
Excel Report Maker Security & Risk Analysis
wordpress.org/plugins/excel-report-makerThis plug-in generates a report file from the post .
Is Excel Report Maker Safe to Use in 2026?
Generally Safe
Score 85/100Excel Report Maker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "excel-report-maker" v0.1.2 plugin exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities and utilizes prepared statements for all its SQL queries, which is a significant strength. The plugin also has a relatively small attack surface with only two AJAX handlers and no shortcodes or cron events. Furthermore, 90% of its outputs are properly escaped, reducing the risk of cross-site scripting vulnerabilities.
However, several areas raise concerns. The presence of 11 dangerous function calls, specifically 'unserialize', is a significant red flag. If user-controlled data is passed to 'unserialize' without proper sanitization, it can lead to arbitrary object injection vulnerabilities, a critical security flaw. The taint analysis, while not reporting critical or high severity flows, did identify three flows with unsanitized paths, which, when combined with the 'unserialize' function, could potentially be exploited. Additionally, the plugin lacks capability checks on its entry points, meaning any authenticated user, regardless of their role, can trigger its functionality. While nonce checks are present for one AJAX handler, the absence of capability checks on all entry points is a significant oversight.
The complete absence of recorded vulnerabilities is encouraging but could also indicate limited testing or a lack of historical analysis. Coupled with the identified code signals like 'unserialize' and missing capability checks, it's prudent to assume potential undiscovered vulnerabilities. The presence of bundled libraries like dompdf and TCPDF, while not directly flagged as an issue here, could become a risk if they are outdated and contain known vulnerabilities not yet patched in the plugin.
Key Concerns
- Presence of 'unserialize' function
- Taint flows with unsanitized paths
- Missing capability checks on entry points
- Bundled libraries (potential risk if outdated)
Excel Report Maker Security Vulnerabilities
Excel Report Maker Release Timeline
Excel Report Maker Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Excel Report Maker Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Excel Report Maker Maintenance & Trust
Maintenance Signals
Community Trust
Excel Report Maker Alternatives
Hsmyv Advanced Post Excel Reporter
hsmyv-advanced-post-excel-reporter
Exports WordPress post data to CSV format securely with advanced filtering.
RawType Order Exporter — Spreadsheet & CSV for WooCommerce
rawtype-order-exporter-woocommerce
Export WooCommerce orders, products & customers to Excel or CSV. Visual query builder with smart filters and bulk download.
GravityExport Lite for Gravity Forms
gf-entries-in-excel
Export all Gravity Forms entries to Excel (.xlsx) or CSV via a download button or a secret shareable URL.
Metorik – Reports & Email Automation for WooCommerce
metorik-helper
The Metorik Helper helps provide your WooCommerce store with powerful analytics, reports, and tools.
Export User Data
export-user-data
Export users data and metadata to a csv or Excel file
Excel Report Maker Developer Profile
3 plugins · 50K total installs
How We Detect Excel Report Maker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/excel-report-maker/js/excel-report-maker-admin.js/wp-content/plugins/excel-report-maker/css/excel-report-maker-admin.css/wp-content/plugins/excel-report-maker/js/excel-report-maker-admin.jsHTML / DOM Fingerprints
excel-report-maker-button-wrap<!-- excel-report-maker -->data-target_report_iddata-target_post_iddata-actiondata-nonceexcel_report_maker_ajaxurl