Import / Export Customizer Settings Security & Risk Analysis

wordpress.org/plugins/astra-import-export

Astra theme customizer offers several settings for header/footer layout, sidebar and blog designs, colors, backgrounds, typography and much more.

50K active installs v1.1.0 PHP 5.4+ WP 4.4+ Updated Dec 1, 2025
astra-addons-exportcustomizer-settingsimportsettingstheme-settings
100
A · Safe
CVEs total1
Unpatched0
Last CVESep 16, 2020
Safety Verdict

Is Import / Export Customizer Settings Safe to Use in 2026?

Generally Safe

Score 100/100

Import / Export Customizer Settings has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 16, 2020Updated 4mo ago
Risk Assessment

The astra-import-export plugin version 1.1.0 demonstrates a strong security posture in its code analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, minimizing the potential attack surface. Furthermore, the code adheres to good security practices by exclusively using prepared statements for SQL queries and implementing nonce checks and capability checks, indicating an effort to prevent common web vulnerabilities. The high percentage of properly escaped output also contributes positively to its security. However, the plugin's vulnerability history is a cause for concern. While there are no currently unpatched vulnerabilities, the single known CVE, a Cross-Site Request Forgery (CSRF) issue patched in 2020, suggests that the plugin has had security flaws in the past. This historical pattern, even with a single instance, warrants vigilance. The lack of taint analysis results and file operations suggests no obvious pathways for code injection or file manipulation were detected in this analysis, but the absence of data here doesn't guarantee complete security.

In conclusion, astra-import-export v1.1.0 shows promising code-level security, particularly in its minimal attack surface and use of prepared statements and authentication checks. The primary weakness lies in its past vulnerability, specifically a CSRF issue. While currently no vulnerabilities are unpatched, users should remain aware of the plugin's history and ensure it is kept up-to-date to benefit from any future security patches. The lack of taint analysis data could be a limitation, as it may not cover all potential complex attack vectors.

Key Concerns

  • Known CVE in history (CSRF)
  • Minor unescaped output detected
Vulnerabilities
1

Import / Export Customizer Settings Security Vulnerabilities

CVEs by Year

1 CVE in 2020
2020
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2020-36737medium · 4.3Cross-Site Request Forgery (CSRF)

Import / Export Customizer Settings <= 1.0.3 - Cross-Site Request Forgery Bypass

Sep 16, 2020 Patched in 1.0.4 (1224d)
Code Analysis
Analyzed Mar 16, 2026

Import / Export Customizer Settings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

Import / Export Customizer Settings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedastra-import-export.php:37
filterastra_collect_customizer_builder_datainc\classes\class-astra-import-export-loader.php:54
actionafter_setup_themeinc\classes\class-astra-import-export-loader.php:55
actionadmin_enqueue_scriptsinc\classes\class-astra-import-export-loader.php:56
actionadmin_initinc\classes\class-astra-import-export-loader.php:57
actionadmin_initinc\classes\class-astra-import-export-loader.php:58
actionadmin_noticesinc\classes\class-astra-import-export-loader.php:59
actionastra_welcome_page_right_sidebar_contentinc\classes\class-astra-import-export-loader.php:70
Maintenance & Trust

Import / Export Customizer Settings Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version5.4
Downloads1.0M

Community Trust

Rating94/100
Number of ratings6
Active installs50K
Developer Profile

Import / Export Customizer Settings Developer Profile

Brainstorm Force

32 plugins · 8.6M total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
196 days
View full developer profile
Detection Fingerprints

How We Detect Import / Export Customizer Settings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/astra-import-export/inc/assets/css/modern-admin-style.css/wp-content/plugins/astra-import-export/inc/assets/css/style.css/wp-content/plugins/astra-import-export/admin/assets/build/dashboard-app.js
Script Paths
/wp-content/plugins/astra-import-export/admin/assets/build/dashboard-app.js
Version Parameters
astra-import-export/inc/assets/css/modern-admin-style.css?ver=astra-import-export/inc/assets/css/style.css?ver=astra-import-export/admin/assets/build/dashboard-app.js?ver=

HTML / DOM Fingerprints

CSS Classes
astra-ie
JS Globals
ast_import_export_admin
FAQ

Frequently Asked Questions about Import / Export Customizer Settings