
Import into Schema.org by WordLift Security & Risk Analysis
wordpress.org/plugins/wordlift-add-on-for-wp-all-importEasily import structured data and schema.org settings from any XML or CSV file to WordLift knowledge graph.
Is Import into Schema.org by WordLift Safe to Use in 2026?
Generally Safe
Score 85/100Import into Schema.org by WordLift has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wordlift-add-on-for-wp-all-import' plugin v1.0.1 presents a mixed security posture. On the positive side, the static analysis reveals a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication checks. Furthermore, all identified SQL queries utilize prepared statements, which is a strong security practice. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a generally stable and well-maintained codebase.
However, there are significant concerns stemming from the code analysis. The presence of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution (RCE) vulnerabilities if it processes untrusted input. The low percentage of properly escaped output (45%) indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the absence of nonce and capability checks on any entry points means that any interaction with these functions, even if not directly exposed via AJAX or REST API, could be manipulated if input validation is not robust. The single file operation also warrants scrutiny to ensure it's not susceptible to directory traversal or other file-based attacks.
In conclusion, while the plugin's limited attack surface and lack of historical vulnerabilities are commendable, the identified risks related to `unserialize`, unescaped output, and missing authorization checks are substantial. These represent potential entry points for attackers to compromise WordPress sites. Prioritizing the secure handling of unserialized data and implementing comprehensive output escaping and authorization checks would significantly improve the plugin's security.
Key Concerns
- Use of unserialize function
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
- Single file operation requires scrutiny
Import into Schema.org by WordLift Security Vulnerabilities
Import into Schema.org by WordLift Code Analysis
Dangerous Functions Found
Output Escaping
Import into Schema.org by WordLift Attack Surface
WordPress Hooks 18
Maintenance & Trust
Import into Schema.org by WordLift Maintenance & Trust
Maintenance Signals
Community Trust
Import into Schema.org by WordLift Alternatives
WP All Import – Import SEO Settings for Yoast SEO
yoast-seo-settings-xml-csv-import
Drag & drop to import from any CSV, Excel, XML, or Google Sheets file into Yoast SEO's titles, meta descriptions, focus keywords, schema sett …
WP All Import – Import SEO Settings for Rank Math SEO
import-xml-csv-settings-to-rank-math-seo
Drag & drop to import from any CSV, Excel, XML, or Google Sheets file into Rank Math SEO's titles, meta descriptions, focus keywords, schema …
WP All Import – Import SEO Settings for All In One SEO
import-xml-csv-settings-to-all-in-one-seo-pack
Drag & drop to import from any CSV, Excel, XML, or Google Sheets file into All In One SEO's titles, meta descriptions, focus keywords, schema …
BoldGrid Easy SEO – Simple and Effective SEO
boldgrid-easy-seo
Easy SEO helps you easily create keyword rich content and rank higher in the search engines.
Internal Links Manager
seo-automated-link-building
Boost your SEO and get better rankings with our automated link building plugin. With this plugin you can link any keyword to any URL - internal or ext …
Import into Schema.org by WordLift Developer Profile
3 plugins · 40 total installs
How We Detect Import into Schema.org by WordLift
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wordlift-add-on-for-wp-all-import/rapid-addon.php