Export Assist Security & Risk Analysis

wordpress.org/plugins/export-assist

A simple plugin that help you to easily export wordpress data to blogger in xml file.

0 active installs v1.5 PHP + WP 4.7+ Updated Mar 11, 2021
bloggerexporterpagespostsxml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Export Assist Safe to Use in 2026?

Generally Safe

Score 85/100

Export Assist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "export-assist" plugin v1.5 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of identifiable attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength. Furthermore, the code signals indicate good practices with 100% of SQL queries using prepared statements, and a reasonable number of capability checks and a nonce check present. The lack of dangerous functions, file operations, and external HTTP requests also contributes positively to its security. The vulnerability history being clean, with no recorded CVEs, further supports a perception of a secure plugin.

However, the analysis does highlight a potential area for concern: only 71% of output is properly escaped. While not a critical flaw in isolation, this could leave the plugin vulnerable to Cross-Site Scripting (XSS) attacks if unsanitized data is directly outputted to the browser, especially if the plugin's functionality indirectly exposes user-controlled data. The total absence of taint analysis flows is unusual and might indicate either the plugin has minimal data handling or the analysis tool had limitations; this lack of detailed flow analysis leaves some uncertainty about potential hidden risks.

In conclusion, "export-assist" v1.5 appears to be a well-developed plugin from a security perspective, with a very small attack surface and good core security practices. The primary weakness identified is the incomplete output escaping. While the lack of historical vulnerabilities is reassuring, the slight deficiency in output sanitization warrants attention to prevent potential XSS vulnerabilities.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Export Assist Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Export Assist Release Timeline

v1.5Current
v1.0
Code Analysis
Analyzed Mar 17, 2026

Export Assist Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
10 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped14 total outputs
Attack Surface

Export Assist Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_loadedplugin.php:17
actionadmin_menuplugin.php:18
Maintenance & Trust

Export Assist Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 11, 2021
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Export Assist Developer Profile

Shuaib Yusuf Shuaib

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Export Assist

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/export-assist/css/style.css
Script Paths
/wp-content/plugins/export-assist/js/export-assist.js
Version Parameters
export-assist/css/style.css?ver=export-assist/js/export-assist.js?ver=

HTML / DOM Fingerprints

CSS Classes
ew2bc_formew2bc_boxew2bc_optionew2bc_otherother_iconrssiconyoutubeiconother_title+6 more
HTML Comments
cookie checkif page selected, hide optionswhen export button submitted
Data Attributes
data-toggledata-target
JS Globals
arrew2bc_exporttoggle_typetoggle_category_checkboxes
FAQ

Frequently Asked Questions about Export Assist