
Export Import Menus Security & Risk Analysis
wordpress.org/plugins/export-import-menusA plugin that lets you export and import your WordPress menus in our own website under Appearance section to Export/Import Menus.
Is Export Import Menus Safe to Use in 2026?
Generally Safe
Score 90/100Export Import Menus has a strong security track record. Known vulnerabilities have been patched promptly.
The 'export-import-menus' plugin version 1.9.2 presents a mixed security posture. On the positive side, it exhibits good practices in several areas, including the complete absence of direct SQL injection vulnerabilities due to 100% prepared statement usage and a limited attack surface with only one AJAX handler, which appears to be protected by authorization checks. The presence of nonces and capability checks also contributes to a stronger defense. However, significant concerns arise from the use of the `unserialize` function, which is a known risk for object injection vulnerabilities if the serialized data is not strictly controlled. While the static analysis did not directly flag critical or high severity taint flows, the presence of `unserialize` inherently introduces a risk that could be exploited if untrusted data reaches it. The vulnerability history reveals a pattern of past issues, including missing authorization and unrestricted file uploads, with a recent medium severity vulnerability. This history suggests a need for ongoing vigilance and thorough code reviews to prevent recurring types of vulnerabilities. Although there are no currently unpatched CVEs, the past issues, combined with the presence of `unserialize`, indicate that the plugin is not without its risks.
Key Concerns
- Use of unserialize function
- Output escaping only 45% proper
- History of medium/high severity CVEs
- History of common vulnerability types
Export Import Menus Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Export Import Menus <= 1.9.1 - Missing Authorization to Unauthenticated Menu Export
Export Import Menus <= 1.8.0 - Authenticated (Subscriber+) Arbitrary File Upload
Export Import Menus Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Export Import Menus Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Export Import Menus Maintenance & Trust
Maintenance Signals
Community Trust
Export Import Menus Alternatives
WPS Menu Exporter
wps-menu-exporter
WPS Menu Exporter lets you export only your WordPress menus via the WordPress Export page.
Export WordPress Menus
wp-export-menus
Export WordPress Menus plugin allows you to export your WordPress Menus. You can also export menus month wise. A filter is provided to export menus fo …
One Menu Export Import
one-menu-export-import
Easily export and import your WordPress menus with a modern, user-friendly interface. Perfect for backups, migrations, or cloning menus between sites.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
Import and export users and customers
import-users-from-csv-with-meta
Import and export users and customers including user meta, roles, and other. Compatible with many plugins. Do it from the front end or using cron.
Export Import Menus Developer Profile
1 plugin · 10K total installs
How We Detect Export Import Menus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/export-import-menus/assets/DspExportImportCss.css/wp-content/plugins/export-import-menus/assets/DspExportImportScript.js/wp-content/plugins/export-import-menus/assets/DspExportImportScript.jsHTML / DOM Fingerprints
dsp-export-import-menusdspexportmenus