
WP All Import – Listings Import for Listable Security & Risk Analysis
wordpress.org/plugins/import-xml-csv-listings-to-listable-themeDrag & drop to import directory listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, categories, locat …
Is WP All Import – Listings Import for Listable Safe to Use in 2026?
Generally Safe
Score 100/100WP All Import – Listings Import for Listable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "import-xml-csv-listings-to-listable-theme" plugin, v1.0.5, exhibits a mixed security posture. On one hand, the attack surface appears to be minimal with no reported AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries utilize prepared statements, which is a strong security practice. However, the static analysis reveals significant concerns. The presence of the `unserialize` function without clear sanitization or context raises a red flag, as it can be exploited for object injection vulnerabilities if the serialized data is controlled by an attacker. Additionally, a concerning 55% of output escaping is not properly implemented, leaving the plugin vulnerable to cross-site scripting (XSS) attacks. The file operations and external HTTP requests also represent potential points of compromise if not handled with extreme care.
The vulnerability history for this plugin is notably clean, with no recorded CVEs. This could indicate robust development practices or a lack of extensive security auditing over time. However, the absence of past vulnerabilities does not guarantee future security, especially given the identified weaknesses in the current code. The plugin's strengths lie in its limited entry points and secure SQL handling, but these are overshadowed by the critical risk posed by `unserialize` and the widespread XSS vulnerability due to insufficient output escaping. Users should approach this plugin with caution and consider the potential risks before deployment.
Key Concerns
- Dangerous function unserialize used
- High percentage of unescaped output
- No nonce checks on entry points
- No capability checks on entry points
WP All Import – Listings Import for Listable Security Vulnerabilities
WP All Import – Listings Import for Listable Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
WP All Import – Listings Import for Listable Attack Surface
WordPress Hooks 19
Maintenance & Trust
WP All Import – Listings Import for Listable Maintenance & Trust
Maintenance Signals
Community Trust
WP All Import – Listings Import for Listable Alternatives
WP All Import – Job Listing Import for WP Job Manager
wp-job-manager-xml-csv-listings-import
Drag & drop to import job listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports company info, locations, applic …
WP All Import – Job Listing Import for Jobify
jobify-xml-csv-listings-import
Drag & drop to import job listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports company info, locations, catego …
WP All Import – WP Job Manager Field Editor Add-On
smyles-wp-job-manager-field-editor-import
Support for custom fields created with WP Job Manager Field Editor when importing Jobs or Resumes using WP All Import
WP All Import – Listings Import for Listify
listify-xml-csv-listings-import
Drag & drop to import directory listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, categories, locat …
Import Listings into the PointFinder Theme
pointfinder-xml-csv-listings-import
Easily import listings from any XML or CSV file to the PointFinder theme with the PointFinder Add-On for WP All Import.
WP All Import – Listings Import for Listable Developer Profile
22 plugins · 207K total installs
How We Detect WP All Import – Listings Import for Listable
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-xml-csv-listings-to-listable-theme/css/style.css/wp-content/plugins/import-xml-csv-listings-to-listable-theme/js/main.js/wp-content/plugins/import-xml-csv-listings-to-listable-theme/js/main.jsimport-xml-csv-listings-to-listable-theme/css/style.css?ver=import-xml-csv-listings-to-listable-theme/js/main.js?ver=HTML / DOM Fingerprints
listable_addondata-repeater-listListable_Addon