
WP All Import – Property Import for Real Places Security & Risk Analysis
wordpress.org/plugins/realplaces-xml-csv-property-listings-importDrag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
Is WP All Import – Property Import for Real Places Safe to Use in 2026?
Generally Safe
Score 100/100WP All Import – Property Import for Real Places has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "realplaces-xml-csv-property-listings-import" plugin version 1.0.4 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and does not appear to have any known historical vulnerabilities. The attack surface is also minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected.
However, there are notable areas of concern. The presence of the `unserialize` function is a significant risk, as it can lead to Remote Code Execution if used with user-supplied data without proper validation. Furthermore, the output escaping is only 45% properly done, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks on the identified entry points, even though there are none currently exposed, is a weakness that could become problematic if the plugin's functionality expands or if an attack vector is discovered that bypasses the current limited entry points.
In conclusion, while the plugin has a low apparent attack surface and a clean vulnerability history, the presence of `unserialize` and insufficient output escaping presents immediate security risks that require attention. The absence of robust authentication and authorization checks on critical functions is a foundational weakness.
Key Concerns
- Unserialized data potentially leading to RCE
- Insufficient output escaping (XSS risk)
- No nonce checks on entry points
- No capability checks on entry points
WP All Import – Property Import for Real Places Security Vulnerabilities
WP All Import – Property Import for Real Places Code Analysis
Dangerous Functions Found
Output Escaping
WP All Import – Property Import for Real Places Attack Surface
WordPress Hooks 16
Maintenance & Trust
WP All Import – Property Import for Real Places Maintenance & Trust
Maintenance Signals
Community Trust
WP All Import – Property Import for Real Places Alternatives
WP All Import – Property Import for RealHomes
realhomes-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for WP Residence
wp-residence-add-on-for-wp-all-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Pro Real Estate 7
wp-pro-real-estate-7-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Reales WP
reales-wp-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Realia
realia-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for Real Places Developer Profile
22 plugins · 207K total installs
How We Detect WP All Import – Property Import for Real Places
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/realplaces-xml-csv-property-listings-import/assets/css/rtl.css/wp-content/plugins/realplaces-xml-csv-property-listings-import/assets/css/realplaces-import.css/wp-content/plugins/realplaces-xml-csv-property-listings-import/assets/js/realplaces-import.js/wp-content/plugins/realplaces-xml-csv-property-listings-import/assets/js/realplaces-import.jsrealplaces-xml-csv-property-listings-import/assets/css/rtl.css?ver=realplaces-xml-csv-property-listings-import/assets/css/realplaces-import.css?ver=realplaces-xml-csv-property-listings-import/assets/js/realplaces-import.js?ver=HTML / DOM Fingerprints
realplaces_import_options