BulkPress – Export Security & Risk Analysis

wordpress.org/plugins/bulkpress-export

Export taxonomies into formatted file compatible with BulkPress (Import) plugin.

300 active installs v0.4 PHP 7.4+ WP 4.9+ Updated Apr 1, 2026
bulkpresscategoriesexporttaxonomiesterms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BulkPress – Export Safe to Use in 2026?

Generally Safe

Score 100/100

BulkPress – Export has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "bulkpress-export" v0.3 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with potential for unauthenticated access significantly reduces its attack surface. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries, performing proper output escaping on a high percentage of outputs, and implementing nonce and capability checks. The fact that no dangerous functions were detected and no file operations or external HTTP requests are made further bolsters its security. The taint analysis also yielded no critical or high severity flows, indicating a low risk of injection vulnerabilities from external input. The plugin's vulnerability history is also clean, with no recorded CVEs, which suggests a consistent focus on security by the developers. Overall, "bulkpress-export" v0.3 appears to be a securely developed plugin with a minimal attack surface and robust security measures in place.

Key Concerns

  • Flows with unsanitized paths
  • Outputs not properly escaped
Vulnerabilities
None known

BulkPress – Export Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BulkPress – Export Release Timeline

v0.4Current
v0.3
v0.2
v0.1
Code Analysis
Analyzed Mar 16, 2026

BulkPress – Export Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped8 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
bpe_listen_export (bulkpress-export.php:164)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BulkPress – Export Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitbulkpress-export.php:33
actionadmin_menubulkpress-export.php:40
actionadmin_initbulkpress-export.php:201
Maintenance & Trust

BulkPress – Export Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 1, 2026
PHP min version7.4
Downloads13K

Community Trust

Rating94/100
Number of ratings3
Active installs300
Developer Profile

BulkPress – Export Developer Profile

meloniq

16 plugins · 710 total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect BulkPress – Export

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bulkpress-export/assets/css/admin.css/wp-content/plugins/bulkpress-export/assets/js/admin.js
Script Paths
/wp-content/plugins/bulkpress-export/assets/js/admin.js
Version Parameters
bulkpress-export/assets/css/admin.css?ver=bulkpress-export/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
bpe-export-form
HTML Comments
<!-- BulkPress Export Form -->
Data Attributes
data-nonce-actiondata-nonce-fielddata-nonce-urldata-taxonomy-selectordata-content-selector
FAQ

Frequently Asked Questions about BulkPress – Export