
WPCasa All Import Security & Risk Analysis
wordpress.org/plugins/wpcasa-all-importAdd-on for the WP All Import plugin to import any XML or CSV File to WPCasa
Is WPCasa All Import Safe to Use in 2026?
Generally Safe
Score 100/100WPCasa All Import has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpcasa-all-import" v1.1.2 plugin demonstrates several good security practices, including the absence of known CVEs and the exclusive use of prepared statements for SQL queries. The static analysis reports a zero attack surface from common entry points like AJAX handlers, REST API routes, and shortcodes, and no cron events, which is a strong indicator of a well-secured plugin. However, there are significant concerns arising from the code analysis. The presence of the `unserialize` function without any apparent input validation or sanitization is a critical risk, as it can lead to Remote Code Execution (RCE) vulnerabilities if an attacker can control the serialized data. The limited proper output escaping (43%) also poses a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-controlled data is being outputted without adequate sanitization. The lack of nonce and capability checks on the identified entry points further exacerbates these risks, leaving the plugin vulnerable to unauthorized actions. The vulnerability history being clean is positive, but it cannot mitigate the inherent risks identified in the code itself, which could be present even if undiscovered or exploited.
Key Concerns
- Dangerous function 'unserialize' used without checks
- Low percentage of properly escaped output
- No nonce checks found
- No capability checks found
WPCasa All Import Security Vulnerabilities
WPCasa All Import Code Analysis
Dangerous Functions Found
Output Escaping
WPCasa All Import Attack Surface
WordPress Hooks 16
Maintenance & Trust
WPCasa All Import Maintenance & Trust
Maintenance Signals
Community Trust
WPCasa All Import Alternatives
Property Hive
propertyhive
Building a property website? Property Hive has everything you need to get started, and so much more.
Custom Product Tabs for WooCommerce WP All Import Add-on
custom-product-tabs-wp-all-import-add-on
This add-on extends Custom Product Tabs for WooCommerce to work with WP All Import.
Houzez Property Feed
houzez-property-feed
Automatically import properties to Houzez from estate agency CRMs and export to portals
WP All Import – Property Import for RealHomes
realhomes-xml-csv-property-listings-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WP All Import – Property Import for WP Residence
wp-residence-add-on-for-wp-all-import
Drag & drop to import real estate listings from any CSV, XML, Excel, or Google Sheets file of any size or format. Supports images, floor plans, am …
WPCasa All Import Developer Profile
10 plugins · 3K total installs
How We Detect WPCasa All Import
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcasa-all-import/css/wpcasa-all-import.css/wp-content/plugins/wpcasa-all-import/js/wpcasa-all-import.jswpcasa-all-import/css/wpcasa-all-import.css?ver=wpcasa-all-import/js/wpcasa-all-import.js?ver=HTML / DOM Fingerprints
<!-- Custom price before text (for upcoming WPCasa version) --><!-- Custom price after text (for upcoming WPCasa version) -->data-wpsight-all-import-fielddata-wpsight-all-import-field-wrap