
WP All Import – Property Import for RealHomes Security & Risk Analysis
wordpress.org/plugins/realhomes-xml-csv-property-listings-importDrag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
Is WP All Import – Property Import for RealHomes Safe to Use in 2026?
Generally Safe
Score 100/100WP All Import – Property Import for RealHomes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "realhomes-xml-csv-property-listings-import" plugin v1.1.5 reveals a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding known vulnerabilities, with no recorded CVEs. The attack surface, defined by entry points like AJAX handlers, REST API routes, shortcodes, and cron events, is notably absent, indicating a limited direct exposure to external manipulation.
However, several significant concerns emerge from the code signals. The presence of the `unserialize` function, a known vector for object injection vulnerabilities if used with untrusted input, is a critical red flag. Coupled with a lack of nonce and capability checks on potential entry points and a low percentage of properly escaped output, this raises the risk of arbitrary code execution or data manipulation. The single file operation and external HTTP request also warrant careful consideration for potential path traversal or insecure communication. The absence of taint analysis flows in the report is also a point of caution, as it suggests this type of analysis may not have been thoroughly performed or may have yielded no results within the analyzed scope, but doesn't negate the risks from other code signals.
In conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the identified code signals, particularly `unserialize` without evident sanitization or checks, and insufficient output escaping, present considerable risks. The plugin's security would be significantly enhanced by implementing robust input validation, proper sanitization around `unserialize`, and comprehensive capability checks for all sensitive operations.
Key Concerns
- Dangerous function unserialize found
- No nonce checks found
- No capability checks found
- Low output escaping percentage
- File operations present
- External HTTP requests present
WP All Import – Property Import for RealHomes Security Vulnerabilities
WP All Import – Property Import for RealHomes Code Analysis
Dangerous Functions Found
Output Escaping
WP All Import – Property Import for RealHomes Attack Surface
WordPress Hooks 16
Maintenance & Trust
WP All Import – Property Import for RealHomes Maintenance & Trust
Maintenance Signals
Community Trust
WP All Import – Property Import for RealHomes Alternatives
WP All Import – Property Import for WP Residence
wp-residence-add-on-for-wp-all-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Pro Real Estate 7
wp-pro-real-estate-7-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Reales WP
reales-wp-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Real Places
realplaces-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Realia
realia-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for RealHomes Developer Profile
22 plugins · 207K total installs
How We Detect WP All Import – Property Import for RealHomes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.