
Import Excel Security & Risk Analysis
wordpress.org/plugins/import-excelPlugin for import tables (xlsx) in site database
Is Import Excel Safe to Use in 2026?
Generally Safe
Score 85/100Import Excel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'import-excel' plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates a lack of publicly disclosed vulnerabilities, a good number of nonce and capability checks, and no external HTTP requests, suggesting a generally careful development approach regarding common attack vectors. However, the static analysis reveals significant concerns, particularly the presence of the 'unserialize' function, which is inherently dangerous if used with untrusted input. Furthermore, a substantial portion of SQL queries are not prepared, increasing the risk of SQL injection. The taint analysis highlights four high-severity flows with unsanitized paths, indicating potential vulnerabilities where data could be manipulated by attackers to execute unintended code or access sensitive information. The absence of known CVEs is reassuring, but the internal code signals, especially concerning 'unserialize' and SQL practices, warrant a cautious approach.
Key Concerns
- Presence of dangerous function (unserialize)
- High percentage of SQL queries not using prepared statements
- High severity taint flows with unsanitized paths
- Lower percentage of properly escaped output
Import Excel Security Vulnerabilities
Import Excel Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Import Excel Attack Surface
WordPress Hooks 4
Maintenance & Trust
Import Excel Maintenance & Trust
Maintenance Signals
Community Trust
Import Excel Alternatives
TablePress – Tables in WordPress made easy
tablepress
Embed beautiful, accessible, and interactive tables into your WordPress website’s posts and pages, without having to write code!
CSV Importer
csv-importer
Import posts from CSV files into WordPress.
Product Excel Import & Export for WooCommerce
woo-product-excel-importer
WordPress Plugin to Import Products and Export Products for Woocommerce in Bulk with Excel.
Import Content in WordPress & WooCommerce with Excel
content-excel-importer
Import Posts, Pages, Simple Products for WooCommerce & Wordpress with Excel. Migrate Easily. No more CSV Hassle
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light
excel-like-price-change-for-woocommerce-and-wp-e-commerce-light
Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light
Import Excel Developer Profile
1 plugin · 10 total installs
How We Detect Import Excel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-excel/style.css/wp-content/plugins/import-excel/script.js/wp-content/plugins/import-excel/script.jsimport-excel/style.css?ver=import-excel/script.js?ver=HTML / DOM Fingerprints
price_excel_validprice_excel_novalid