
Rara One Click Demo Import Security & Risk Analysis
wordpress.org/plugins/rara-one-click-demo-importMake your website look like the live demo of the theme with a click!
Is Rara One Click Demo Import Safe to Use in 2026?
Generally Safe
Score 91/100Rara One Click Demo Import has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'rara-one-click-demo-import' version 1.3.4 exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation (71% prepared) and output escaping (90% escaped), several significant concerns emerge from the static analysis. The presence of two AJAX handlers without authentication checks creates a direct attack vector, significantly increasing the risk of unauthorized actions. The lack of any taint analysis results is also noteworthy, although this may indicate robust sanitization or simply that the analysis was not comprehensive enough to detect potential flows.
The vulnerability history reveals a past high-severity Cross-Site Request Forgery (CSRF) vulnerability, which, although currently patched, suggests a historical weakness in handling user-initiated actions securely. The absence of any currently unpatched vulnerabilities is a positive sign, indicating that past issues have been addressed. However, the combination of unprotected entry points and historical CSRF issues warrants caution. The plugin has a relatively small attack surface, but the unprotected AJAX handlers are a critical vulnerability that needs immediate attention.
In conclusion, 'rara-one-click-demo-import' v1.3.4 has strengths in its handling of SQL and output but significant weaknesses in its authentication for AJAX endpoints. The historical CSRF vulnerability serves as a warning sign. The overall security can be considered moderate, with a critical need to address the unprotected AJAX handlers to move towards a more robust security posture.
Key Concerns
- AJAX handlers without authentication checks
- Past high severity CVE
Rara One Click Demo Import Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Rara One Click Demo Import <= 1.2.9 - Cross-Site Request Forgery to Arbitrary File Upload
Rara One Click Demo Import Code Analysis
SQL Query Safety
Output Escaping
Rara One Click Demo Import Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Rara One Click Demo Import Maintenance & Trust
Maintenance Signals
Community Trust
Rara One Click Demo Import Alternatives
SKT Themes Demo Import
skt-themes-demo-importer
Live demo content can be imported quickly in just one click including all widgets and settings.
Theme Demo Import
theme-demo-import
Quickly import demo content, widgets and settings in one click. Made for theme authors to simplify importing demo content for their users.
Fable Extra
fable-extra
Used for WP Fable Themes.
Starter Templates by Gradient Themes
gradient-starter-templates
Setup you site with dummy data easily. Import settings, widgets and content with one click. Your dummy data must have ZIP file of xml, dat and wie fi …
Flawless Themes Demo Importer
flawless-themes-demo-importer
Flawless Themes Demo Importer plugin helps you import demo content for various free themes of flawlessthemes . Flawless Themes are dedicated to creati …
Rara One Click Demo Import Developer Profile
76 plugins · 74K total installs
How We Detect Rara One Click Demo Import
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rara-one-click-demo-import/assets/css/rrdi-admin.css/wp-content/plugins/rara-one-click-demo-import/assets/css/rrdi-frontend.css/wp-content/plugins/rara-one-click-demo-import/assets/js/rrdi-admin.js/wp-content/plugins/rara-one-click-demo-import/assets/js/rrdi-frontend.jsRARA One Click Demo ImportRARA One Click Demo Import v1.3.4/wp-content/plugins/rara-one-click-demo-import/assets/js/rrdi-admin.js/wp-content/plugins/rara-one-click-demo-import/assets/js/rrdi-frontend.jsrara-one-click-demo-import/assets/css/rrdi-admin.css?ver=rara-one-click-demo-import/assets/css/rrdi-frontend.css?ver=rara-one-click-demo-import/assets/js/rrdi-admin.js?ver=rara-one-click-demo-import/assets/js/rrdi-frontend.js?ver=HTML / DOM Fingerprints
rrdi-content-wrapperrrdi-main-contentrrdi-preloaderrrdi-noticerrdi-demo-import-wraprrdi-theme-noticerrdi-install-btnrrdi-import-data-wrap+1 more<!-- Main Rara One Click Demo Import plugin class/file. --><!-- Rara One Click Demo Import class, so we don't have to worry about namespaces. --><!-- Singleton instance --><!-- Actions. -->+9 moredata-demo-iddata-titledata-filedata-parentrrdi_admin_optionsrrdi_ajax_object/wp-json/rrdi/v1/import-demo