
AEIOU Security & Risk Analysis
wordpress.org/plugins/aeiouMake a full user backup, restore wherever you want!
Is AEIOU Safe to Use in 2026?
Generally Safe
Score 85/100AEIOU has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'aeiou' plugin v0.7 exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and all identified SQL queries are properly prepared, mitigating risks of SQL injection. The plugin also avoids making external HTTP requests and does not appear to bundle any external libraries, which are positive security indicators.
However, there are notable areas for concern. The analysis reveals two taint flows with unsanitized paths, indicating potential vulnerabilities if these flows are reachable through user input. Furthermore, a significant weakness is the lack of proper output escaping, with only 4% of outputs being correctly escaped. This widespread issue presents a high risk of cross-site scripting (XSS) vulnerabilities, as untrusted data could be rendered directly in the browser.
The vulnerability history is entirely clean, with no recorded CVEs. While this is a positive sign, it must be considered alongside the identified code-level risks. The lack of past vulnerabilities might be due to the plugin's limited functionality or simply a lack of past security audits. The absence of nonce and capability checks, particularly in conjunction with the identified taint flows and poor output escaping, suggests that even if the attack surface were larger, there are insufficient security controls in place.
Key Concerns
- Unsanitized paths in taint flows
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
AEIOU Security Vulnerabilities
AEIOU Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
AEIOU Attack Surface
WordPress Hooks 2
Maintenance & Trust
AEIOU Maintenance & Trust
Maintenance Signals
Community Trust
AEIOU Alternatives
Export and Import Users and Customers
users-customers-import-export-for-wp-woocommerce
Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.
Simple Membership WP user Import
simple-membership-wp-user-import
An addon for importing existing WordPress users to the Simple Membership plugin as members
Import Users & Customers | Export Users with Excel for WordPress & WooCommerce
users-import-export-with-excel-for-wp
WordPress Plugin to import Users and export Users with Excel for WordPress and WooCommerce Customers Import Export
Import Users from CSV
import-users-from-csv
Import users from a CSV into WordPress
Export User Data
export-user-data
Export users data and metadata to a csv or Excel file
AEIOU Developer Profile
2 plugins · 20 total installs
How We Detect AEIOU
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- Export made with Wordpress AEIOU by toSend.it di Luisa Marra (http://tosend.it/) -->keyoptionglobalbase_idgroupname