
Wetu Content Importer Security & Risk Analysis
wordpress.org/plugins/lsx-importer-for-wetuIntegrate with the Wetu Tour Operator system to import destination, accommodation, and tour content into the Tour Operator plugin format.
Is Wetu Content Importer Safe to Use in 2026?
Generally Safe
Score 92/100Wetu Content Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lsx-importer-for-wetu" v1.5.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, utilizing prepared statements for all queries, and ensuring all output is properly escaped. This significantly mitigates risks related to SQL injection and cross-site scripting (XSS) vulnerabilities originating from data manipulation and display.
The primary concern lies in its attack surface. With 6 AJAX handlers, 4 of which lack authentication checks, there is a substantial opportunity for unauthenticated users to interact with sensitive functionalities. While taint analysis did not reveal critical or high severity issues with unsanitized paths, the presence of 8 such flows, even if lower severity, warrants attention, especially when combined with unprotected AJAX endpoints. The lack of capability checks on AJAX handlers is a significant weakness, potentially allowing unauthorized users to trigger unintended actions.
The plugin's vulnerability history is entirely clean, with no recorded CVEs. This suggests a good track record and potentially diligent maintenance. However, a clean history does not negate the inherent risks identified in the current code analysis. The plugin’s strengths in data handling are overshadowed by the significant exposure presented by its unprotected AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths (even if low severity)
- No capability checks on AJAX handlers
Wetu Content Importer Security Vulnerabilities
Wetu Content Importer Release Timeline
Wetu Content Importer Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Wetu Content Importer Attack Surface
AJAX Handlers 6
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Wetu Content Importer Maintenance & Trust
Maintenance Signals
Community Trust
Wetu Content Importer Alternatives
Tour Operator Reviews
tour-operator-reviews
This plugin adds reviews to tours, accommodation and destinations.
Tourfic Toolkit
travelfic-toolkit
A companion plugin to the Travelfic and Ultimate Hotel Booking with which you can easily build your own Hotel, Accommodation, Tour & Travel Bookin …
Tourwriter Itineraries
minim-by-tourwriter
Easily display your Tourwriter itineraries on your website
Tour Operator
tour-operator
Tour Operator is a block-based plugin for WordPress that helps travel agencies and tour operators showcase tours, destinations, and accommodations usi …
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
wp-travel-engine
WP Travel Engine is the most popular tour and travel booking WordPress plugin. Used by over 20,000 travel agency websites.
Wetu Content Importer Developer Profile
17 plugins · 710 total installs
How We Detect Wetu Content Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lsx-importer-for-wetu/assets/css/lsx-wetu-importer.css/wp-content/plugins/lsx-importer-for-wetu/assets/js/lsx-wetu-importer.js/wp-content/plugins/lsx-importer-for-wetu/assets/js/lsx-wetu-importer.jslsx-wetu-importer/assets/css/lsx-wetu-importer.css?ver=lsx-wetu-importer/assets/js/lsx-wetu-importer.js?ver=HTML / DOM Fingerprints
lsx-wetu-importer-pagedata-plugin-slug="lsx-wetu-importer"lsx_wetu_importer_settings