WP All Import – WP Job Manager Field Editor Add-On Security & Risk Analysis

wordpress.org/plugins/smyles-wp-job-manager-field-editor-import

Support for custom fields created with WP Job Manager Field Editor when importing Jobs or Resumes using WP All Import

100 active installs v1.0.3 PHP 5.4+ WP 4.7+ Updated Aug 8, 2019
import-directoryimport-job-listingsimport-listingsjob-directorywp-job-manager
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP All Import – WP Job Manager Field Editor Add-On Safe to Use in 2026?

Generally Safe

Score 85/100

WP All Import – WP Job Manager Field Editor Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "smyles-wp-job-manager-field-editor-import" plugin v1.0.3 presents a mixed security posture. On one hand, the absence of known CVEs and a clean taint analysis are positive indicators, suggesting the plugin has a history of being relatively secure and free from critical vulnerabilities in its code execution paths. The use of prepared statements for all SQL queries is also a strong security practice, mitigating risks of SQL injection.

However, the static analysis reveals several significant concerns. The presence of the `unserialize` function without any apparent safeguards is a critical risk. If user-supplied data is passed to `unserialize`, it can lead to object injection vulnerabilities, allowing attackers to potentially execute arbitrary code. Furthermore, the low percentage of properly escaped output (38%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as sensitive data displayed to users might not be properly neutralized. The lack of nonce checks and capability checks on any entry points, although the attack surface appears minimal, leaves any potential future entry points vulnerable to unauthorized actions or information disclosure.

Given the lack of historical vulnerabilities, it's possible that the identified risks have not yet been exploited or are mitigated by external factors. However, the presence of a dangerous function like `unserialize` and significant output escaping issues represent immediate and serious threats that must be addressed. The plugin's strengths lie in its SQL query handling and lack of known historical exploits, but its weaknesses in handling serialized data and output sanitization are significant and require immediate attention.

Key Concerns

  • Dangerous function 'unserialize' used
  • Low percentage of output escaping (38%)
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

WP All Import – WP Job Manager Field Editor Add-On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP All Import – WP Job Manager Field Editor Add-On Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
8
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$fieldData = (!empty($field_params['field_obj']->post_content)) ? unserialize($field_params['field_orapid-addon.php:551

Output Escaping

38% escaped13 total outputs
Attack Surface

WP All Import – WP Job Manager Field Editor Add-On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
filterpmxi_custom_field_to_updateintegration.php:78
filterpmxi_custom_fieldintegration.php:79
filterwp_all_import_is_show_add_new_imagesintegration.php:352
filterwp_all_import_is_allow_import_imagesintegration.php:355
filterpmxi_addonsrapid-addon.php:144
filterwp_all_import_addon_parserapid-addon.php:145
filterwp_all_import_addon_importrapid-addon.php:146
filterwp_all_import_addon_saved_postrapid-addon.php:147
filterpmxi_options_optionsrapid-addon.php:148
filterwp_all_import_image_sectionsrapid-addon.php:149
filterpmxi_custom_typesrapid-addon.php:150
filterpmxi_post_list_orderrapid-addon.php:151
filterwp_all_import_post_type_imagerapid-addon.php:152
actionpmxi_extend_options_featuredrapid-addon.php:153
actionadmin_initrapid-addon.php:154
filterwp_all_import_acf_is_show_grouprapid-addon.php:219
filterwp_all_import_is_show_add_new_imagesrapid-addon.php:912
filterwp_all_import_is_allow_import_imagesrapid-addon.php:915
filterwp_all_import_is_images_section_enabledrapid-addon.php:958
actionadmin_noticesrapid-addon.php:1153
actionadmin_noticeswp-job-manager-field-editor-addon.php:37
actionplugins_loadedwp-job-manager-field-editor-addon.php:150
Maintenance & Trust

WP All Import – WP Job Manager Field Editor Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 8, 2019
PHP min version5.4
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

WP All Import – WP Job Manager Field Editor Add-On Developer Profile

tripflex

9 plugins · 900 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP All Import – WP Job Manager Field Editor Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smyles-wp-job-manager-field-editor-import/css/main.css/wp-content/plugins/smyles-wp-job-manager-field-editor-import/js/main.js
Script Paths
/wp-content/plugins/smyles-wp-job-manager-field-editor-import/js/main.js
Version Parameters
smyles-wp-job-manager-field-editor-import/css/main.css?ver=smyles-wp-job-manager-field-editor-import/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpjm-fe-import-notice
HTML Comments
WP All Import - WP Job Manager Field Editor Add-OnSupport importing listings in WP Job Manager, with support for WP Job Manager Field Editor custom fieldsMyles McNamarahttp://plugins.smyl.es+5 more
JS Globals
field_editor_import_multi_filesfield_editor_import_multi_field
FAQ

Frequently Asked Questions about WP All Import – WP Job Manager Field Editor Add-On