
Delicious XML Importer Security & Risk Analysis
wordpress.org/plugins/delicious-xml-importerLets you import your Delicious bookmarks into WordPress as links, posts, or a custom post type.
Is Delicious XML Importer Safe to Use in 2026?
Generally Safe
Score 85/100Delicious XML Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'delicious-xml-importer' v0.4 plugin presents a mixed security posture. On one hand, its static analysis reveals a commendable lack of direct entry points like AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication. The use of prepared statements for all SQL queries and the presence of a nonce check are positive security indicators. However, the plugin has two critical vulnerabilities identified by the use of the `create_function` dangerous PHP function. This function is deprecated and has known security implications, particularly when used with untrusted input, as it can lead to remote code execution. Furthermore, a significant concern is the low percentage of properly escaped outputs (45%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website's output, impacting users or the site's integrity. The absence of recorded vulnerabilities in its history might suggest a lack of historical exploitation or reporting, but it does not negate the immediate risks identified in the code analysis. The plugin's strengths lie in its limited attack surface and safe SQL practices, but the presence of `create_function` and widespread output unescaping are serious weaknesses that require immediate attention.
Key Concerns
- Use of deprecated and dangerous function create_function
- Low percentage of properly escaped outputs (XSS risk)
Delicious XML Importer Security Vulnerabilities
Delicious XML Importer Code Analysis
Dangerous Functions Found
Output Escaping
Delicious XML Importer Attack Surface
WordPress Hooks 1
Maintenance & Trust
Delicious XML Importer Maintenance & Trust
Maintenance Signals
Community Trust
Delicious XML Importer Alternatives
Content Egg – Affiliate Product Importer & Price Comparison
content-egg
Import affiliate products, compare prices, sync to WooCommerce, and auto-generate SEO content with AI — all in one toolkit.
The Social Links
the-social-links
The Social Links plugin adds a widget and shortcode to your WordPress website allowing you to display icons linking to your social profiles.
Blogroll Links
blogroll-links
Display your blogroll links anywhere in posts or pages using a simple shortcode.
Blogroll Widget with RSS Feeds
blogroll-rss-widget
Displays the recent posts of your blogroll links via RSS Feeds in a customizable sidebar widget
Featured Link Image
featured-link-image
Add a meta box in the Links add/edit page for easy uploading/inserting images in your bookmarks.
Delicious XML Importer Developer Profile
16 plugins · 17K total installs
How We Detect Delicious XML Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/delicious-xml-importer/style.css?ver=/wp-content/plugins/delicious-xml-importer/js/delicious-importer.js?ver=HTML / DOM Fingerprints
name="import"name="action"name="bookmarksposts"name="categoriestags"name="custom_field"name="custom_field_name"+1 more<form enctype="multipart/form-data" method="post" action="admin.php?import=delicious&step=1"><label for="upload"><input type="file" id="upload" name="import" size="25" /><label for="bookmarksposts">