WP All Import – Property Import for Realia Security & Risk Analysis

wordpress.org/plugins/realia-xml-csv-property-listings-import

Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …

30 active installs v2.0.9 PHP + WP 4.1.0+ Updated Jan 30, 2026
import-propertiesimport-property-listingsimport-real-estateimport-real-estate-listingsreal-estate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP All Import – Property Import for Realia Safe to Use in 2026?

Generally Safe

Score 100/100

WP All Import – Property Import for Realia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The security posture of the "realia-xml-csv-property-listings-import" v2.0.9 plugin appears to be a mixed bag, leaning towards caution due to the presence of a dangerous function without apparent safeguards. While the plugin boasts a clean record with zero known vulnerabilities and a complete absence of taint flows, this doesn't entirely negate potential risks. The static analysis highlights the use of the `unserialize` function, which is a known vector for object injection vulnerabilities if the serialized data originates from an untrusted source. The limited number of output escaping instances also raises concerns about potential cross-site scripting (XSS) vulnerabilities, especially given that only 45% of outputs are properly escaped. The lack of capability checks and nonce checks on entry points, though the attack surface is currently zero, means that if any entry points were to be introduced in future updates, they would be unprotected by default. The absence of recorded vulnerabilities is a positive sign, suggesting either good development practices in the past or a lack of exploitation. However, the identified code signals warrant attention, particularly the use of `unserialize` and the incomplete output escaping.

Key Concerns

  • Use of dangerous function unserialize
  • Low percentage of properly escaped output
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

WP All Import – Property Import for Realia Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP All Import – Property Import for Realia Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserialize$fieldData = (!empty($field_params['field_obj']->post_content)) ? unserialize($field_params['field_orapid-addon.php:551

Output Escaping

45% escaped11 total outputs
Attack Surface

WP All Import – Property Import for Realia Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
filterpmxi_addonsrapid-addon.php:144
filterwp_all_import_addon_parserapid-addon.php:145
filterwp_all_import_addon_importrapid-addon.php:146
filterwp_all_import_addon_saved_postrapid-addon.php:147
filterpmxi_options_optionsrapid-addon.php:148
filterwp_all_import_image_sectionsrapid-addon.php:149
filterpmxi_custom_typesrapid-addon.php:150
filterpmxi_post_list_orderrapid-addon.php:151
filterwp_all_import_post_type_imagerapid-addon.php:152
actionpmxi_extend_options_featuredrapid-addon.php:153
actionadmin_initrapid-addon.php:154
filterwp_all_import_acf_is_show_grouprapid-addon.php:219
filterwp_all_import_is_show_add_new_imagesrapid-addon.php:912
filterwp_all_import_is_allow_import_imagesrapid-addon.php:915
filterwp_all_import_is_images_section_enabledrapid-addon.php:958
actionadmin_noticesrapid-addon.php:1153
actionpmxi_saved_postrealia-add-on.php:883
Maintenance & Trust

WP All Import – Property Import for Realia Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

WP All Import – Property Import for Realia Developer Profile

WP All Import

22 plugins · 207K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1036 days
View full developer profile
Detection Fingerprints

How We Detect WP All Import – Property Import for Realia

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/realia-xml-csv-property-listings-import/css/style.css/wp-content/plugins/realia-xml-csv-property-listings-import/js/script.js
Script Paths
/wp-content/plugins/realia-xml-csv-property-listings-import/js/script.js
Version Parameters
realia-xml-csv-property-listings-import/style.css?ver=realia-xml-csv-property-listings-import/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
realia-addon-sectionrealia-addon-fieldrealia-addon-title
Data Attributes
data-realia-addon-field-iddata-realia-addon-section-id
JS Globals
RealiaAddon
FAQ

Frequently Asked Questions about WP All Import – Property Import for Realia