Export Users Data CSV Security & Risk Analysis

wordpress.org/plugins/export-users-data-csv

Export Users Data Plugin allows you to export users information with important meta data in CSV file format.

900 active installs v3.0 PHP 7.4+ WP 6.1+ Updated Feb 4, 2026
csvcsv-exportexport-usersuser-export
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 30, 2022
Download
Safety Verdict

Is Export Users Data CSV Safe to Use in 2026?

Generally Safe

Score 100/100

Export Users Data CSV has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 30, 2022Updated 3mo ago
Risk Assessment

The 'export-users-data-csv' plugin v3.0 generally demonstrates good security practices, with a clean static analysis report showing no critical vulnerabilities in its attack surface, code signals, or taint analysis. The absence of dangerous functions, reliance on prepared statements for SQL queries, proper output escaping for the vast majority of outputs, and the presence of nonce and capability checks are all positive indicators. Furthermore, the plugin has no known unpatched vulnerabilities, which is excellent.

However, the plugin does have a history of known vulnerabilities, specifically one medium severity CVE related to injection. While this vulnerability is currently patched and no longer a direct threat, it suggests that past versions of the plugin may have had weaknesses in how they handled external input. This history, combined with the fact that there is still 100% of output escaping to be checked, warrants some caution. Overall, the current version appears robust, but the past vulnerability should be noted as a potential area for developers to remain vigilant in the future.

Key Concerns

  • History of 1 medium vulnerability
  • 9% of outputs not properly escaped
Vulnerabilities
1 published

Export Users Data CSV Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-41616medium · 6Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Export Users Data CSV <= 2.1 - Authenticated (Subscriber+) CSV Injection

Nov 30, 2022 Patched in 2.2 (419d)
Version History

Export Users Data CSV Release Timeline

v3.0Current
v2.2
v2.11 CVE
v2.01 CVE
v1.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Export Users Data CSV Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
20 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped22 total outputs
Attack Surface

Export Users Data CSV Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_footerexport-users-data-csv.php:55
actionadmin_initexport-users-data-csv.php:108
Maintenance & Trust

Export Users Data CSV Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version7.4
Downloads12K

Community Trust

Rating100/100
Number of ratings4
Active installs900
Developer Profile

Export Users Data CSV Developer Profile

Kaushik

2 plugins · 910 total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
419 days
View full developer profile
Detection Fingerprints

How We Detect Export Users Data CSV

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

JS Globals
eudc_export_users
FAQ

Frequently Asked Questions about Export Users Data CSV