WP All Import – Property Import for Pro Real Estate 7 Security & Risk Analysis

wordpress.org/plugins/wp-pro-real-estate-7-xml-csv-property-listings-import

Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …

100 active installs v1.0.6 PHP + WP 4.1.0+ Updated Jan 30, 2026
import-propertiesimport-property-listingsimport-real-estateimport-real-estate-listingsreal-estate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP All Import – Property Import for Pro Real Estate 7 Safe to Use in 2026?

Generally Safe

Score 100/100

WP All Import – Property Import for Pro Real Estate 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin 'wp-pro-real-estate-7-xml-csv-property-listings-import' v1.0.6 exhibits a mixed security posture. On the positive side, the static analysis reveals no known CVEs and a complete absence of raw SQL queries, demonstrating good practice in database interaction. Furthermore, there are no identified REST API routes, shortcodes, or cron events, and notably, no AJAX handlers or REST API routes that lack authentication checks, significantly reducing the plugin's attack surface from external entry points.

However, the analysis does flag several areas of concern. The presence of the 'unserialize' function is a significant risk, as it can be exploited for remote code execution if user-supplied data is unserialized without proper validation. The low percentage of properly escaped output (45%) indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. Additionally, the absence of nonce checks and capability checks on any potential (though not identified as exposed) code paths is worrying, as it implies a reliance on the WordPress core for all authorization, which might not be sufficient if internal functions are somehow triggered.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, but it doesn't negate the risks identified in the current code analysis. The combination of a seemingly low external attack surface with a critical function like 'unserialize' and insufficient output escaping presents a moderate risk. While the lack of history is good, the code itself contains elements that require careful attention and potential remediation to ensure robust security.

Key Concerns

  • Dangerous function 'unserialize' used
  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP All Import – Property Import for Pro Real Estate 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP All Import – Property Import for Pro Real Estate 7 Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$fieldData = (!empty($field_params['field_obj']->post_content)) ? unserialize($field_params['field_orapid-addon.php:551

Output Escaping

45% escaped11 total outputs
Attack Surface

WP All Import – Property Import for Pro Real Estate 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
filterpmxi_addonsrapid-addon.php:144
filterwp_all_import_addon_parserapid-addon.php:145
filterwp_all_import_addon_importrapid-addon.php:146
filterwp_all_import_addon_saved_postrapid-addon.php:147
filterpmxi_options_optionsrapid-addon.php:148
filterwp_all_import_image_sectionsrapid-addon.php:149
filterpmxi_custom_typesrapid-addon.php:150
filterpmxi_post_list_orderrapid-addon.php:151
filterwp_all_import_post_type_imagerapid-addon.php:152
actionpmxi_extend_options_featuredrapid-addon.php:153
actionadmin_initrapid-addon.php:154
filterwp_all_import_acf_is_show_grouprapid-addon.php:219
filterwp_all_import_is_show_add_new_imagesrapid-addon.php:912
filterwp_all_import_is_allow_import_imagesrapid-addon.php:915
filterwp_all_import_is_images_section_enabledrapid-addon.php:958
actionadmin_noticesrapid-addon.php:1153
actionpmxi_saved_postwp-pro-realestate-7-add-on.php:702
Maintenance & Trust

WP All Import – Property Import for Pro Real Estate 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

WP All Import – Property Import for Pro Real Estate 7 Developer Profile

WP All Import

22 plugins · 207K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1036 days
View full developer profile
Detection Fingerprints

How We Detect WP All Import – Property Import for Pro Real Estate 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-pro-real-estate-7-xml-csv-property-listings-import/css/style.css/wp-content/plugins/wp-pro-real-estate-7-xml-csv-property-listings-import/js/script.js/wp-content/plugins/wp-pro-real-estate-7-xml-csv-property-listings-import/css/wp-pro-real-estate-7.css/wp-content/plugins/wp-pro-real-estate-7-xml-csv-property-listings-import/js/wp-pro-real-estate-7.js
Script Paths
/wp-content/plugins/wp-pro-real-estate-7-xml-csv-property-listings-import/js/script.js
Version Parameters
wp-pro-real-estate-7-xml-csv-property-listings-import/style.css?ver=wp-pro-real-estate-7-xml-csv-property-listings-import/css/wp-pro-real-estate-7.css?ver=wp-pro-real-estate-7-xml-csv-property-listings-import/js/wp-pro-real-estate-7.js?ver=

HTML / DOM Fingerprints

CSS Classes
wppre_addon
Data Attributes
data-wppre-property-addressdata-wppre-property-latitudedata-wppre-property-longitude
JS Globals
wppre_addon
FAQ

Frequently Asked Questions about WP All Import – Property Import for Pro Real Estate 7