
JVH WP All Import Extender Security & Risk Analysis
wordpress.org/plugins/jvh-wp-all-import-extenderThis plugin extends the WP All Import and Export plugins. It will add the ability to import Visual Composer single images, which are stored as id' …
Is JVH WP All Import Extender Safe to Use in 2026?
Generally Safe
Score 85/100JVH WP All Import Extender has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jvh-wp-all-import-extender" v1.4.2 plugin exhibits a strong security posture in many areas. Static analysis reveals no direct attack surface exposed through AJAX handlers, REST API, shortcodes, or cron events without proper authentication or capability checks. Furthermore, all SQL queries are properly prepared, and output escaping is consistently applied. The absence of any recorded vulnerabilities in its history is also a positive indicator of robust security practices.
However, the presence of two instances of the `unserialize` function without apparent sanitization or context is a significant concern. Although the static analysis did not detect any explicit taint flows, `unserialize` is inherently risky as it can lead to object injection vulnerabilities if the data being deserialized originates from an untrusted source. The lack of any recorded vulnerability history could be due to the plugin being less targeted or the analysis not having identified exploitable chains in the past.
In conclusion, while the plugin demonstrates good general security hygiene, the `unserialize` function represents a notable weakness that could be exploited under certain conditions. The absence of historical vulnerabilities is encouraging but should not entirely negate the potential risk posed by this function. Further investigation into how `unserialize` is used and the source of the data it processes is highly recommended.
Key Concerns
- Dangerous function: unserialize
JVH WP All Import Extender Security Vulnerabilities
JVH WP All Import Extender Release Timeline
JVH WP All Import Extender Code Analysis
Dangerous Functions Found
JVH WP All Import Extender Attack Surface
WordPress Hooks 8
Maintenance & Trust
JVH WP All Import Extender Maintenance & Trust
Maintenance Signals
Community Trust
JVH WP All Import Extender Alternatives
JVH Easy login
jvh-easy-login
This plugin can only be used by JVH webbouw employees.
JVH Gridbuilder WPBakery VC Element
jvh-gridbuilder-wpbakery-vc-element
This plugin adds a WPBakery (VC) element for WP Gridbuilder.
JVH Woody Snippets helper
jvh-woody-snippets-helper
This plugin extends the Woody Snippets plugin. It will add the ability to add images to snippets and all library snippets will be on one page for easy …
JVH CSS Classes
jvh-css-classes
This plugin adds a new CSS Classes Custom Post Type for WPBakery elements. This let you create classes and apply them on WPBakery elements.
JVH VC Templates Essentials
jvh-vc-templates-essentials
This plugin adds the ability to create custom VC Templates for the Essentials theme.
JVH WP All Import Extender Developer Profile
8 plugins · 470 total installs
How We Detect JVH WP All Import Extender
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jvh-wp-all-import-extender/assets/css/style.css/wp-content/plugins/jvh-wp-all-import-extender/assets/js/admin.js/wp-content/plugins/jvh-wp-all-import-extender/assets/js/admin.jsjvh-wp-all-import-extender/assets/css/style.css?ver=jvh-wp-all-import-extender/assets/js/admin.js?ver=HTML / DOM Fingerprints
<!-- Subtitle often contains VC snippets. --><!-- These are stored as id and don't work on import. --><!-- Add snippet content and title so the snippet can be imported. -->