
Export Assist Security & Risk Analysis
wordpress.org/plugins/export-assistA simple plugin that help you to easily export wordpress data to blogger in xml file.
Is Export Assist Safe to Use in 2026?
Generally Safe
Score 85/100Export Assist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "export-assist" plugin v1.5 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of identifiable attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength. Furthermore, the code signals indicate good practices with 100% of SQL queries using prepared statements, and a reasonable number of capability checks and a nonce check present. The lack of dangerous functions, file operations, and external HTTP requests also contributes positively to its security. The vulnerability history being clean, with no recorded CVEs, further supports a perception of a secure plugin.
However, the analysis does highlight a potential area for concern: only 71% of output is properly escaped. While not a critical flaw in isolation, this could leave the plugin vulnerable to Cross-Site Scripting (XSS) attacks if unsanitized data is directly outputted to the browser, especially if the plugin's functionality indirectly exposes user-controlled data. The total absence of taint analysis flows is unusual and might indicate either the plugin has minimal data handling or the analysis tool had limitations; this lack of detailed flow analysis leaves some uncertainty about potential hidden risks.
In conclusion, "export-assist" v1.5 appears to be a well-developed plugin from a security perspective, with a very small attack surface and good core security practices. The primary weakness identified is the incomplete output escaping. While the lack of historical vulnerabilities is reassuring, the slight deficiency in output sanitization warrants attention to prevent potential XSS vulnerabilities.
Key Concerns
- Unescaped output detected
Export Assist Security Vulnerabilities
Export Assist Release Timeline
Export Assist Code Analysis
Output Escaping
Export Assist Attack Surface
WordPress Hooks 2
Maintenance & Trust
Export Assist Maintenance & Trust
Maintenance Signals
Community Trust
Export Assist Alternatives
QuickExport: Single & Bulk Post/Page Exporter
quickexport-single-bulk-post-page
Easily export single or bulk posts/pages to clean WordPress XML with Elementor support, AJAX operations & customizable export fields.
Duplicate Post
copy-delete-posts
Duplicate post
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
CMS Tree Page View
cms-tree-page-view
Adds a tree view of all pages & custom posts. Get a great overview + options to drag & drop to reorder & option to add multiple pages.
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
Export Assist Developer Profile
1 plugin · 0 total installs
How We Detect Export Assist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/export-assist/css/style.css/wp-content/plugins/export-assist/js/export-assist.jsexport-assist/css/style.css?ver=export-assist/js/export-assist.js?ver=HTML / DOM Fingerprints
ew2bc_formew2bc_boxew2bc_optionew2bc_otherother_iconrssiconyoutubeiconother_title+6 morecookie checkif page selected, hide optionswhen export button submitteddata-toggledata-targetarrew2bc_exporttoggle_typetoggle_category_checkboxes