Pixelpost Importer Security & Risk Analysis
wordpress.org/plugins/pixelpost-importerImport your PixelPost database in WordPress (categories, posts, comments, and ratings).
Is Pixelpost Importer Safe to Use in 2026?
Generally Safe
Score 85/100Pixelpost Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pixelpost-importer plugin exhibits a concerning security posture due to several critical findings in its static analysis. The presence of two unprotected AJAX handlers significantly increases the attack surface, as these can be exploited without proper authentication. Furthermore, the use of the `unserialize` function is a major red flag, as it can lead to Remote Code Execution vulnerabilities if untrusted data is unserialized. The taint analysis also reveals two high-severity flows with unsanitized paths, indicating potential for data injection or manipulation through user-controlled input. While the plugin has no recorded CVEs, this absence should not be interpreted as a guarantee of security, especially given the inherent risks identified in the code.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function unserialize used
- High severity taint flows (unsanitized paths)
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Pixelpost Importer Security Vulnerabilities
Pixelpost Importer Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Pixelpost Importer Attack Surface
AJAX Handlers 2
WordPress Hooks 2
Maintenance & Trust
Pixelpost Importer Maintenance & Trust
Maintenance Signals
Community Trust
Pixelpost Importer Alternatives
WP-PostRatings
wp-postratings
Adds an AJAX rating system for your WordPress site's content.
wp-postratings-my
wp-postratings-my
Shows users their WP-PostRatings and allows filters.
WordPress Importer
wordpress-importer
Import posts, pages, comments, custom fields, categories, tags and more from a WordPress export file.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
Import and export users and customers
import-users-from-csv-with-meta
Import and export users and customers including user meta, roles, and other. Compatible with many plugins. Do it from the front end or using cron.
Pixelpost Importer Developer Profile
1 plugin · 10 total installs
How We Detect Pixelpost Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pixelpost-importer/pixelpost-importer.phpHTML / DOM Fingerprints
PP_Importer/wp-json/pixelpost-importer/v1/migrate