
Export Plugin Details Security & Risk Analysis
wordpress.org/plugins/export-plugin-detailsSimple way to export your installed plugins list in CSV format.
Is Export Plugin Details Safe to Use in 2026?
Generally Safe
Score 92/100Export Plugin Details has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "export-plugin-details" v1.1.7 plugin demonstrates a generally good security posture in several areas. Static analysis shows no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface with no unprotected entry points. Furthermore, the absence of dangerous functions, external HTTP requests, and the use of prepared statements for all SQL queries are positive indicators. The plugin also does not bundle any libraries, which can sometimes be a source of vulnerabilities if outdated.
However, significant concerns arise from the code analysis. Notably, 100% of the 8 identified output operations are not properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress admin area or potentially user-facing content if the plugin's output is displayed there. The lack of any nonce checks or capability checks on any of the plugin's potential entry points (even if currently zero) is also a notable weakness, as it implies that if new entry points were introduced or existing ones discovered, they might lack essential security measures. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign, but it cannot completely mitigate the risks identified in the current code analysis.
In conclusion, while the plugin boasts a small attack surface and employs secure database practices, the critical flaw of unescaped output is a severe security concern that significantly elevates the risk profile. The absence of basic security checks like nonces and capabilities also warrants attention. Until the output escaping issue is addressed, the plugin should be considered risky.
Key Concerns
- Output not properly escaped
- Missing nonce checks
- Missing capability checks
Export Plugin Details Security Vulnerabilities
Export Plugin Details Code Analysis
Output Escaping
Export Plugin Details Attack Surface
WordPress Hooks 1
Maintenance & Trust
Export Plugin Details Maintenance & Trust
Maintenance Signals
Community Trust
Export Plugin Details Alternatives
Extension Info Exporter
extension-info-exporter
Professional WordPress plugin export tool for plugin inventory management and audit reports.
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
WP All Export – Product Export Add-On for WooCommerce
product-export-for-woocommerce
Drag & drop to export products to CSV, Excel, or XML files of any format. Supports variations, images, attributes, brands, and more with powerful …
Export All Posts, Products, Orders, Refunds & Users
wp-ultimate-exporter
Export any WordPress website including WooCommerce data seamlessly with our powerful export plugin. Save records as CSV, XML, or Excel file for secure …
Export Plugins and Templates
export-plugins-and-templates
Export Plugins and Templates allows you to export any template or plugin already installed in your WordPress.
Export Plugin Details Developer Profile
13 plugins · 44K total installs
How We Detect Export Plugin Details
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapnoticenotice-warningis-dismissiblewp-list-tablewidefatfixedposts