
Export All Post Meta Security & Risk Analysis
wordpress.org/plugins/export-all-post-metaExport WordPress post with all serialized post meta in readable in CSV format. Supports custom post types, taxonomies and selected fields.
Is Export All Post Meta Safe to Use in 2026?
Mostly Safe
Score 71/100Export All Post Meta is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The 'export-all-post-meta' plugin v1.2.1 exhibits a mixed security posture. On the positive side, static analysis reveals no identified attack surface points (AJAX, REST API, shortcodes, cron events) without authentication checks. SQL queries are exclusively prepared, and output escaping is generally robust, with only a small percentage of outputs not being properly escaped. Nonce checks are present, and taint analysis shows no critical or high severity unsanitized flows.
However, significant concerns arise from the presence of the 'unserialize' function, which can be a vector for remote code execution if not handled with extreme care and input validation. Furthermore, the plugin has a known vulnerability history, with one medium severity issue marked as currently unpatched. The common vulnerability type being 'Missing Authorization' in the past, even if not directly evident in this version's static analysis, suggests a potential area of weakness that should be monitored. The single file operation also warrants attention, depending on its context.
In conclusion, while the current static analysis shows an improvement in some areas like attack surface and SQL handling, the presence of 'unserialize' and the history of unpatched vulnerabilities, particularly those related to authorization, necessitate caution. The unpatched medium vulnerability is the most pressing concern, requiring immediate attention. The plugin's security can be considered moderate, with clear areas for improvement and a critical need to address existing known vulnerabilities.
Key Concerns
- Unpatched medium severity CVE
- Presence of unserialize function
- One file operation found
- Low percentage of unescaped outputs
Export All Post Meta Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Export All Post Meta <= 1.2.1 - Missing Authorization
Export All Post Meta Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Export All Post Meta Attack Surface
WordPress Hooks 4
Maintenance & Trust
Export All Post Meta Maintenance & Trust
Maintenance Signals
Community Trust
Export All Post Meta Alternatives
CSV Import and Exporter
csv-import-and-exporter
You can import & export posts in CSV format for each post type. It is compatible with posts' custom fields and custom taxonomies.
WPQ Post CSV Exporter
wpq-post-csv-exporter
Export your posts and custom post types into CSV format effortlessly, including the created date, author, title, URL, and featured image URL.
Simple Export Import for ACF Data
simple-export-import-for-acf-data
With this plugin you simply export and import page, post and custom post. This plugin supports ACF fields.
Simple PDF Exporter
simple-pdf-exporter
Export a single PDF with all posts, or custom post types.
WPBULKiT – Bulk Edit WordPress Posts & Pages
ithemeland-bulk-posts-editing-lite
Editing Date in WordPress is very painful. Be professionals with managing data in the reliable and flexible way by Wordpress Bulk Posts Editing.
Export All Post Meta Developer Profile
14 plugins · 7K total installs
How We Detect Export All Post Meta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/export-all-post-meta/assets/css/custom-eapm.cssexport-all-post-meta/assets/css/custom-eapm.css?ver=1.2.0HTML / DOM Fingerprints
<!-- Exit if accessed directly. -->name="eapm_export_posts_nonce"