Audit Export Security & Risk Analysis

wordpress.org/plugins/audit-export

Audits and exports WordPress site structure: plugins, themes, content types, users, menus, widgets, and taxonomies with remote posting.

0 active installs v1.0.1 PHP 7.2+ WP 6.2+ Updated Dec 8, 2025
auditexportreportingsite-analysiswp-cli
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Audit Export Safe to Use in 2026?

Generally Safe

Score 100/100

Audit Export has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The audit-export plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for the vast majority of its SQL queries and properly escaping a high percentage of its output. The absence of known CVEs and bundled libraries further contributes to a generally stable foundation. However, significant concerns arise from its attack surface. All four identified AJAX handlers lack authentication checks, presenting a direct avenue for unauthorized actions if these handlers are exploitable. Furthermore, the taint analysis reveals four critical flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data could be mishandled with severe consequences. While the vulnerability history is clean, the static analysis highlights immediate risks that require attention. The plugin's strengths lie in its data handling diligence, but its unprotected entry points and critical taint flows create a notable risk profile that needs mitigation.

Key Concerns

  • 4 AJAX handlers without auth checks
  • 4 Critical severity taint flows with unsanitized paths
Vulnerabilities
None known

Audit Export Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Audit Export Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Audit Export Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
32 prepared
Unescaped Output
26
320 escaped
Nonce Checks
6
Capability Checks
4
File Operations
8
External Requests
4
Bundled Libraries
0

SQL Query Safety

84% prepared38 total queries

Output Escaping

92% escaped346 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
ajax_download_report (admin\class-audit-export-admin.php:339)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Audit Export Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_audit_export_processincludes\class-audit-export.php:149
authwp_ajax_audit_export_downloadincludes\class-audit-export.php:150
authwp_ajax_audit_export_processtrunk\includes\class-audit-export.php:149
authwp_ajax_audit_export_downloadtrunk\includes\class-audit-export.php:150
WordPress Hooks 20
actionplugins_loadedincludes\class-audit-export.php:125
actionadmin_enqueue_scriptsincludes\class-audit-export.php:139
actionadmin_enqueue_scriptsincludes\class-audit-export.php:140
actionadmin_menuincludes\class-audit-export.php:143
actionadmin_initincludes\class-audit-export.php:146
actionaudit_export_cron_hookincludes\class-audit-export.php:165
filtercron_schedulesincludes\class-audit-export.php:166
actionaudit_export_process_queueincludes\class-audit-export.php:169
actionaudit_export_completeincludes\class-audit-export.php:172
actioninitincludes\class-audit-export.php:175
actionplugins_loadedtrunk\includes\class-audit-export.php:125
actionadmin_enqueue_scriptstrunk\includes\class-audit-export.php:139
actionadmin_enqueue_scriptstrunk\includes\class-audit-export.php:140
actionadmin_menutrunk\includes\class-audit-export.php:143
actionadmin_inittrunk\includes\class-audit-export.php:146
actionaudit_export_cron_hooktrunk\includes\class-audit-export.php:165
filtercron_schedulestrunk\includes\class-audit-export.php:166
actionaudit_export_process_queuetrunk\includes\class-audit-export.php:169
actionaudit_export_completetrunk\includes\class-audit-export.php:172
actioninittrunk\includes\class-audit-export.php:175

Scheduled Events 8

audit_export_cron_hook
audit_export_cron_hook
audit_export_process_queue
audit_export_process_queue
audit_export_cron_hook
audit_export_cron_hook
audit_export_process_queue
audit_export_process_queue
Maintenance & Trust

Audit Export Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version7.2
Downloads200

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Audit Export Developer Profile

Will Jackson

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Audit Export

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/audit-export/admin/css/audit-export-admin.css/wp-content/plugins/audit-export/admin/js/audit-export-admin.js/wp-content/plugins/audit-export/admin/js/audit-export-admin-inline.js
Script Paths
/wp-content/plugins/audit-export/admin/js/audit-export-admin.js/wp-content/plugins/audit-export/admin/js/audit-export-admin-inline.js
Version Parameters
audit-export/admin/css/audit-export-admin.css?ver=audit-export/admin/js/audit-export-admin.js?ver=audit-export/admin/js/audit-export-admin-inline.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-audit-export-export-typedata-audit-export-export-formatdata-audit-export-audit-type
JS Globals
audit_export_ajax
FAQ

Frequently Asked Questions about Audit Export