PostmagThemes Demo Import Security & Risk Analysis

wordpress.org/plugins/postmagthemes-demo-import

PostmagThemes Demo Import is a simple and easy-to-use demo importer WordPress plugin that allows you to import the theme demo data (design and content …

1K active installs v1.1.6 PHP 5.2.4+ WP 4.7+ Updated Dec 31, 2025
contentdatademoimportwidgets
98
A · Safe
CVEs total2
Unpatched0
Last CVENov 11, 2022
Safety Verdict

Is PostmagThemes Demo Import Safe to Use in 2026?

Generally Safe

Score 98/100

PostmagThemes Demo Import has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Nov 11, 2022Updated 6mo ago
Risk Assessment

The postmagthemes-demo-import plugin v1.1.6 presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped outputs, significant concerns arise from its attack surface. Three AJAX handlers are present, and critically, all three lack authentication checks, creating direct entry points for attackers. The presence of the `unserialize` function, a known source of vulnerabilities if not handled with extreme caution, is another red flag, especially when combined with unprotected AJAX endpoints.

The vulnerability history reveals two past high-severity CVEs, both related to 'Unrestricted Upload of File with Dangerous Type'. The fact that these are no longer unpatched is positive, but the pattern of past vulnerabilities suggests that the plugin has had issues with handling user-supplied data, particularly file uploads, in a secure manner. The absence of taint analysis results is not necessarily an indicator of security but rather a limitation of the analysis performed; it doesn't negate the risks identified by other signals.

In conclusion, while the plugin incorporates some strong security measures, the unprotected AJAX handlers represent a substantial and immediate risk. The past vulnerability history also warrants caution. The plugin's security could be significantly improved by implementing proper authentication and authorization checks on its AJAX endpoints and ensuring robust sanitization of any user-supplied data, particularly for file uploads, to prevent recurrence of past vulnerabilities.

Key Concerns

  • AJAX handlers without authentication checks
  • Presence of dangerous function unserialize
  • Past high-severity vulnerabilities
  • One file operation found
  • One external HTTP request found
Vulnerabilities
2 published

PostmagThemes Demo Import Security Vulnerabilities

CVEs by Year

2 CVEs in 2022
2022
Patched Has unpatched

Severity Breakdown

High
2

2 total CVEs

CVE-2022-1540high · 7.2Unrestricted Upload of File with Dangerous Type

PostmagThemes Demo Import <= 1.0.7 - Authenticated (Administrator+) Arbitrary File Upload

Nov 11, 2022 Patched in 1.0.8 (573d)
WF-5bf0267d-b84f-4ad2-8bb3-cc2aa4996af1-postmagthemes-demo-importhigh · 7.2Unrestricted Upload of File with Dangerous Type

PostmagThemes Demo Import <= 1.0.6 - Authenticated (Admin+) Arbitrary File Upload

Aug 5, 2022 Patched in 1.0.7 (536d)
Version History

PostmagThemes Demo Import Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

PostmagThemes Demo Import Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
1
103 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$data = unserialize( $raw );inc\CustomizerImporter.php:95

Output Escaping

99% escaped104 total outputs
Attack Surface
3 unprotected

PostmagThemes Demo Import Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_pmdi_import_demo_datainc\OneClickDemoImport.php:107
authwp_ajax_pmdi_import_customizer_datainc\OneClickDemoImport.php:108
authwp_ajax_pmdi_after_import_datainc\OneClickDemoImport.php:109
WordPress Hooks 32
filterpt-pmdi/disable_pt_brandingdemo\class-demo.php:57
filterpt-pmdi/import_filesdemo\class-demo.php:60
actionpt-pmdi/after_importdemo\class-demo.php:63
filterpt-pmdi/import_filesdemo\demo.php:10
actionpt-pmdi/after_importdemo\demo.php:49
filterpt-pmdi/import_filesdemo\demo.php:80
actionpt-pmdi/after_importdemo\demo.php:103
filterpt-pmdi/import_filesdemo\demo.php:134
filterpt-pmdi/import_filesdemo\demo.php:162
filterpt-pmdi/import_filesdemo\demo.php:189
filterpt-pmdi/import_filesdemo\demo.php:216
filterpt-pmdi/import_filesdemo\demo.php:243
actionpt-pmdi/after_importdemo\demo.php:267
filterpt-pmdi/import_filesdemo\demo.php:299
filterupload_mimesinc\Helpers.php:394
actionpt-pmdi/before_content_import_executioninc\ImportActions.php:22
actionpt-pmdi/after_content_import_executioninc\ImportActions.php:25
actionpt-pmdi/after_content_import_executioninc\ImportActions.php:26
actionpt-pmdi/customizer_import_executioninc\ImportActions.php:29
actionpt-pmdi/after_all_import_executioninc\ImportActions.php:32
actionpt-pmdi/widget_settings_arrayinc\ImportActions.php:38
filterwxr_importer.pre_process.userinc\Importer.php:124
filterwxr_importer.pre_process.postinc\Importer.php:127
filterintermediate_image_sizes_advancedinc\Importer.php:131
actionadmin_menuinc\OneClickDemoImport.php:105
actionadmin_enqueue_scriptsinc\OneClickDemoImport.php:106
actionafter_setup_themeinc\OneClickDemoImport.php:110
actionplugins_loadedinc\OneClickDemoImport.php:111
filterpt-pmdi/time_for_one_ajax_callinc\WPCLICommands.php:191
filterwxr_importer.pre_process.terminc\WXRImporter.php:38
actionadmin_noticespostmagthemes-demo-import.php:31
actionadmin_initpostmagthemes-demo-import.php:77
Maintenance & Trust

PostmagThemes Demo Import Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 31, 2025
PHP min version5.2.4
Downloads24K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

PostmagThemes Demo Import Developer Profile

postmagthemes

15 plugins · 6K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
278 days
View full developer profile
Detection Fingerprints

How We Detect PostmagThemes Demo Import

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/postmagthemes-demo-import/assets/css/style.css/wp-content/plugins/postmagthemes-demo-import/assets/js/main.js
Script Paths
/wp-content/plugins/postmagthemes-demo-import/assets/js/main.js
Version Parameters
postmagthemes-demo-import/assets/css/style.css?ver=postmagthemes-demo-import/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
postmagthemes-demo-import-containerpt-pmdi-modal-contentpt-pmdi-modal-headerpt-pmdi-modal-bodypt-pmdi-import-formpt-pmdi-import-intro-textpt-pmdi-import-controlspt-pmdi-import-notice+38 more
Data Attributes
data-iddata-importdata-titledata-urldata-contentdata-thumbnail+2 more
JS Globals
pmdi_import_datapmdi_customizer_datapmdi_after_import_dataPT_PMDI_IMPORT_DATAPT_PMDI_CUSTOMIZER_DATAPT_PMDI_AFTER_IMPORT_DATA
REST Endpoints
/wp-json/pt-pmdi/v1/import-demo-data/wp-json/pt-pmdi/v1/import-customizer-data/wp-json/pt-pmdi/v1/after-import-data
FAQ

Frequently Asked Questions about PostmagThemes Demo Import