shouldiuse.io

Categories

VERDICT

Should I use Smackcoders?

Trusted by 1.7M+ WordPress users worldwide. Smackcoders builds powerful plugins and custom solutions for imports, exports, CRM sync, and more. - smackcoders.com

Depends. Buy if you run WordPress and need deep CSV/CRM import-export at a one-time price — and you can patch plugins promptly. Avoid if your site handles sensitive data or you require mature vendor security and third-party validation.

Confidence

Medium. Based on 20+ public sources. Pricing amounts and verbatim user quotes not retrievable from reviewed pages.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

WP Ultimate CSV Importer Pro

One-time fee (amount not published in reviewed sources)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • WordPress sites doing bulk CSV imports
  • WooCommerce catalog and order exports
  • WordPress-to-CRM sync (Zoho, Vtiger)
  • One-time-fee buyers avoiding subscriptions

Not for

  • Security-sensitive sites (importer has CVE history)
  • Enterprise teams needing vendor security programs
  • Non-WordPress projects
  • Buyers wanting strong third-party review validation

Gotchas - check before you buy

high

CVE history demands fast patching; verify plugin version before installing

medium

Pricing opaque: one-time fee amount unpublished; discounts up to 22% appear promo-driven

medium

Support mixed: Trustpilot 4.0/49; complaints appear on PissedConsumer

low

Guess: recurring imports may lock workflows into the plugin's mapping format

Pros and cons

Pros

  • One-time pricing model on flagship importer
  • Complex imports proven: FTP, gallery mapping, meta relationships
  • Large install base: 1.7M+ users (vendor-claimed)
  • Free custom development hours bundled with purchases
  • Featured among best WordPress import plugins

Cons

  • Repeated CVEs 2024-2025, including SQL injection in SendGrid plugin
  • Missing-authorization vulnerabilities in WP Ultimate CSV Importer
  • No security page found on vendor website
  • Third-party validation thin: one G2 review, unrated seller page

Sources & method

Analyzed 9/21/2026 - 16 sources - Multiple CVEs across Smackcoders plugins in 2024-2025, including SQL injection and missing-authorization flaws in import and SendGrid plugins.

official x7review x5security x4
  • CVE-2024-43965 — SQL injection (SendGrid plugin), SQL injection vulnerability in Smackcoders SendGrid plugin, disclosed 2024.
  • CVE-2025-24611 — Path traversal, Improper limitation of a pathname to a restricted directory in a Smackcoders plugin.
  • CVE-2025-22647 — Missing authorization, Missing authorization vulnerability in a Smackcoders plugin.
  • CVE-2025-31530 — Missing authorization, Another missing-authorization flaw, disclosed March 2025.

Key stats

  • Value for money: 4/5

    Rating

  • One-time fee (amount not published in reviewed sources)

    Starting price

  • 16

    Sources

  • Analyzed

  • Value for money: 4/5. One-time pricing plus bundled dev hours
  • Ease of use: 3/5. Listed among best WordPress import plugins
  • Feature depth: 4/5. Case studies show FTP, ACF, CRM sync
  • Support quality: 3/5. Trustpilot 4.0/49; complaints elsewhere
  • Security posture: 2/5. Repeated 2024-25 CVEs, including SQLi
  • 4.0/5 Trustpilot 49 reviews
  • 1.7M+ WordPress users Vendor-claimed
  • 1 G2 reviews 5/5; seller page unrated
  • 2014 Founded India-registered (ZaubaCorp)

Pricing

WP Ultimate CSV Importer Pro

One-time fee (amount not published in reviewed sources)

  • Bulk CSV import for posts, products, users
  • Custom-field (ACF) mapping
  • FTP import and gallery mapping

Security

Multiple CVEs across Smackcoders plugins in 2024-2025, including SQL injection and missing-authorization flaws in import and SendGrid plugins.

  • CVE-2024-43965 — SQL injection (SendGrid plugin)SQL injection vulnerability in Smackcoders SendGrid plugin, disclosed 2024.12
  • CVE-2025-24611 — Path traversalImproper limitation of a pathname to a restricted directory in a Smackcoders plugin.14
  • CVE-2025-22647 — Missing authorizationMissing authorization vulnerability in a Smackcoders plugin.15
  • CVE-2025-31530 — Missing authorizationAnother missing-authorization flaw, disclosed March 2025.13

What users say

Sentiment is mildly positive on Trustpilot (4.0/5 from 49 reviews) but nearly absent on G2 (one 5/5 review), with some complaints on PissedConsumer.

Companies that use it

  • Digital Humanity10
  • Wealden Technology11
Full analysis

Based on 20+ public sources. Pricing amounts and verbatim user quotes not retrievable from reviewed pages.

Capable WordPress import/export plugins, one-time pricing — but repeated 2024-25 CVEs make it risky for sensitive data.

Methodology

Based on 20+ public sources. Pricing amounts and verbatim user quotes not retrievable from reviewed pages.

Sources

  1. official
  2. Trustpilot reviewstrustpilot.com
    review
  3. review
  4. review
  5. PissedConsumer reviewspissedconsumer.com
    review
  6. review
  7. WordPress.org profileprofiles.wordpress.org
    official
  8. official
  9. official
  10. official
  11. official
  12. security
  13. security
  14. security
  15. security
  16. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.