
Export Plugins and Templates Security & Risk Analysis
wordpress.org/plugins/export-plugins-and-templatesExport Plugins and Templates allows you to export any template or plugin already installed in your WordPress.
Is Export Plugins and Templates Safe to Use in 2026?
Generally Safe
Score 92/100Export Plugins and Templates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "export-plugins-and-templates" v1.3 exhibits a mixed security posture. On one hand, the absence of known vulnerabilities and CVEs, along with the complete absence of an attack surface via AJAX, REST API, shortcodes, and cron events, suggests a generally safe plugin. The use of prepared statements for all SQL queries is also a strong positive security practice.
However, significant concerns arise from the static analysis. The fact that 100% of outputs are not properly escaped (6 total outputs) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. This is further amplified by the taint analysis revealing two flows with unsanitized paths, which, while not categorized as critical or high severity, could potentially be exploited in conjunction with the unescaped outputs. The plugin also performs a substantial number of file operations (85), which, without proper sanitization and validation, could lead to arbitrary file operations or path traversal vulnerabilities, especially when combined with unsanitized paths from the taint analysis.
The lack of any recorded vulnerabilities in its history is a positive sign, but it cannot negate the risks identified in the current code analysis. The plugin's strengths lie in its minimal attack surface and secure SQL practices, but its weaknesses in output escaping and potential unsanitized path handling present a notable risk that users should be aware of.
Key Concerns
- All outputs are unescaped
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
Export Plugins and Templates Security Vulnerabilities
Export Plugins and Templates Code Analysis
Output Escaping
Data Flow Analysis
Export Plugins and Templates Attack Surface
WordPress Hooks 7
Maintenance & Trust
Export Plugins and Templates Maintenance & Trust
Maintenance Signals
Community Trust
Export Plugins and Templates Alternatives
WP Theme Exporter
wp-theme-exporter
WP Theme Exporter is a amazing tool helps you export theme and plugin easily.
Site Extensions Snapshot
site-extensions-snapshot
A dashboard to view installed plugins and themes with status, plus CSV export.
Advanced Automatic Updates
automatic-updater
Adds extra options to WordPress' built-in Automatic Updates feature.
Export Plugin Details
export-plugin-details
Simple way to export your installed plugins list in CSV format.
KP Zip Downloader
kp-zip-downloader
This plugin allows administrators to download installed plugins and themes as ZIP files directly from the WordPress dashboard.
Export Plugins and Templates Developer Profile
3 plugins · 2K total installs
How We Detect Export Plugins and Templates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/export-plugins-and-templates/style.css/wp-content/plugins/export-plugins-and-templates/js/plugins.js/wp-content/plugins/export-plugins-and-templates/js/plugins.jsexport-plugins-and-templates/style.css?ver=export-plugins-and-templates/js/plugins.js?ver=HTML / DOM Fingerprints
ep-plugins-themes-fonts-hedep-plugins-themes-fonts-pep-plugins-templates-item-captionep-plugins-templates-table-wrapep-plugins-templates-table