
WP All Import – Import SEO Settings for All In One SEO Security & Risk Analysis
wordpress.org/plugins/import-xml-csv-settings-to-all-in-one-seo-packDrag & drop to import from any CSV, Excel, XML, or Google Sheets file into All In One SEO's titles, meta descriptions, focus keywords, schema …
Is WP All Import – Import SEO Settings for All In One SEO Safe to Use in 2026?
Generally Safe
Score 100/100WP All Import – Import SEO Settings for All In One SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'import-xml-csv-settings-to-all-in-one-seo-pack' version 2.0.0 exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities, a zero attack surface for AJAX and REST API routes, and all SQL queries use prepared statements, indicating good development practices in these areas. There are also no external HTTP requests or cron events, which reduces potential attack vectors.
However, several concerns are present. The `unserialize` function is flagged as a dangerous function, and without clear input sanitization or validation for its usage, it could be a potential vector for remote code execution or object injection vulnerabilities. The low percentage of properly escaped output (45%) suggests that data displayed to users might not be sufficiently sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and capability checks on the identified entry points, while the entry point count is zero, leaves room for concern if the attack surface were to expand or be discovered later. The lack of taint analysis results also makes it difficult to fully assess data flow risks.
Given the clean vulnerability history and the absence of exploitable entry points currently identified, the plugin appears to have a generally good security foundation. However, the presence of `unserialize` and insufficient output escaping are significant weaknesses that require attention. Remediation of these specific issues would greatly improve the plugin's overall security.
Key Concerns
- Usage of unserialize function
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
WP All Import – Import SEO Settings for All In One SEO Security Vulnerabilities
WP All Import – Import SEO Settings for All In One SEO Code Analysis
Dangerous Functions Found
Output Escaping
WP All Import – Import SEO Settings for All In One SEO Attack Surface
WordPress Hooks 17
Maintenance & Trust
WP All Import – Import SEO Settings for All In One SEO Maintenance & Trust
Maintenance Signals
Community Trust
WP All Import – Import SEO Settings for All In One SEO Alternatives
WP All Import – Import SEO Settings for Yoast SEO
yoast-seo-settings-xml-csv-import
Drag & drop to import from any CSV, Excel, XML, or Google Sheets file into Yoast SEO's titles, meta descriptions, focus keywords, schema sett …
WP All Import – Import SEO Settings for Rank Math SEO
import-xml-csv-settings-to-rank-math-seo
Drag & drop to import from any CSV, Excel, XML, or Google Sheets file into Rank Math SEO's titles, meta descriptions, focus keywords, schema …
Import into Schema.org by WordLift
wordlift-add-on-for-wp-all-import
Easily import structured data and schema.org settings from any XML or CSV file to WordLift knowledge graph.
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
Internal Links Manager
seo-automated-link-building
Boost your SEO and get better rankings with our automated link building plugin. With this plugin you can link any keyword to any URL - internal or ext …
WP All Import – Import SEO Settings for All In One SEO Developer Profile
22 plugins · 207K total installs
How We Detect WP All Import – Import SEO Settings for All In One SEO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-all-import-all-in-one-seo-addon/assets/css/wpai-aioseo-admin.css/wp-content/plugins/wp-all-import-all-in-one-seo-addon/assets/js/wpai-aioseo-admin.js/wp-content/plugins/wp-all-import-all-in-one-seo-addon/assets/js/wpai-aioseo-admin.jswpai-aioseo-admin.css?ver=wpai-aioseo-admin.js?ver=