export users and customers
import-users-from-csv-with-meta
Import and export users and customers including user meta, roles, and other. Compatible with many plugins. Do it from the front end or using cron.
Cheritto's Importer Developer Profile
2 plugins · 70 total installs
How We Detect Cheritto's Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cherittos-importer/css/cheritto-wordpress-importer.css/wp-content/plugins/cherittos-importer/js/cheritto-wordpress-importer.js/wp-content/plugins/cherittos-importer/js/cheritto-wordpress-importer.jscheritto-wordpress-importer.css?ver=cheritto-wordpress-importer.js?ver=HTML / DOM Fingerprints
window.addEventListener("load", () => {window.addEventListener("load", () => { var filelist = document.getElementById("filelist"); var uploader = new plupload.Uploader({/wp-ajax-handler/?action=cheritto_wordpress_importer_cancel_job/wp-ajax-handler/?action=cheritto_wordpress_importer_check_files/wp-ajax-handler/?action=cheritto_wordpress_importer_start_download_queue/wp-ajax-handler/?action=cheritto_wordpress_importer_pause_download_queue/wp-ajax-handler/?action=cheritto_wordpress_importer_start_thumbnails_queue/wp-ajax-handler/?action=cheritto_wordpress_importer_pause_thumbnails_queue/wp-ajax-handler/?action=cheritto_wordpress_importer_start_data_import