Template Kit – Import Security & Risk Analysis

wordpress.org/plugins/template-kit-import

Use this plugin to import Template Kits to WordPress

400K active installs v1.0.16 PHP 5.6+ WP 5.3+ Updated Aug 1, 2024
elementortemplatetemplates
92
A · Safe
CVEs total1
Unpatched0
Last CVEApr 1, 2024
Download
Safety Verdict

Is Template Kit – Import Safe to Use in 2026?

Generally Safe

Score 92/100

Template Kit – Import has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 1, 2024Updated 1yr ago
Risk Assessment

The template-kit-import plugin v1.0.16 exhibits a generally strong security posture, with excellent adherence to best practices such as using prepared statements for all SQL queries and properly escaping the vast majority of output. The code analysis reveals a very small attack surface, with only one AJAX handler and no unprotected entry points. Furthermore, the taint analysis showed no critical or high severity flows, indicating a lack of immediate, high-impact vulnerabilities within the current code.

However, the plugin's vulnerability history is a significant concern. While there are no currently unpatched vulnerabilities, a past medium severity vulnerability related to 'Unrestricted Upload of File with Dangerous Type' highlights a recurring area of risk. This type of vulnerability can lead to severe security breaches if not properly mitigated. The existence of this past vulnerability, even if patched, suggests that the developers may have struggled with secure file handling in the past, and future issues in this area are a possibility.

In conclusion, the plugin demonstrates good secure coding practices in many areas, particularly with data sanitization and access control. The minimal attack surface and absence of critical taint flows are positive indicators. Nevertheless, the historical medium vulnerability regarding file uploads warrants caution. While the current version appears secure based on static analysis, continuous vigilance and thorough security audits, especially around file handling, are recommended.

Key Concerns

  • Past medium severity vulnerability found
  • Past vulnerability type: Unrestricted file upload
Vulnerabilities
1 published

Template Kit – Import Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-2334medium · 6.4Unrestricted Upload of File with Dangerous Type

Template Kit – Import <= 1.0.14 - Authenticated(Author+) Stored Cross-Site Scripting via template upload

Apr 1, 2024 Patched in 1.0.15 (122d)
Version History

Template Kit – Import Release Timeline

v1.0.16Current96 files changed
v1.0.1511 files changed
v1.0.141 CVE3 files changed
v1.0.131 CVE15 files changed
v1.0.121 CVE4 files changed
v1.0.111 CVE21 files changed
v1.0.101 CVE6 files changed
v1.0.91 CVE20 files changed
v1.0.81 CVE8 files changed
v1.0.71 CVE5 files changed
v1.0.61 CVE18 files changed
v1.0.51 CVE9 files changed
v1.0.41 CVE22 files changed
v1.0.31 CVE131 files changed
v1.0.21 CVE4 files changed
v1.0.11 CVE22 files changed
v1.0.01 CVE
v1.0.0-RC21 CVE17 files changed
Code Analysis
Analyzed Mar 16, 2026

Template Kit – Import Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
69 escaped
Nonce Checks
1
Capability Checks
8
File Operations
2
External Requests
3
Bundled Libraries
0

Output Escaping

93% escaped74 total outputs
Attack Surface

Template Kit – Import Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_template_kit_importinc\backend\class-rest.php:40
WordPress Hooks 14
actionelementor/editor/before_enqueue_scriptsinc\backend\class-elementor-modal.php:30
actionelementor/preview/enqueue_stylesinc\backend\class-elementor-modal.php:32
actionadmin_headinc\backend\class-options.php:30
actionelementor/editor/before_enqueue_scriptsinc\backend\class-options.php:31
actionelementor/preview/enqueue_stylesinc\backend\class-options.php:32
actionrest_api_initinc\backend\class-rest.php:38
actionbefore_delete_postinc\backend\class-template-kits.php:29
actionadmin_menuinc\class-plugin.php:38
actionadmin_initinc\class-plugin.php:39
actionplugins_loadedinc\class-plugin.php:40
filterbig_image_size_thresholdinc\utils\class-limits.php:33
actionplugins_loadedtemplate-kit-import.php:51
actionadmin_noticestemplate-kit-import.php:54
actionadmin_noticestemplate-kit-import.php:56
Maintenance & Trust

Template Kit – Import Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedAug 1, 2024
PHP min version5.6
Downloads1.3M

Community Trust

Rating68/100
Number of ratings16
Active installs400K
Developer Profile

Template Kit – Import Developer Profile

envato

2 plugins · 408K total installs

82
trust score
Avg Security Score
92/100
Avg Patch Time
68 days
View full developer profile
Detection Fingerprints

How We Detect Template Kit – Import

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/template-kit-import/assets/custom/elementor-modal.js/wp-content/plugins/template-kit-import/assets/react/main.css/wp-content/plugins/template-kit-import/assets/custom/elementor-modal.css/wp-content/plugins/template-kit-import/assets/react/main.js
Script Paths
/wp-content/plugins/template-kit-import/assets/custom/elementor-modal.js/wp-content/plugins/template-kit-import/assets/react/main.js
Version Parameters
template-kit-import/assets/react/main.css?ver=template-kit-import/assets/custom/elementor-modal.css?ver=template-kit-import/assets/react/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
template-kit-import-app-holder
JS Globals
window.templateKitImport
REST Endpoints
/wp-json/template-kit-import/v2
FAQ

Frequently Asked Questions about Template Kit – Import