
WP All Import – Property Import for Reales WP Security & Risk Analysis
wordpress.org/plugins/reales-wp-xml-csv-property-listings-importDrag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
Is WP All Import – Property Import for Reales WP Safe to Use in 2026?
Generally Safe
Score 100/100WP All Import – Property Import for Reales WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "reales-wp-xml-csv-property-listings-import" v1.1.3 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities, no known CVEs, and all detected SQL queries utilize prepared statements, indicating good practices in database interaction. Furthermore, the attack surface appears to be minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed without authentication or permission checks. This suggests that the plugin developers have taken steps to limit direct entry points for potential attackers.
However, there are significant concerns arising from the static code analysis. The presence of the `unserialize` function is a critical security risk, as it can lead to Remote Code Execution (RCE) if an attacker can control the data being unserialized. The fact that there are no nonce checks or capability checks directly associated with any potential execution points (though the attack surface is reported as zero, the presence of `unserialize` implies it's triggered somewhere) is worrying. Additionally, over half of the output escaping is not properly done, which could lead to Cross-Site Scripting (XSS) vulnerabilities. The single file operation and external HTTP request, while not inherently dangerous, represent potential vectors for further exploitation if not handled securely.
Overall, while the plugin's history and database handling are clean, the static analysis reveals critical vulnerabilities in the form of `unserialize` usage and insufficient output escaping. The lack of explicit capability or nonce checks on potentially sensitive functions is a significant weakness. The absence of any recorded past vulnerabilities, while positive, does not negate the present risks identified in the code. The plugin is recommended for immediate review and remediation of these identified security flaws.
Key Concerns
- Use of unserialize function
- No nonce checks
- No capability checks
- Improper output escaping (43% not escaped)
- Single file operation (potential risk)
- Single external HTTP request (potential risk)
WP All Import – Property Import for Reales WP Security Vulnerabilities
WP All Import – Property Import for Reales WP Code Analysis
Dangerous Functions Found
Output Escaping
WP All Import – Property Import for Reales WP Attack Surface
WordPress Hooks 16
Maintenance & Trust
WP All Import – Property Import for Reales WP Maintenance & Trust
Maintenance Signals
Community Trust
WP All Import – Property Import for Reales WP Alternatives
WP All Import – Property Import for RealHomes
realhomes-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for WP Residence
wp-residence-add-on-for-wp-all-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Pro Real Estate 7
wp-pro-real-estate-7-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Real Places
realplaces-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Realia
realia-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Reales WP Developer Profile
22 plugins · 207K total installs
How We Detect WP All Import – Property Import for Reales WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reales-wp-xml-csv-property-listings-import/css/style.css/wp-content/plugins/reales-wp-xml-csv-property-listings-import/js/script.js/wp-content/plugins/reales-wp-xml-csv-property-listings-import/js/script.jsreales-wp-xml-csv-property-listings-import/css/style.css?ver=reales-wp-xml-csv-property-listings-import/js/script.js?ver=HTML / DOM Fingerprints
reales-addon-field-wrapreales-addon-section-titlereales-addon-field-labelreales-addon-field-input<!-- WP ALL IMPORT - REALES ADD-ON -->data-field-iddata-field-typedata-field-labelwindow.reales_addon_options<div class="reales-addon-field-wrap"><h3 class="reales-addon-section-title"><label class="reales-addon-field-label"><input class="reales-addon-field-input"