WP All Import – Rental Property Import for WP Rentals Security & Risk Analysis

wordpress.org/plugins/import-wp-rentals-listings

Drag & drop to import rental properties from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, availability, book …

10 active installs v1.0.1 PHP 7.4+ WP 4.9.0+ Updated Jan 31, 2026
import-property-listingsimport-wp-rentalsimport-wp-rentals-ownerimport-wp-rentals-propertieswp-rentals
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP All Import – Rental Property Import for WP Rentals Safe to Use in 2026?

Generally Safe

Score 100/100

WP All Import – Rental Property Import for WP Rentals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "import-wp-rentals-listings" v1.0.1 exhibits a generally good security posture based on the static analysis provided, with a strong emphasis on proper output escaping and the use of prepared statements for SQL queries. The absence of known vulnerabilities in its history is also a positive indicator of its development practices. However, the presence of the `unserialize` function without any apparent input validation or sanitization presents a significant risk. While the attack surface appears minimal with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, this single dangerous function remains a critical concern. The lack of nonce checks and capability checks further exacerbates this risk, as it suggests that any mechanism that might indirectly lead to the unserialization of untrusted data could be exploited.

Key Concerns

  • Dangerous function: unserialize without checks
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

WP All Import – Rental Property Import for WP Rentals Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP All Import – Rental Property Import for WP Rentals Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
2 prepared
Unescaped Output
1
92 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$import_options_arr = unserialize($import_options['options']);classes\class-helper.php:48

SQL Query Safety

100% prepared2 total queries

Output Escaping

99% escaped93 total outputs
Attack Surface

WP All Import – Rental Property Import for WP Rentals Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitimport-wp-rentals-csv-xml.php:52
Maintenance & Trust

WP All Import – Rental Property Import for WP Rentals Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 31, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP All Import – Rental Property Import for WP Rentals Developer Profile

WP All Import

22 plugins · 207K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1036 days
View full developer profile
Detection Fingerprints

How We Detect WP All Import – Rental Property Import for WP Rentals

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/import-wp-rentals-csv-xml/classes/class-rapid-addon.php/wp-content/plugins/import-wp-rentals-csv-xml/classes/class-importer-listings.php/wp-content/plugins/import-wp-rentals-csv-xml/classes/class-importer-owners.php/wp-content/plugins/import-wp-rentals-csv-xml/classes/class-importer-location.php/wp-content/plugins/import-wp-rentals-csv-xml/classes/class-field-factory-owners.php/wp-content/plugins/import-wp-rentals-csv-xml/classes/class-field-factory-listings.php/wp-content/plugins/import-wp-rentals-csv-xml/classes/class-helper.php

HTML / DOM Fingerprints

JS Globals
PMXI_WP_Rentals_Import_Add_On
FAQ

Frequently Asked Questions about WP All Import – Rental Property Import for WP Rentals