WP All Import – Property Import for Reales WP Security & Risk Analysis

wordpress.org/plugins/reales-wp-xml-csv-property-listings-import

Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …

40 active installs v1.1.3 PHP + WP 4.1.0+ Updated Jan 30, 2026
import-propertiesimport-property-listingsimport-real-estateimport-real-estate-listingsreal-estate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP All Import – Property Import for Reales WP Safe to Use in 2026?

Generally Safe

Score 100/100

WP All Import – Property Import for Reales WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "reales-wp-xml-csv-property-listings-import" v1.1.3 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities, no known CVEs, and all detected SQL queries utilize prepared statements, indicating good practices in database interaction. Furthermore, the attack surface appears to be minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed without authentication or permission checks. This suggests that the plugin developers have taken steps to limit direct entry points for potential attackers.

However, there are significant concerns arising from the static code analysis. The presence of the `unserialize` function is a critical security risk, as it can lead to Remote Code Execution (RCE) if an attacker can control the data being unserialized. The fact that there are no nonce checks or capability checks directly associated with any potential execution points (though the attack surface is reported as zero, the presence of `unserialize` implies it's triggered somewhere) is worrying. Additionally, over half of the output escaping is not properly done, which could lead to Cross-Site Scripting (XSS) vulnerabilities. The single file operation and external HTTP request, while not inherently dangerous, represent potential vectors for further exploitation if not handled securely.

Overall, while the plugin's history and database handling are clean, the static analysis reveals critical vulnerabilities in the form of `unserialize` usage and insufficient output escaping. The lack of explicit capability or nonce checks on potentially sensitive functions is a significant weakness. The absence of any recorded past vulnerabilities, while positive, does not negate the present risks identified in the code. The plugin is recommended for immediate review and remediation of these identified security flaws.

Key Concerns

  • Use of unserialize function
  • No nonce checks
  • No capability checks
  • Improper output escaping (43% not escaped)
  • Single file operation (potential risk)
  • Single external HTTP request (potential risk)
Vulnerabilities
None known

WP All Import – Property Import for Reales WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP All Import – Property Import for Reales WP Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$fieldData = (!empty($field_params['field_obj']->post_content)) ? unserialize($field_params['field_orapid-addon.php:551

Output Escaping

57% escaped14 total outputs
Attack Surface

WP All Import – Property Import for Reales WP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
filterpmxi_addonsrapid-addon.php:144
filterwp_all_import_addon_parserapid-addon.php:145
filterwp_all_import_addon_importrapid-addon.php:146
filterwp_all_import_addon_saved_postrapid-addon.php:147
filterpmxi_options_optionsrapid-addon.php:148
filterwp_all_import_image_sectionsrapid-addon.php:149
filterpmxi_custom_typesrapid-addon.php:150
filterpmxi_post_list_orderrapid-addon.php:151
filterwp_all_import_post_type_imagerapid-addon.php:152
actionpmxi_extend_options_featuredrapid-addon.php:153
actionadmin_initrapid-addon.php:154
filterwp_all_import_acf_is_show_grouprapid-addon.php:219
filterwp_all_import_is_show_add_new_imagesrapid-addon.php:912
filterwp_all_import_is_allow_import_imagesrapid-addon.php:915
filterwp_all_import_is_images_section_enabledrapid-addon.php:958
actionadmin_noticesrapid-addon.php:1153
Maintenance & Trust

WP All Import – Property Import for Reales WP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

WP All Import – Property Import for Reales WP Developer Profile

WP All Import

22 plugins · 207K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1036 days
View full developer profile
Detection Fingerprints

How We Detect WP All Import – Property Import for Reales WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reales-wp-xml-csv-property-listings-import/css/style.css/wp-content/plugins/reales-wp-xml-csv-property-listings-import/js/script.js
Script Paths
/wp-content/plugins/reales-wp-xml-csv-property-listings-import/js/script.js
Version Parameters
reales-wp-xml-csv-property-listings-import/css/style.css?ver=reales-wp-xml-csv-property-listings-import/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
reales-addon-field-wrapreales-addon-section-titlereales-addon-field-labelreales-addon-field-input
HTML Comments
<!-- WP ALL IMPORT - REALES ADD-ON -->
Data Attributes
data-field-iddata-field-typedata-field-label
JS Globals
window.reales_addon_options
Shortcode Output
<div class="reales-addon-field-wrap"><h3 class="reales-addon-section-title"><label class="reales-addon-field-label"><input class="reales-addon-field-input"
FAQ

Frequently Asked Questions about WP All Import – Property Import for Reales WP