WP All Import – Job Listing Import for Jobify Security & Risk Analysis

wordpress.org/plugins/jobify-xml-csv-listings-import

Drag & drop to import job listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports company info, locations, catego …

100 active installs v1.0.9 PHP + WP 4.1.0+ Updated Jan 30, 2026
import-directoryimport-job-listingsimport-listingsjob-directorytags-wp-job-manager
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP All Import – Job Listing Import for Jobify Safe to Use in 2026?

Generally Safe

Score 100/100

WP All Import – Job Listing Import for Jobify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "jobify-xml-csv-listings-import" plugin v1.0.9 exhibits a generally positive security posture regarding its attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. This significantly limits direct exploit vectors. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and having no recorded vulnerability history, suggesting a history of stable and secure development.

However, the presence of the `unserialize` function is a significant concern. Without proper validation or sanitization of the data being unserialized, this function can lead to Remote Code Execution (RCE) vulnerabilities if an attacker can control the serialized data. Additionally, the static analysis indicates that a substantial portion (55%) of output is not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without sufficient sanitization.

While the plugin has a clean vulnerability history, this does not negate the inherent risks posed by the identified code signals. The combination of a potentially dangerous function (`unserialize`) and a high percentage of unescaped output presents a notable risk that needs to be addressed to ensure the plugin's security.

Key Concerns

  • Dangerous function unserialize found
  • 55% of outputs not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP All Import – Job Listing Import for Jobify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP All Import – Job Listing Import for Jobify Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$fieldData = (!empty($field_params['field_obj']->post_content)) ? unserialize($field_params['field_orapid-addon.php:551

Output Escaping

45% escaped11 total outputs
Attack Surface

WP All Import – Job Listing Import for Jobify Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionpmxi_before_post_importjobify-add-on.php:549
filterpmxi_addonsrapid-addon.php:144
filterwp_all_import_addon_parserapid-addon.php:145
filterwp_all_import_addon_importrapid-addon.php:146
filterwp_all_import_addon_saved_postrapid-addon.php:147
filterpmxi_options_optionsrapid-addon.php:148
filterwp_all_import_image_sectionsrapid-addon.php:149
filterpmxi_custom_typesrapid-addon.php:150
filterpmxi_post_list_orderrapid-addon.php:151
filterwp_all_import_post_type_imagerapid-addon.php:152
actionpmxi_extend_options_featuredrapid-addon.php:153
actionadmin_initrapid-addon.php:154
filterwp_all_import_acf_is_show_grouprapid-addon.php:219
filterwp_all_import_is_show_add_new_imagesrapid-addon.php:912
filterwp_all_import_is_allow_import_imagesrapid-addon.php:915
filterwp_all_import_is_images_section_enabledrapid-addon.php:958
actionadmin_noticesrapid-addon.php:1153
Maintenance & Trust

WP All Import – Job Listing Import for Jobify Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

WP All Import – Job Listing Import for Jobify Developer Profile

WP All Import

22 plugins · 207K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1036 days
View full developer profile
Detection Fingerprints

How We Detect WP All Import – Job Listing Import for Jobify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jobify-xml-csv-listings-import/admin/css/bootstrap.css/wp-content/plugins/jobify-xml-csv-listings-import/admin/css/bootstrap-responsive.css/wp-content/plugins/jobify-xml-csv-listings-import/admin/css/colorpicker.css/wp-content/plugins/jobify-xml-csv-listings-import/admin/css/jquery-ui-1.10.3.custom.min.css/wp-content/plugins/jobify-xml-csv-listings-import/admin/css/style.css
Script Paths
/wp-content/plugins/jobify-xml-csv-listings-import/admin/js/bootstrap.js/wp-content/plugins/jobify-xml-csv-listings-import/admin/js/colorpicker.js/wp-content/plugins/jobify-xml-csv-listings-import/admin/js/jquery-ui-1.10.3.custom.min.js/wp-content/plugins/jobify-xml-csv-listings-import/admin/js/scripts.js

HTML / DOM Fingerprints

CSS Classes
jobify-addon-settings
Data Attributes
data-field-iddata-field-typedata-iddata-options
JS Globals
JobifyAddon
FAQ

Frequently Asked Questions about WP All Import – Job Listing Import for Jobify