Export Category Posts (PDF) Security & Risk Analysis

wordpress.org/plugins/export-category-posts-pdf

Export all posts from specific category to a PDF file.

10 active installs v2.0 PHP + WP 3.0.1+ Updated Mar 1, 2016
exportpdfrtl
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Export Category Posts (PDF) Safe to Use in 2026?

Generally Safe

Score 85/100

Export Category Posts (PDF) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "export-category-posts-pdf" plugin v2.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any discovered CVEs, critical taint flows, or raw SQL queries suggests a developer conscious of common web vulnerabilities. The plugin also demonstrates good practices in output escaping, with a high percentage of outputs being properly escaped, and includes necessary nonce and capability checks for its single entry point. The limited attack surface, with no AJAX handlers, REST API routes, or shortcodes, further contributes to its perceived security.

However, a minor concern arises from the bundled TCPDF v1.0 library. While the static analysis doesn't explicitly flag it as vulnerable, older versions of libraries can sometimes contain undisclosed vulnerabilities or be susceptible to known exploits if not updated. The presence of file operations and an external HTTP request, while not flagged as dangerous, represent potential areas where vulnerabilities could be introduced if not handled with extreme care. Overall, the plugin appears to be well-secured with a minimal risk profile, but the outdated bundled library warrants a small point deduction as a cautionary measure.

Key Concerns

  • Bundled outdated library (TCPDF v1.0)
Vulnerabilities
None known

Export Category Posts (PDF) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Export Category Posts (PDF) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
100 escaped
Nonce Checks
1
Capability Checks
1
File Operations
33
External Requests
1
Bundled Libraries
1

Bundled Libraries

TCPDF1.0

Output Escaping

84% escaped119 total outputs
Attack Surface

Export Category Posts (PDF) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuexport-category-posts-pdf.php:12
actionadmin_initexport-category-posts-pdf.php:37
Maintenance & Trust

Export Category Posts (PDF) Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedMar 1, 2016
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Export Category Posts (PDF) Developer Profile

hojjatmr

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Export Category Posts (PDF)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/export-category-posts-pdf/ft.js/wp-content/plugins/export-category-posts-pdf/datepicker.css
Script Paths
/wp-content/plugins/export-category-posts-pdf/ft.js
Version Parameters
export-category-posts-pdf/ft.js?ver=export-category-posts-pdf/datepicker.css?ver=

HTML / DOM Fingerprints

CSS Classes
wrapicon32
Data Attributes
name="pdfname"id="pdfname"name="numberposts"id="numberposts"name="offset"id="offset"+9 more
FAQ

Frequently Asked Questions about Export Category Posts (PDF)