
WP All Import – Job Listing Import for WP Job Manager Security & Risk Analysis
wordpress.org/plugins/wp-job-manager-xml-csv-listings-importDrag & drop to import job listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports company info, locations, applic …
Is WP All Import – Job Listing Import for WP Job Manager Safe to Use in 2026?
Generally Safe
Score 100/100WP All Import – Job Listing Import for WP Job Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-job-manager-xml-csv-listings-import" v1.2.1 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known historical vulnerabilities. The attack surface appears minimal, with no reported AJAX handlers, REST API routes, shortcodes, or cron events exposed, further reducing direct entry points for attackers. However, the static analysis reveals significant concerns. The presence of the `unserialize` function is a known risk, especially if the input to this function is not strictly controlled. Taint analysis indicates two flows with unsanitized paths, both flagged as high severity. This, combined with the lack of nonce checks and capability checks on any entry points (though the static analysis indicates zero entry points, the taint analysis suggests otherwise for sensitive operations), creates a potential for privilege escalation or data manipulation if the unsanitized inputs can be controlled by an attacker.
While the plugin boasts a clean vulnerability history, this does not negate the risks identified in the code. The high-severity taint flows and the use of `unserialize` are critical indicators of potential security weaknesses that could be exploited. The lack of capability checks, in particular, is a concerning omission if these unsanitized paths involve sensitive operations. The plugin's strengths lie in its SQL handling and lack of historical CVEs, but its weaknesses in input sanitization and authorization checks present a tangible risk that needs careful consideration. Users should proceed with caution and ensure robust input validation is in place if this plugin is used in a production environment.
Key Concerns
- High severity taint flow found
- High severity taint flow found
- Dangerous function: unserialize
- No nonce checks
- No capability checks
- Unsanitized path in taint flow
- Unsanitized path in taint flow
- Output escaping is not fully proper
WP All Import – Job Listing Import for WP Job Manager Security Vulnerabilities
WP All Import – Job Listing Import for WP Job Manager Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP All Import – Job Listing Import for WP Job Manager Attack Surface
WordPress Hooks 18
Maintenance & Trust
WP All Import – Job Listing Import for WP Job Manager Maintenance & Trust
Maintenance Signals
Community Trust
WP All Import – Job Listing Import for WP Job Manager Alternatives
WP All Import – Job Listing Import for Jobify
jobify-xml-csv-listings-import
Drag & drop to import job listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports company info, locations, catego …
WP All Import – WP Job Manager Field Editor Add-On
smyles-wp-job-manager-field-editor-import
Support for custom fields created with WP Job Manager Field Editor when importing Jobs or Resumes using WP All Import
WP All Import – Listings Import for Listable
import-xml-csv-listings-to-listable-theme
Drag & drop to import directory listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, categories, locat …
WP All Import – Listings Import for Listify
listify-xml-csv-listings-import
Drag & drop to import directory listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, categories, locat …
Import Listings into the PointFinder Theme
pointfinder-xml-csv-listings-import
Easily import listings from any XML or CSV file to the PointFinder theme with the PointFinder Add-On for WP All Import.
WP All Import – Job Listing Import for WP Job Manager Developer Profile
22 plugins · 207K total installs
How We Detect WP All Import – Job Listing Import for WP Job Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-job-manager-xml-csv-listings-import/css/main.css/wp-content/plugins/wp-job-manager-xml-csv-listings-import/js/main.js/wp-content/plugins/wp-job-manager-xml-csv-listings-import/js/main.js/wp-content/plugins/wp-job-manager-xml-csv-listings-import/css/main.css?ver=/wp-content/plugins/wp-job-manager-xml-csv-listings-import/js/main.js?ver=HTML / DOM Fingerprints
data-id