WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
by WP All Import · Content & Feeds
Also makes 18 other plugins · 227.1K+ installs across the portfolio →
Easily import any file of any size into any plugin, post type, custom field, or taxonomy. Supports WooCommerce, ACF, images, galleries, users, real es …
90 health vs 60 average across 779 Content & Feeds plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
32.9K
now · peak 161.8K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
8
releases in the last 12 months
1mo ago
latest release · v4.1.1
88
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 41% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “100K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-03 · 1,496 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ ixian1mo ago
The product is truly awesome and support responded to my question quickly during business hours.
Read on wp.org ↗ - ★★★★★ chlustanec3mo ago
Cant do variable products. Cant do variable products. Cant do variable products. Cant do variable products. Cant do variable products.
Read on wp.org ↗ - ★★★★★ pixelshouse4mo ago
WP All Import is honestly one of the most powerful and intelligent plugins I’ve ever used in WordPress. It saved me a huge amount of time and effort when dealing with large datasets. What would normally take days of manual work, I was able to complete in a fraction of the time. The interface is very flexible and smart — you can map fields exactly the way you want, handle complex imports, and even automate the process. It works smoothly with WooCommerce and custom fields, which makes it perfect for real-world projects. What I really appreciate is how it simplifies complicated tasks. Even when working with large files or detailed product data, everything feels fast and under control. If you deal with bulk data, products, or migrations, WP All Import is not just helpful — it’s essential. Highly recommended.
Read on wp.org ↗ - ★★★★★ joezappie5mo ago
I made a bug report a few months ago, they confirmed it was a bug and gave me a work around. Told me it would take more than a few days to fix so I waited around a month and reached back out to get an update. Another 3 weeks nothing so I checked in again. Nothing. Been another few weeks and I’m not going to bother trying to get a hold of them again. Unfortunately this is a bug that makes it very difficult for us to use the plugin based on our ACF structure. We really want to to buy the scheduling subscription to automate our imports monthly, but with this bug I cant justify it. This topic was modified 3 months, 3 weeks ago by joezappie.
Read on wp.org ↗ - ★★★★★ emdiadesign6mo ago
No UX/UI, Almost none importable without premium and it doesn’t even show custom taxonomies. Just throw that plugin into the bin. This topic was modified 4 months, 1 week ago by emdiadesign.
Read on wp.org ↗ - ★★★★★ zhayter886mo ago
I’ve been using the pro version of this plugin for 8 years now and it’s consistently been a great experience. As with all new software there’s a learning curve, but this one was worth it. I couldn’t manage a e-commerce site with a catalogue of over 600 products without it.
Read on wp.org ↗ - ★★★★★ koupmi6mo ago
You have zero knowledge about user interface. Zero. So i clicked on export all post from CPT. I clicked on import all post to CPT. What happened? First attempt – 228 new imported blank posts Second attempt – 228 rewrited post with blank title and blank content So i have to now fix my database from backup, because you are not able make it simple for users, click on export click on import. No instead you set default rules what gonna destroy database. Great Great job, i go now vibecode new plugin what will work 1000% better than yours!
Read on wp.org ↗ - ★★★★★ adw2597mo ago
Wp All Import is a very well-written application with lots of granular control. I’ve used it to migrate hundreds of listings from one website to another with ease!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 4.1.1 security improvement: hardening of inline PHP execution restriction 4.1.1
- — Version 4.1.0 security improvement: hardening of database queries improvement: ported new add-on API API: pmxi_fire_hooks, pmxi_disabled_delete_missing_options, pmxi_hidden_delete_missing_options, pmxi_status_of_removed_options, pmxi_ 4.1.0
- — Version 4.0.1 security improvement: fixes CVE-2026-2830 maintenance: update packages 4.0.1
- — Version 4.0.0 NOTE: inline PHP execution is disabled when both DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS are set in wp-config.php security improvement: fixes CVE-2025-12733 maintenance: update PhpSpreadsheet 4.0.0
- — Version 3.9.6 fix: hierarchical taxonomy terms are not imported correctly fix: JS error in some cases with certain field names 3.9.6
- — Version 3.9.5 improvement: upgrade svg-sanitize library 3.9.5
Known vulnerabilities
via Wordfence Intelligence23 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-06-26 CVE-2026-57628 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.0.1 Patched in 4.1.0
- 2026-03-05 CVE-2026-2830 Improper Control of Generation of Code ('Code Injection') Affects <= 4.0.0 Patched in 4.0.1
- 2025-11-12 CVE-2025-12733 Improper Control of Generation of Code ('Code Injection') Affects <= 3.9.6 Patched in 4.0.0
- 2025-09-09 CVE-2025-10001 Unrestricted Upload of File with Dangerous Type Affects <= 3.9.3 Patched in 3.9.4
- 2025-04-07 CVE-2014-2054 Dependency on Vulnerable Third-Party Component Affects <= 3.8.0 Patched in 3.9.0
- 2023-12-29 CVE-2023-7082 Unrestricted Upload of File with Dangerous Type Affects < 3.7.3 Patched in 3.7.3
- 2022-10-17 CVE-2022-2711 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.6.8 Patched in 3.6.9
- Medium · 6.5 Import any XML or CSV File to WordPress <= 3.6.8 - Authenticated (Administrator+) Arbitrary File Upload ↗2022-10-17 CVE-2022-3418 Unrestricted Upload of File with Dangerous Type Affects <= 3.6.8 Patched in 3.6.9
- 2022-07-01 CVE-2022-2268 Improper Control of Generation of Code ('Code Injection') Affects <= 3.6.7 Patched in 3.6.8
- 2022-06-30 CVE-2022-1565 Unrestricted Upload of File with Dangerous Type Affects <= 3.6.7 Patched in 3.6.8
- 2022-06-28 CVE-2022-36386 Improper Control of Generation of Code ('Code Injection') Affects <= 3.6.7 Patched in 3.6.8
- 2022-06-02 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.6 Patched in 3.6.7
- Medium · 4.8 Import any XML or CSV File to WordPress <= 3.6.2 - Authenticated Stored Cross-Site Scripting ↗2021-11-02 CVE-2021-24714 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.6.3 Patched in 3.6.3
- 2020-02-19 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.2.4 Patched in 3.2.5
- Medium · 6.3 Import any XML or CSV File to WordPress <= 3.2.4 - Missing Authorization and Cross-Site Request Forgery Checks ↗2020-02-19 Missing Authorization Affects <= 3.2.4 Patched in 3.2.5
- Medium · 6.1 WP All Import <= 3.4.5 - Cross-Site Scripting ↗2018-03-08 CVE-2018-0546 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.4.6 Patched in 3.4.6
- Medium · 6.1 WP All Import <= 3.4.6 - Cross-Site Scripting ↗2018-03-08 CVE-2018-0547 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.4.7 Patched in 3.4.7
- 2018-03-07 CVE-2018-20978 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.4.7 Patched in 3.4.7
- 2017-10-08 CVE-2017-18567 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.4.6 Patched in 3.4.6
- 2015-03-12 CVE-2015-9330 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.2.5 Patched in 3.2.5
- 2015-02-26 CVE-2015-9329 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.4 Patched in 3.2.5
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 59 languages, 2 at 90% or more
Plus 35 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Import WP – Export and Import CSV and XML files to WordPress 4K+ installs · 4.3★ · 5 shared tags A -
Get Use APIs – JSON Content Importer 5K+ installs · 4.8★ · 2 shared tags A -
WP All Export – Order Export for WooCommerce 3K+ installs · 3.9★ · 2 shared tags B -
WP All Export – User Export Add-On 2K+ installs · 3.8★ · 2 shared tags B -
Import into Easy Property Listings 1K+ installs · 4.0★ · 2 shared tags B -
WP Smart Import : Import any XML File to WordPress 900+ installs · 3.9★ · 2 shared tags B
Embed this report card
Drop a live Pulse card for WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wp-all-import" width="480" height="300" style="border:0" loading="lazy" title="WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets — Plugin Pulse"></iframe> WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets: 100K+ active installs, 4.7★ (1,962 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/wp-all-import