
Export Media URLs Security & Risk Analysis
wordpress.org/plugins/export-media-urlsExtract every Media Library URL with title, size, dimensions, alt text and more. Filter by media type, export to CSV/JSON, and audit your library.
Is Export Media URLs Safe to Use in 2026?
Generally Safe
Score 98/100Export Media URLs has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "export-media-urls" plugin v2.3.1 exhibits a generally good security posture in its static analysis, with no identified dangerous functions, all SQL queries using prepared statements, and a notable absence of exploitable attack surface points like AJAX handlers, REST API routes, or shortcodes. The presence of nonce and capability checks further indicates an effort to implement basic security measures. However, the code analysis reveals a concerning 57% of output is not properly escaped, which is a significant risk for Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while showing no critical or high severity flows, also indicates a very limited scope of analysis, leaving potential for undiscovered issues.
The plugin's vulnerability history is a major concern. With two known medium severity CVEs in the past, specifically related to XSS and CSRF, even though none are currently unpatched, it demonstrates a pattern of past exploitable weaknesses. The fact that the last vulnerability was in 2026-02-04, despite the current version being 2.3.1, suggests this historical data might be from a later version or a future projection, but the underlying pattern of past vulnerabilities remains a red flag. While the static analysis shows improvements, the historical context suggests a need for continued vigilance and robust security testing.
In conclusion, "export-media-urls" v2.3.1 has made strides in reducing its attack surface and implementing core security checks. However, the high percentage of unescaped output and the history of medium severity vulnerabilities, particularly XSS and CSRF, present a tangible risk. The limited taint analysis also warrants caution. A balanced assessment highlights the positive steps taken but emphasizes the ongoing need to address output escaping and to consider the implications of past security flaws.
Key Concerns
- Significant percentage of unescaped output
- History of medium severity CVEs (XSS, CSRF)
- Limited taint analysis scope
Export Media URLs Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Export Media URLs <= 2.2 - Reflected Cross-Site Scripting
Export Media URLs <= 1.0 - Cross-Site Request Forgery
Export Media URLs Release Timeline
Export Media URLs Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Export Media URLs Attack Surface
WordPress Hooks 5
Maintenance & Trust
Export Media URLs Maintenance & Trust
Maintenance Signals
Community Trust
Export Media URLs Alternatives
Export All URLs
export-all-urls
Export post, page and custom post type data to CSV or JSON, and snapshot your site to detect added, removed or changed content.
Export/Import Media – CSV Media Library Import & Export
calliope-media-import-export
Import and export your WordPress media library from CSV with preview, batch processing, metadata support, and duplicate prevention.
All Page URLs
all-page-urls
Displays a list of all published post, page, and WooCommerce product URLs in your admin dashboard.
Espresso Diagnostics
espresso-diagnostics
Plugin that extracts data on WP installation, installed themes, installed plugins and server info for diagnostic purposes. Export data in csv and json
JKK URL Scout
jkk-url-scout
Export WordPress post/page URL lists to CSV in batches (large-site friendly).
Export Media URLs Developer Profile
4 plugins · 57K total installs
How We Detect Export Media URLs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/export-media-urls/assets/css/style.css/wp-content/plugins/export-media-urls/assets/js/script.js/wp-content/plugins/export-media-urls/assets/js/select2.min.js/wp-content/plugins/export-media-urls/assets/js/script.jsexport-media-urls/assets/css/style.css?ver=export-media-urls/assets/js/select2.min.js?ver=export-media-urls/assets/css/select2.min.css?ver=export-media-urls/assets/js/script.js?ver=HTML / DOM Fingerprints
EMU-WrapperEMU-Main-ContainerCopyright (c) 2020- Atlas Gondal (contact : https://atlasgondal.com/contact-me/)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License as published bythe Free Software Foundation; version 2 of the License.+4 morename="additional-data[]"name="post-author"name="date-range"name="start-date"name="end-date"name="export-type"window.plugin_url