
Export/Import Media Security & Risk Analysis
wordpress.org/plugins/calliope-media-import-exportImport and export your WordPress media library using CSV, with preview, batch processing, duplicate prevention, and support for media metadata.
Is Export/Import Media Safe to Use in 2026?
Generally Safe
Score 100/100Export/Import Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Calliope Media Import/Export plugin v1.4.4 exhibits a strong security posture based on the provided static analysis. All identified entry points (AJAX handlers, cron events) appear to have appropriate authorization checks, and the code adheres to secure coding practices by exclusively using prepared statements for SQL queries and properly escaping all output. Furthermore, the absence of any recorded vulnerabilities (CVEs) suggests a history of diligent security maintenance or a lack of discoverable flaws.
However, a deeper inspection of the file operations reveals a potential area for concern. While no taint analysis indicated unsanitized paths, the presence of 10 file operations without further context on how they are handled warrants caution. If these operations involve user-supplied input or paths without stringent validation and sanitization, they could represent a latent risk, particularly in scenarios involving file manipulation or directory traversal. The absence of external HTTP requests is a positive indicator, reducing the risk of supply chain attacks or compromised external resources.
In conclusion, the plugin is generally well-secured with robust SQL handling and output escaping. The primary area of potential weakness lies in the file operation handling, which, while not flagged as vulnerable in the current analysis, requires further scrutiny to ensure absolute safety. The clean vulnerability history is a significant strength, but vigilance regarding file operations is advised.
Export/Import Media Security Vulnerabilities
Export/Import Media Release Timeline
Export/Import Media Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Export/Import Media Attack Surface
AJAX Handlers 3
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Export/Import Media Maintenance & Trust
Maintenance Signals
Community Trust
Export/Import Media Alternatives
Post Export Import with Media
post-export-import-with-media
Easily export and import WP posts, pages, media, widgets, menus, themes, plugins & settings with their media files- secure, fast, and with real-ti …
Magic Export & Import
magic-export-import
The ultimate tool to migrate any content including posts, terms, users, comments, WooCommerce shop orders, menus and ACF Options pages.
Export Import For WooCommerce
export-import-for-woocommerce
A tool to export/import selective Post types.
Product Import Export for WooCommerce – Import Export Product CSV Suite
product-import-export-for-woo
Easily import/export WooCommerce products (simple, grouped, external/affiliate) via CSV. Transfer product data, including images, reviews, categories, …
Import and export users and customers
import-users-from-csv-with-meta
Import and export users and customers including user meta, roles, and other. Compatible with many plugins. Do it from the front end or using cron.
Export/Import Media Developer Profile
2 plugins · 940 total installs
How We Detect Export/Import Media
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/calliope-media-import-export/assets/css/style.css/wp-content/plugins/calliope-media-import-export/assets/js/importer.js/wp-content/plugins/calliope-media-import-export/assets/js/importer.jscalliope-media-import-export/assets/css/style.css?ver=calliope-media-import-export/assets/js/importer.js?ver=HTML / DOM Fingerprints
eim-review-notice-topeim-noticedata-error-prefixdata-server-errordata-invalid-responsedata-request-faileddata-stopping-processdata-process-complete+4 moreeim_ajaxeim_import_nonce