Export Import For WooCommerce Security & Risk Analysis

wordpress.org/plugins/export-import-for-woocommerce

A tool to export/import selective Post types.

10 active installs v1.2.7 PHP 7.0+ WP 3.5+ Updated Unknown
csvexportexport-productmigrationproduct-import
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Export Import For WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Export Import For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "export-import-for-woocommerce" v1.2.7 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce checks for its AJAX handlers. Furthermore, it has no recorded vulnerabilities in its history, suggesting a generally stable codebase. However, a significant concern arises from the taint analysis, which identified one flow with unsanitized paths. While no critical or high-severity taint flows were found, this single instance indicates a potential for privilege escalation or unauthorized data access if exploited, even if the severity is currently assessed as low or medium. Additionally, the output escaping is a notable weakness, with only 36% of outputs being properly escaped. This leaves the plugin susceptible to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into pages viewed by other users.

Key Concerns

  • Flow with unsanitized path
  • Low output escaping percentage
Vulnerabilities
None known

Export Import For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Export Import For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
48
27 escaped
Nonce Checks
6
Capability Checks
0
File Operations
11
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared7 total queries

Output Escaping

36% escaped75 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
woie_update_option (inc\functions.php:238)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Export Import For WooCommerce Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_woie_update_optioninc\functions.php:235
authwp_ajax_woie_filters_saveinc\functions.php:292
authwp_ajax_woie_export_ordersinc\functions.php:325
authwp_ajax_woie_export_posts_datainc\Woo_Import_Export.php:18
authwp_ajax_woie_import_posts_data_fileinc\Woo_Import_Export.php:19
authwp_ajax_woie_import_posts_datainc\Woo_Import_Export.php:20
WordPress Hooks 6
actionadmin_headinc\functions.php:2
actionadmin_enqueue_scriptsinc\functions.php:205
actionwp_enqueue_scriptsinc\functions.php:207
actionadmin_menuinc\functions.php:217
filterwoie_export_order_data_columnsinc\functions.php:538
filterwoie_export_order_datainc\functions.php:555
Maintenance & Trust

Export Import For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Export Import For WooCommerce Developer Profile

Fahad Mahmood

40 plugins · 33K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
237 days
View full developer profile
Detection Fingerprints

How We Detect Export Import For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Export Import For WooCommerce