
Export All URLs Security & Risk Analysis
wordpress.org/plugins/export-all-urlsExport post, page and custom post type data to CSV or JSON, and snapshot your site to detect added, removed or changed content.
Is Export All URLs Safe to Use in 2026?
Generally Safe
Score 92/100Export All URLs has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "export-all-urls" v5.1 plugin exhibits a mixed security posture. On one hand, the static analysis reveals a relatively small attack surface with no apparent unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices by using prepared statements for all SQL queries and implementing nonce and capability checks. However, a significant concern is the low percentage of properly escaped output (23%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered directly to the browser without proper sanitization. The history of 5 medium severity vulnerabilities, including XSS, Path Traversal, and CSRF, reinforces this concern, suggesting recurring issues in input validation and output escaping, even though none are currently unpatched.
Despite the lack of critical or high severity issues in the current static analysis and no unpatched CVEs, the historical vulnerability pattern and the poor output escaping are serious indicators of potential weaknesses. The plugin has a history of allowing malicious code injection and unauthorized actions. While the attack surface appears controlled, the internal code handling is less secure due to insufficient output sanitization. This means that even if data enters the plugin through a protected mechanism, it could still be exploited if not properly escaped before display. Therefore, while the plugin's architecture might seem sound at first glance, the persistent output escaping issues and past vulnerabilities necessitate caution.
Key Concerns
- Significant percentage of unescaped output
- History of medium severity vulnerabilities (5 total)
- Past XSS and Path Traversal vulnerabilities
Export All URLs Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Export All URLs < 5.1 - Unauthenticated Information Exposure
Export All URLs <= 4.5 - Reflected Cross-Site Scripting
Export All URLs <= 4.3 - Arbitrary File Deletion
Export All URLs <= 4.1 - Authenticated (Editor+) Stored Cross-Site Scripting
Export All URLs <= 4.1 - Authenticated (Editor+) Stored Cross-Site Scripting
Export All URLs <= 4.1 - Reflected Cross-Site Scripting
Export All URLs <= 4.2 - Cross-Site Request Forgery to Sensitive Data Export
Export All URLs Release Timeline
Export All URLs Code Analysis
Output Escaping
Export All URLs Attack Surface
WordPress Hooks 4
Maintenance & Trust
Export All URLs Maintenance & Trust
Maintenance Signals
Community Trust
Export All URLs Alternatives
Export Media URLs
export-media-urls
Extract every Media Library URL with title, size, dimensions, alt text and more. Filter by media type, export to CSV/JSON, and audit your library.
LinkGather
linkgather
Admin utility to gather internal post/page URLs with filters, pagination, and CSV export.
All Page URLs
all-page-urls
Displays a list of all published post, page, and WooCommerce product URLs in your admin dashboard.
Espresso Diagnostics
espresso-diagnostics
Plugin that extracts data on WP installation, installed themes, installed plugins and server info for diagnostic purposes. Export data in csv and json
JKK URL Scout
jkk-url-scout
Export WordPress post/page URL lists to CSV in batches (large-site friendly).
Export All URLs Developer Profile
4 plugins · 57K total installs
How We Detect Export All URLs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/export-all-urls/assets/css/style.css/wp-content/plugins/export-all-urls/assets/js/script.js/wp-content/plugins/export-all-urls/assets/js/script.jsexport-all-urls/assets/css/style.css?ver=export-all-urls/assets/js/script.js?ver=