
User Information to CSV Security & Risk Analysis
wordpress.org/plugins/export-users-csv-recordsExport-users-csv-records Plugin allows you to export users list and their metadata in CSV file.
Is User Information to CSV Safe to Use in 2026?
Generally Safe
Score 85/100User Information to CSV has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'export-users-csv-records' v1.3.2 plugin exhibits a generally good security posture in several key areas. The static analysis reveals no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting its attack surface. Furthermore, all SQL queries are correctly implemented using prepared statements, and there are no external HTTP requests or bundled libraries that might introduce vulnerabilities. The absence of any known CVEs in its history further reinforces this impression of a well-maintained and secure plugin.
However, there are notable areas of concern that temper this positive assessment. The plugin has a complete lack of nonce checks and capability checks. This means that any functionality exposed, even if not immediately apparent from the attack surface analysis, is not protected against unauthorized access or abuse. Critically, 100% of the identified output operations are not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamically generated content could be injected and executed within the browser of other users, potentially leading to session hijacking, defacement, or malicious redirects.
While the plugin's limited attack surface and secure SQL practices are commendable, the absence of essential security controls like nonce and capability checks, coupled with the pervasive issue of unescaped output, introduces significant risks. The lack of past vulnerabilities might be due to the limited exposure of its features or a fortunate oversight, rather than inherent robustness. Therefore, while not demonstrably vulnerable in its current state based on the provided data, the plugin has critical weaknesses that require immediate attention to prevent potential exploitation.
Key Concerns
- Unescaped output (100%)
- Missing nonce checks
- Missing capability checks
User Information to CSV Security Vulnerabilities
User Information to CSV Release Timeline
User Information to CSV Code Analysis
SQL Query Safety
Output Escaping
User Information to CSV Attack Surface
WordPress Hooks 1
Maintenance & Trust
User Information to CSV Maintenance & Trust
Maintenance Signals
Community Trust
User Information to CSV Alternatives
LH Export Users to CSV
lh-export-users-to-csv
Export Users to CSV Plugin allows you to export users listings and their metadata into a CSV file.
WP All Export – User Export Add-On
export-wp-users-xml-csv
Drag & drop to export users and all user data to a completely custom CSV, Excel, or XML of any format. Supports roles, metadata, custom fields, wi …
PiWeb Export Customers Users & Guest customer to CSV for WooCommerce
export-woocommerce-customer-list
Export WooCommerce customer list CSV, export WooCommerce guest customer list CSV, export WordPress users CSV, Product Customer List for WooCommerce
Export Users Data CSV
export-users-data-csv
Export Users Data Plugin allows you to export users information with important meta data in CSV file format.
All Users Filter
all-users-filter
Filter, sort, and export WordPress users to CSV using powerful UI-driven meta queries (roles, dates, numeric ranges, regex, and more).
User Information to CSV Developer Profile
1 plugin · 0 total installs
How We Detect User Information to CSV
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrap