Import Kyero Feed Security & Risk Analysis

wordpress.org/plugins/import-kyero-feed

Import Easy Real Estate properties and images from a kyero feed.

10 active installs v0.1 PHP 5.6+ WP 5.2+ Updated Jun 1, 2023
importerkyero
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Import Kyero Feed Safe to Use in 2026?

Generally Safe

Score 85/100

Import Kyero Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "import-kyero-feed" plugin v0.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by consistently using prepared statements for SQL queries and a high percentage of properly escaped outputs. The absence of dangerous functions, known vulnerabilities, and a limited attack surface are all positive indicators. However, there are areas that warrant attention. The presence of unsanitized paths in two taint flows, even without critical or high severity ratings, suggests a potential for path traversal or file manipulation vulnerabilities if not carefully handled downstream. Furthermore, the plugin performs file operations and external HTTP requests, which, while not inherently insecure, are common vectors for vulnerabilities if not implemented with robust error handling and input validation.

The vulnerability history is remarkably clean, with no recorded CVEs. This suggests a lack of publicly disclosed security flaws, which is a positive sign for a plugin's maturity and security development lifecycle. However, it's important to note that the plugin is at a very early version (0.1), and a lack of historical vulnerabilities does not guarantee future security. The limited capabilities checked (only one check found) and the limited number of nonce checks (two found) on specific actions could be areas for improvement to further harden the plugin against potential attacks. Overall, the plugin shows promise with its secure coding fundamentals, but the taint analysis findings and the limited checks suggest that further scrutiny and refinement are necessary to ensure comprehensive security.

Key Concerns

  • Unsanitized paths in taint flows
  • File operations present
  • External HTTP requests present
  • Limited capability checks
  • Low version number (0.1)
Vulnerabilities
None known

Import Kyero Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Import Kyero Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
14
70 escaped
Nonce Checks
2
Capability Checks
1
File Operations
10
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

83% escaped84 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
dispatch (class-kyero-import.php:46)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Import Kyero Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterimport_post_meta_keyclass-kyero-import.php:100
filterhttp_request_timeoutclass-kyero-import.php:101
actionadmin_initkyero-importer.php:54
actionimport_kyero_urlkyero-importer.php:61
filterwp_import_post_metakyero-importer.php:75
filterwp_import_existing_postkyero-importer.php:81

Scheduled Events 1

importer_scheduled_cleanup
Maintenance & Trust

Import Kyero Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJun 1, 2023
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Import Kyero Feed Developer Profile

Grimace of Despair

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Import Kyero Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/import-kyero-feed/js/import.js

HTML / DOM Fingerprints

JS Globals
import_kyero_feed_vars
FAQ

Frequently Asked Questions about Import Kyero Feed