
WP All Import – WP Job Manager Field Editor Add-On Security & Risk Analysis
wordpress.org/plugins/smyles-wp-job-manager-field-editor-importSupport for custom fields created with WP Job Manager Field Editor when importing Jobs or Resumes using WP All Import
Is WP All Import – WP Job Manager Field Editor Add-On Safe to Use in 2026?
Generally Safe
Score 85/100WP All Import – WP Job Manager Field Editor Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smyles-wp-job-manager-field-editor-import" plugin v1.0.3 presents a mixed security posture. On one hand, the absence of known CVEs and a clean taint analysis are positive indicators, suggesting the plugin has a history of being relatively secure and free from critical vulnerabilities in its code execution paths. The use of prepared statements for all SQL queries is also a strong security practice, mitigating risks of SQL injection.
However, the static analysis reveals several significant concerns. The presence of the `unserialize` function without any apparent safeguards is a critical risk. If user-supplied data is passed to `unserialize`, it can lead to object injection vulnerabilities, allowing attackers to potentially execute arbitrary code. Furthermore, the low percentage of properly escaped output (38%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as sensitive data displayed to users might not be properly neutralized. The lack of nonce checks and capability checks on any entry points, although the attack surface appears minimal, leaves any potential future entry points vulnerable to unauthorized actions or information disclosure.
Given the lack of historical vulnerabilities, it's possible that the identified risks have not yet been exploited or are mitigated by external factors. However, the presence of a dangerous function like `unserialize` and significant output escaping issues represent immediate and serious threats that must be addressed. The plugin's strengths lie in its SQL query handling and lack of known historical exploits, but its weaknesses in handling serialized data and output sanitization are significant and require immediate attention.
Key Concerns
- Dangerous function 'unserialize' used
- Low percentage of output escaping (38%)
- No nonce checks found
- No capability checks found
WP All Import – WP Job Manager Field Editor Add-On Security Vulnerabilities
WP All Import – WP Job Manager Field Editor Add-On Code Analysis
Dangerous Functions Found
Output Escaping
WP All Import – WP Job Manager Field Editor Add-On Attack Surface
WordPress Hooks 22
Maintenance & Trust
WP All Import – WP Job Manager Field Editor Add-On Maintenance & Trust
Maintenance Signals
Community Trust
WP All Import – WP Job Manager Field Editor Add-On Alternatives
WP All Import – Job Listing Import for WP Job Manager
wp-job-manager-xml-csv-listings-import
Drag & drop to import job listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports company info, locations, applic …
WP All Import – Job Listing Import for Jobify
jobify-xml-csv-listings-import
Drag & drop to import job listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports company info, locations, catego …
WP All Import – Listings Import for Listable
import-xml-csv-listings-to-listable-theme
Drag & drop to import directory listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, categories, locat …
WP All Import – Listings Import for Listify
listify-xml-csv-listings-import
Drag & drop to import directory listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, categories, locat …
Import Listings into the PointFinder Theme
pointfinder-xml-csv-listings-import
Easily import listings from any XML or CSV file to the PointFinder theme with the PointFinder Add-On for WP All Import.
WP All Import – WP Job Manager Field Editor Add-On Developer Profile
9 plugins · 900 total installs
How We Detect WP All Import – WP Job Manager Field Editor Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smyles-wp-job-manager-field-editor-import/css/main.css/wp-content/plugins/smyles-wp-job-manager-field-editor-import/js/main.js/wp-content/plugins/smyles-wp-job-manager-field-editor-import/js/main.jssmyles-wp-job-manager-field-editor-import/css/main.css?ver=smyles-wp-job-manager-field-editor-import/js/main.js?ver=HTML / DOM Fingerprints
wpjm-fe-import-noticeWP All Import - WP Job Manager Field Editor Add-OnSupport importing listings in WP Job Manager, with support for WP Job Manager Field Editor custom fieldsMyles McNamarahttp://plugins.smyl.es+5 morefield_editor_import_multi_filesfield_editor_import_multi_field