
All Woocommerce Export Security & Risk Analysis
wordpress.org/plugins/all-woocommerce-exportExport WooCommerce Orders, products and Customers into Excel. Supports all Excel format XLS, XLSX & Mac)
Is All Woocommerce Export Safe to Use in 2026?
Generally Safe
Score 100/100All Woocommerce Export has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'all-woocommerce-export' plugin version 1.1 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of properly escaped output. It also shows no history of known vulnerabilities, which is a strong indicator of diligent development and patching in the past. However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack any authentication checks, creating direct entry points for potentially malicious actions.
The code analysis also flags the presence of the `unserialize` function, which, if used with untrusted data, can lead to remote code execution vulnerabilities. Although no taint flows with unsanitized paths were identified in this specific analysis, the presence of `unserialize` coupled with unprotected AJAX endpoints significantly elevates the risk. The absence of nonce checks on these AJAX handlers further exacerbates the security gap, leaving them vulnerable to Cross-Site Request Forgery (CSRF) attacks. While the plugin's history is clean, the current static analysis reveals critical weaknesses that require immediate attention to secure the application.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function 'unserialize' present
- Missing nonce checks on AJAX handlers
- Bundled outdated libraries (dompdf, TCPDF)
All Woocommerce Export Security Vulnerabilities
All Woocommerce Export Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
All Woocommerce Export Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
All Woocommerce Export Maintenance & Trust
Maintenance Signals
Community Trust
All Woocommerce Export Alternatives
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
woocommerce-exporter
Export WooCommerce products, orders, customers, categories, tags, subscriptions & more into formatted files like CSV, XML, Excel 2007, XLS, XLSX.
Order Export for WooCommerce
order-export-and-more-for-woocommerce
Export WooCommerce orders & export products with advanced filtering. Supports CSV & all Excel formats.
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Order Export & Order Import for WooCommerce
order-import-export-for-woocommerce
The best order export import plugin for WooCommerce. Easily import and export WooCommerce orders and WooCommerce coupons using CSV.
WP All Export – Product Export Add-On for WooCommerce
product-export-for-woocommerce
Drag & drop to export products to CSV, Excel, or XML files of any format. Supports variations, images, attributes, brands, and more with powerful …
All Woocommerce Export Developer Profile
6 plugins · 920 total installs
How We Detect All Woocommerce Export
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-woocommerce-export/css/allwoocommerceexport.css/wp-content/plugins/all-woocommerce-export/js/ajax-script.js/wp-content/plugins/all-woocommerce-export/js/ajax-script.jsall-woocommerce-export/style.css?ver=all-woocommerce-export/js/ajax-script.js?ver=HTML / DOM Fingerprints
wrapmain-titledescriptionradio_wrapperstv-radio-tablinksall-fields<!-- Main Wrapper Start --><!-- Order Form Start --><!-- Order Form End --><!-- Main Wrapper End -->rel="<?php echo $val['placeholder']; ?>"MyAjaxawe