
PK InExPress Security & Risk Analysis
wordpress.org/plugins/pk-inexpressQuick importer from management software (CRMs) to specific WordPress themes.
Is PK InExPress Safe to Use in 2026?
Generally Safe
Score 100/100PK InExPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pk-inexpress" v1.1.7 plugin exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and having no recorded vulnerabilities, significant concerns arise from its attack surface. With 3 AJAX handlers identified, all of which lack authentication checks, there's a direct and unprotected pathway for potential exploitation. Additionally, the taint analysis revealed one flow with unsanitized paths, which, although not classified as critical or high severity in this specific analysis, still represents a potential risk for data injection or manipulation if user-supplied input isn't properly validated and escaped before being used in sensitive operations. The absence of any historical vulnerabilities is positive, but it does not negate the immediate risks presented by the current code analysis.
Overall, the plugin has strengths in its SQL handling and lack of past exploits. However, the unprotected AJAX endpoints and the identified unsanitized path flow are critical weaknesses that expose the installation to potential security breaches. These issues significantly elevate the risk profile of the plugin, despite its otherwise clean record and secure SQL practices. Prioritizing the remediation of these exposed entry points is crucial for the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
PK InExPress Security Vulnerabilities
PK InExPress Release Timeline
PK InExPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PK InExPress Attack Surface
AJAX Handlers 3
WordPress Hooks 10
Maintenance & Trust
PK InExPress Maintenance & Trust
Maintenance Signals
Community Trust
PK InExPress Alternatives
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
wp-all-import
Easily import any file of any size into any plugin, post type, custom field, or taxonomy. Supports WooCommerce, ACF, images, galleries, users, real es …
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress
wp-ultimate-csv-importer
Effortlessly import, export, and migrate your WordPress data with WP Ultimate CSV Importer. This all-in-one solution supports CSV, XML, and Excel file …
Import WP – Export and Import CSV and XML files to WordPress
jc-importer
Import WP, a simple, fast and powerful XML and CSV import solution, Making it easy to import posts, pages, categories, tags, users and attachments.
Import WooCommerce Suite
import-woocommerce
Use the WooCommerce Import Suite to import Products, Orders, Coupons, Customers, and Reviews with ease. Requires the WP Ultimate CSV Importer Free plu …
PK InExPress Developer Profile
1 plugin · 0 total installs
How We Detect PK InExPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pk-inexpress/assets/css/pkinex-admin.css/wp-content/plugins/pk-inexpress/assets/js/pkinex-admin.js/wp-content/plugins/pk-inexpress/assets/js/pkinex-frontend.js/wp-content/plugins/pk-inexpress/assets/js/pkinex-admin.js/wp-content/plugins/pk-inexpress/assets/js/pkinex-frontend.jspk-inexpress/assets/css/pkinex-admin.css?ver=pk-inexpress/assets/js/pkinex-admin.js?ver=pk-inexpress/assets/js/pkinex-frontend.js?ver=HTML / DOM Fingerprints
pkinex-admin-formPKINEX_Inexpress pk-inexpress mainpkinex_inexpress