User Import with meta – WP Ultimate CSV Importer Add-on Security & Risk Analysis

wordpress.org/plugins/import-users

Import and export WordPress and WooCommerce users with full user meta, custom fields, billing & shipping details, and membership data.

5K active installs v1.6 PHP 7.4+ WP 5.0+ Updated Dec 4, 2025
bulk-user-importcsv-importimport-usersuser-importuser-meta-import
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is User Import with meta – WP Ultimate CSV Importer Add-on Safe to Use in 2026?

Generally Safe

Score 100/100

User Import with meta – WP Ultimate CSV Importer Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'import-users' plugin v1.6 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The lack of known CVEs and the absence of critical or high-severity issues in its history are positive indicators. The plugin also demonstrates good practices by having all AJAX entry points protected by authentication checks, zero shortcodes or cron events, and a substantial portion of SQL queries using prepared statements, along with good output escaping practices. However, there are areas for improvement. The presence of the `unserialize` function is a significant concern, as it can lead to object injection vulnerabilities if untrusted data is passed to it. While no taint flows were identified in this specific analysis, the potential for exploit remains if `unserialize` is used with user-supplied input without proper sanitization. The complete absence of capability checks, despite having AJAX handlers, is another notable weakness that could allow authenticated users to perform actions they shouldn't be authorized for.

Key Concerns

  • Use of unserialize function
  • 0% capability checks on AJAX handlers
Vulnerabilities
None known

User Import with meta – WP Ultimate CSV Importer Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

User Import with meta – WP Ultimate CSV Importer Add-on Release Timeline

v1.6Current
v1.5
v1.4.3
v1.4.2
v1.4.1
v1.4
v1.3
v1.2.9
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

User Import with meta – WP Ultimate CSV Importer Add-on Code Analysis

Dangerous Functions
6
Raw SQL Queries
19
18 prepared
Unescaped Output
4
13 escaped
Nonce Checks
4
Capability Checks
0
File Operations
7
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserialize$stored_ids = unserialize(get_option('total_attachment_ids', ''));importExtensions\MediaHandling.php:505
unserialize$get_stored_ids = unserialize(get_option('total_attachment_ids', ''));importExtensions\MediaHandling.php:507
unserialize$stored_ids = unserialize(get_option('total_attachment_ids', ''));importExtensions\MediaHandling.php:515
unserialize$stored_ids = unserialize(get_option('failed_attachment_ids', ''));importExtensions\MediaHandling.php:524
unserialize$get_stored_ids = unserialize(get_option('failed_attachment_ids', ''));importExtensions\MediaHandling.php:526
unserialize$stored_ids = unserialize(get_option('failed_attachment_ids', ''));importExtensions\MediaHandling.php:534

SQL Query Safety

49% prepared37 total queries

Output Escaping

76% escaped17 total outputs
Attack Surface

User Import with meta – WP Ultimate CSV Importer Add-on Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_settings_optionscontrollers\SendPassword.php:40
authwp_ajax_get_optionscontrollers\SendPassword.php:41
authwp_ajax_image_optionsimportExtensions\MediaHandling.php:21
authwp_ajax_delete_imageimportExtensions\MediaHandling.php:22
WordPress Hooks 2
actionadmin_noticesimport-users.php:81
actionplugins_loadedimport-users.php:109
Maintenance & Trust

User Import with meta – WP Ultimate CSV Importer Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version7.4
Downloads119K

Community Trust

Rating60/100
Number of ratings2
Active installs5K
Developer Profile

User Import with meta – WP Ultimate CSV Importer Add-on Developer Profile

Smackcoders Inc.,

23 plugins · 40K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
946 days
View full developer profile
Detection Fingerprints

How We Detect User Import with meta – WP Ultimate CSV Importer Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/import-users/css/style.css/wp-content/plugins/import-users/js/custom.js
Script Paths
/wp-content/plugins/import-users/js/custom.js
Version Parameters
import-users/css/style.css?ver=import-users/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-warning
Data Attributes
securekey
FAQ

Frequently Asked Questions about User Import with meta – WP Ultimate CSV Importer Add-on