
WP All Import – Product Import for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-xml-csv-product-importDrag & drop to import products from any CSV, XML, Excel, or Google Sheets file. Supports variations, images, attributes, brands, and more with pow …
Is WP All Import – Product Import for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100WP All Import – Product Import for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woocommerce-xml-csv-product-import" plugin v1.5.5 presents a mixed security posture. On one hand, the absence of known CVEs and a low volume of past vulnerabilities suggest a generally stable and secure codebase. The plugin also demonstrates good practices by utilizing prepared statements for the vast majority of its SQL queries and has a limited number of external dependencies. However, the static analysis reveals several areas of concern that temper this positive outlook.
The presence of dangerous functions like `create_function` and `unserialize` is a significant red flag. `unserialize` is particularly risky when handling user-supplied data, as it can lead to object injection vulnerabilities. While the TAINT analysis indicates only one high severity flow, the potential for these dangerous functions to be exploited, especially if coupled with improperly handled input, warrants caution. Furthermore, the lack of nonce checks and capability checks on what appear to be potential entry points (even if the attack surface is currently reported as zero) is a weakness. The 68% proper output escaping rate also suggests that some outputs might be vulnerable to cross-site scripting (XSS) attacks.
In conclusion, while the plugin's vulnerability history is commendable, the presence of risky functions and a less-than-perfect output escaping rate, combined with a potential for missing critical security checks in unanalyzed code paths, mean that the plugin is not entirely without risk. Developers should prioritize mitigating the risks associated with `unserialize` and `create_function` and ensure all output is properly escaped.
Key Concerns
- Dangerous functions present (create_function, unserialize)
- High severity taint flow found
- Only 68% of outputs properly escaped
- No nonce checks
- Only 3 capability checks
WP All Import – Product Import for WooCommerce Security Vulnerabilities
WP All Import – Product Import for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP All Import – Product Import for WooCommerce Attack Surface
WordPress Hooks 14
Maintenance & Trust
WP All Import – Product Import for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WP All Import – Product Import for WooCommerce Alternatives
Product Import Export for WooCommerce – Import Export Product CSV Suite
product-import-export-for-woo
Easily import/export WooCommerce products (simple, grouped, external/affiliate) via CSV. Transfer product data, including images, reviews, categories, …
Solo Solis Product Import
solo-solis-product-import
Easily import Solo Solid products into WooCommerce store. Import WooCommerce Products from Solo Solis JSON Feed.
Product Excel Import & Export for WooCommerce
woo-product-excel-importer
WordPress Plugin to Import Products and Export Products for Woocommerce in Bulk with Excel.
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
wp-all-import
Easily import any file of any size into any plugin, post type, custom field, or taxonomy. Supports WooCommerce, ACF, images, galleries, users, real es …
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
WP All Import – Product Import for WooCommerce Developer Profile
4 plugins · 124K total installs
How We Detect WP All Import – Product Import for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-xml-csv-product-import/static/css/styles.css/wp-content/plugins/woocommerce-xml-csv-product-import/static/js/main.js/wp-content/plugins/woocommerce-xml-csv-product-import/static/js/product-importer.js/wp-content/plugins/woocommerce-xml-csv-product-import/static/css/admin.css/wp-content/plugins/woocommerce-xml-csv-product-import/static/js/main.js/wp-content/plugins/woocommerce-xml-csv-product-import/static/js/product-importer.jswoocommerce-xml-csv-product-import/static/css/styles.css?ver=woocommerce-xml-csv-product-import/static/js/main.js?ver=woocommerce-xml-csv-product-import/static/js/product-importer.js?ver=woocommerce-xml-csv-product-import/static/css/admin.css?ver=HTML / DOM Fingerprints
wpai-import-woocommerce-add-ondata-plugin-root-urlpmwi_import_scripts