
Export Media URLs Security & Risk Analysis
wordpress.org/plugins/export-media-urlsAn efficient media information extraction utility with CSV export option, suitable for several use-cases including migration and SEO.
Is Export Media URLs Safe to Use in 2026?
Generally Safe
Score 98/100Export Media URLs has a strong security track record. Known vulnerabilities have been patched promptly.
The "export-media-urls" plugin v2.3.1 exhibits a generally good security posture in its static analysis, with no identified dangerous functions, all SQL queries using prepared statements, and a notable absence of exploitable attack surface points like AJAX handlers, REST API routes, or shortcodes. The presence of nonce and capability checks further indicates an effort to implement basic security measures. However, the code analysis reveals a concerning 57% of output is not properly escaped, which is a significant risk for Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while showing no critical or high severity flows, also indicates a very limited scope of analysis, leaving potential for undiscovered issues.
The plugin's vulnerability history is a major concern. With two known medium severity CVEs in the past, specifically related to XSS and CSRF, even though none are currently unpatched, it demonstrates a pattern of past exploitable weaknesses. The fact that the last vulnerability was in 2026-02-04, despite the current version being 2.3.1, suggests this historical data might be from a later version or a future projection, but the underlying pattern of past vulnerabilities remains a red flag. While the static analysis shows improvements, the historical context suggests a need for continued vigilance and robust security testing.
In conclusion, "export-media-urls" v2.3.1 has made strides in reducing its attack surface and implementing core security checks. However, the high percentage of unescaped output and the history of medium severity vulnerabilities, particularly XSS and CSRF, present a tangible risk. The limited taint analysis also warrants caution. A balanced assessment highlights the positive steps taken but emphasizes the ongoing need to address output escaping and to consider the implications of past security flaws.
Key Concerns
- Significant percentage of unescaped output
- History of medium severity CVEs (XSS, CSRF)
- Limited taint analysis scope
Export Media URLs Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Export Media URLs <= 2.2 - Reflected Cross-Site Scripting
Export Media URLs <= 1.0 - Cross-Site Request Forgery
Export Media URLs Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Export Media URLs Attack Surface
WordPress Hooks 5
Maintenance & Trust
Export Media URLs Maintenance & Trust
Maintenance Signals
Community Trust
Export Media URLs Alternatives
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
Product Import Export for WooCommerce – Import Export Product CSV Suite
product-import-export-for-woo
Easily import/export WooCommerce products (simple, grouped, external/affiliate) via CSV. Transfer product data, including images, reviews, categories, …
Import and export users and customers
import-users-from-csv-with-meta
Import and export users and customers including user meta, roles, and other. Compatible with many plugins. Do it from the front end or using cron.
Export and Import Users and Customers
users-customers-import-export-for-wp-woocommerce
Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.
WP Import Export Lite
wp-import-export-lite
Complete Import & Export solution for Posts, Pages, Custom Post, Users, Taxonomies, Comments etc.
Export Media URLs Developer Profile
4 plugins · 56K total installs
How We Detect Export Media URLs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/export-media-urls/assets/css/style.css/wp-content/plugins/export-media-urls/assets/js/script.js/wp-content/plugins/export-media-urls/assets/js/select2.min.js/wp-content/plugins/export-media-urls/assets/js/script.jsexport-media-urls/assets/css/style.css?ver=export-media-urls/assets/js/select2.min.js?ver=export-media-urls/assets/css/select2.min.css?ver=export-media-urls/assets/js/script.js?ver=HTML / DOM Fingerprints
EMU-WrapperEMU-Main-ContainerCopyright (c) 2020- Atlas Gondal (contact : https://atlasgondal.com/contact-me/)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License as published bythe Free Software Foundation; version 2 of the License.+4 morename="additional-data[]"name="post-author"name="date-range"name="start-date"name="end-date"name="export-type"window.plugin_url