
Custom Importer & Exporter Security & Risk Analysis
wordpress.org/plugins/custom-importer-exporterIt is a plugin for importing and exporting Term, Post information.
Is Custom Importer & Exporter Safe to Use in 2026?
Generally Safe
Score 85/100Custom Importer & Exporter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-importer-exporter' plugin v1.0 exhibits a mixed security posture. On the positive side, there are no registered CVEs, no taint analysis findings, and the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on the limited number of identified code signals. The attack surface appears minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks. This indicates a cautious approach to exposing functionality.
However, a significant concern arises from the complete lack of output escaping. With 24 total outputs identified and 0% properly escaped, this presents a high risk of cross-site scripting (XSS) vulnerabilities. Any data that is rendered to the user interface, whether user-provided or from the database, is susceptible to malicious injection. The presence of two file operations also warrants careful review to ensure these operations are not exploitable in conjunction with the unescaped output or other potential vulnerabilities not immediately apparent in this static analysis.
While the plugin's vulnerability history is clean, this should not be interpreted as a guarantee of absolute security, especially given the critical flaw in output escaping. The absence of past vulnerabilities might be due to the plugin's age, limited usage, or simply the limited scope of the static analysis performed. The combination of unescaped output and potential file operations creates a tangible risk that needs immediate attention.
Key Concerns
- Output escaping is completely missing
- Presence of file operations without further context
Custom Importer & Exporter Security Vulnerabilities
Custom Importer & Exporter Release Timeline
Custom Importer & Exporter Code Analysis
Output Escaping
Custom Importer & Exporter Attack Surface
WordPress Hooks 1
Maintenance & Trust
Custom Importer & Exporter Maintenance & Trust
Maintenance Signals
Community Trust
Custom Importer & Exporter Alternatives
Simple Export Import for ACF Data
simple-export-import-for-acf-data
With this plugin you simply export and import page, post and custom post. This plugin supports ACF fields.
Post Porter
post-porter
Post Porter enables seamless posts migration between WordPress sites via REST API, ensuring alignment with standard post principles.
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
WP Migrate Lite – Migration Made Easy
wp-migrate-db
Migrate your database. Export full sites including media, themes, and plugins. Find and replace content with support for serialized data.
Custom Importer & Exporter Developer Profile
1 plugin · 10 total installs
How We Detect Custom Importer & Exporter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-importer-exporter/css/custom-importer-exporter.cssHTML / DOM Fingerprints
box_wrapboxcontentsbutton_wrapname="export_posttype[]"name="page"value="custom-importer-exporter-post-type"name="download"value="true"type="submit"+1 more