WP All Import – Listings Import for Listable Security & Risk Analysis

wordpress.org/plugins/import-xml-csv-listings-to-listable-theme

Drag & drop to import directory listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, categories, locat …

80 active installs v1.0.5 PHP + WP 4.1.0+ Updated Jan 30, 2026
import-directoryimport-job-listingsimport-listingsjob-directorytags-listable
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP All Import – Listings Import for Listable Safe to Use in 2026?

Generally Safe

Score 100/100

WP All Import – Listings Import for Listable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "import-xml-csv-listings-to-listable-theme" plugin, v1.0.5, exhibits a mixed security posture. On one hand, the attack surface appears to be minimal with no reported AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries utilize prepared statements, which is a strong security practice. However, the static analysis reveals significant concerns. The presence of the `unserialize` function without clear sanitization or context raises a red flag, as it can be exploited for object injection vulnerabilities if the serialized data is controlled by an attacker. Additionally, a concerning 55% of output escaping is not properly implemented, leaving the plugin vulnerable to cross-site scripting (XSS) attacks. The file operations and external HTTP requests also represent potential points of compromise if not handled with extreme care.

The vulnerability history for this plugin is notably clean, with no recorded CVEs. This could indicate robust development practices or a lack of extensive security auditing over time. However, the absence of past vulnerabilities does not guarantee future security, especially given the identified weaknesses in the current code. The plugin's strengths lie in its limited entry points and secure SQL handling, but these are overshadowed by the critical risk posed by `unserialize` and the widespread XSS vulnerability due to insufficient output escaping. Users should approach this plugin with caution and consider the potential risks before deployment.

Key Concerns

  • Dangerous function unserialize used
  • High percentage of unescaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

WP All Import – Listings Import for Listable Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP All Import – Listings Import for Listable Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
2 prepared
Unescaped Output
6
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$fieldData = (!empty($field_params['field_obj']->post_content)) ? unserialize($field_params['field_orapid-addon.php:551

SQL Query Safety

100% prepared2 total queries

Output Escaping

45% escaped11 total outputs
Attack Surface

WP All Import – Listings Import for Listable Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionpmxi_saved_postlistable-add-on.php:14
actionpmxi_before_xml_importlistable-add-on.php:15
actionpmxi_before_post_importlistable-add-on.php:16
filterpmxi_addonsrapid-addon.php:144
filterwp_all_import_addon_parserapid-addon.php:145
filterwp_all_import_addon_importrapid-addon.php:146
filterwp_all_import_addon_saved_postrapid-addon.php:147
filterpmxi_options_optionsrapid-addon.php:148
filterwp_all_import_image_sectionsrapid-addon.php:149
filterpmxi_custom_typesrapid-addon.php:150
filterpmxi_post_list_orderrapid-addon.php:151
filterwp_all_import_post_type_imagerapid-addon.php:152
actionpmxi_extend_options_featuredrapid-addon.php:153
actionadmin_initrapid-addon.php:154
filterwp_all_import_acf_is_show_grouprapid-addon.php:219
filterwp_all_import_is_show_add_new_imagesrapid-addon.php:912
filterwp_all_import_is_allow_import_imagesrapid-addon.php:915
filterwp_all_import_is_images_section_enabledrapid-addon.php:958
actionadmin_noticesrapid-addon.php:1153
Maintenance & Trust

WP All Import – Listings Import for Listable Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version
Downloads8K

Community Trust

Rating60/100
Number of ratings2
Active installs80
Developer Profile

WP All Import – Listings Import for Listable Developer Profile

WP All Import

22 plugins · 207K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1036 days
View full developer profile
Detection Fingerprints

How We Detect WP All Import – Listings Import for Listable

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/import-xml-csv-listings-to-listable-theme/css/style.css/wp-content/plugins/import-xml-csv-listings-to-listable-theme/js/main.js
Script Paths
/wp-content/plugins/import-xml-csv-listings-to-listable-theme/js/main.js
Version Parameters
import-xml-csv-listings-to-listable-theme/css/style.css?ver=import-xml-csv-listings-to-listable-theme/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
listable_addon
Data Attributes
data-repeater-list
JS Globals
Listable_Addon
FAQ

Frequently Asked Questions about WP All Import – Listings Import for Listable