Manueller Datenexport von WooCommerce nach Lexware Security & Risk Analysis

wordpress.org/plugins/adlib-woo2lex-manuell

Exports not yet exported orders from woocommerce to a xml-file for Lexware - format is openTRANS. On demand only completed orders are exported.

40 active installs v1.0.4 PHP + WP + Updated Jan 23, 2026
exportlexwareopentransorderwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Manueller Datenexport von WooCommerce nach Lexware Safe to Use in 2026?

Generally Safe

Score 100/100

Manueller Datenexport von WooCommerce nach Lexware has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The adlib-woo2lex-manuell plugin v1.0.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and avoids making external HTTP requests, which are common vectors for vulnerabilities. The absence of any recorded CVEs also suggests a relatively clean history and potentially thorough prior security auditing.

However, several significant concerns emerge from the static analysis. The complete lack of nonce checks and capability checks, especially with 71 file operations performed, creates a substantial risk. This indicates that any user, regardless of their logged-in status or role, could potentially trigger file operations, leading to unauthorized modifications or data exposure. Furthermore, the fact that 100% of its outputs are not properly escaped is a critical security flaw. This leaves the plugin highly susceptible to cross-site scripting (XSS) attacks, where malicious code could be injected and executed in the user's browser.

While the plugin has no known CVEs and an empty vulnerability history, this does not inherently guarantee its safety. The identified issues in output escaping and the absence of essential security checks like nonces and capability checks represent immediate and severe risks. The plugin's strengths in SQL handling are overshadowed by these critical weaknesses, necessitating immediate attention.

Key Concerns

  • All output is unescaped
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Manueller Datenexport von WooCommerce nach Lexware Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Manueller Datenexport von WooCommerce nach Lexware Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
11 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
71
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared11 total queries

Output Escaping

0% escaped3 total outputs
Attack Surface

Manueller Datenexport von WooCommerce nach Lexware Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuadlib-woo2lex-manuell.php:35
actioninitadlib-woo2lex-manuell.php:36
Maintenance & Trust

Manueller Datenexport von WooCommerce nach Lexware Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 23, 2026
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Manueller Datenexport von WooCommerce nach Lexware Developer Profile

Odido

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Manueller Datenexport von WooCommerce nach Lexware

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/adlib-woo2lex-manuell/export.png

HTML / DOM Fingerprints

Data Attributes
id="export"value="Exportbutton"
Shortcode Output
<img alt="PayPal" src="paypal.png"></img>
FAQ

Frequently Asked Questions about Manueller Datenexport von WooCommerce nach Lexware