
Export Without Shortcodes: convert to pure HTML the exported content Security & Risk Analysis
wordpress.org/plugins/export-without-shortcodesDuring the exporting process it converts the shortcodes to pure HTML.
Is Export Without Shortcodes: convert to pure HTML the exported content Safe to Use in 2026?
Generally Safe
Score 100/100Export Without Shortcodes: convert to pure HTML the exported content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "export-without-shortcodes" plugin version 0.0.3 demonstrates a generally good security posture based on the provided static analysis. The plugin has a small attack surface, with only one AJAX handler and no exposed REST API routes or shortcodes. Crucially, the analysis indicates no unprotected entry points, and all SQL queries are properly prepared. The presence of nonce checks is a positive sign, suggesting an awareness of common web vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a strong security profile.
The plugin's vulnerability history is also commendable, with zero known CVEs recorded. This lack of historical vulnerabilities, combined with the clean static analysis, suggests that the developers are actively maintaining security or that the plugin's functionality is inherently low-risk. However, the absence of capability checks on the AJAX handler is a minor concern. While the nonce check provides a layer of protection, proper capability checks would ensure that only authorized users can trigger the AJAX action, further hardening the plugin against potential privilege escalation or unauthorized data access.
In conclusion, "export-without-shortcodes" v0.0.3 appears to be a secure plugin. Its minimal attack surface, lack of known vulnerabilities, and use of prepared statements are significant strengths. The only notable area for improvement is the addition of capability checks to the AJAX handler to provide a more robust security framework.
Key Concerns
- Missing capability checks on AJAX handler
Export Without Shortcodes: convert to pure HTML the exported content Security Vulnerabilities
Export Without Shortcodes: convert to pure HTML the exported content Code Analysis
Output Escaping
Export Without Shortcodes: convert to pure HTML the exported content Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
Export Without Shortcodes: convert to pure HTML the exported content Maintenance & Trust
Maintenance Signals
Community Trust
Export Without Shortcodes: convert to pure HTML the exported content Alternatives
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
WP Migrate Lite – Migration Made Easy
wp-migrate-db
Migrate your database. Export full sites including media, themes, and plugins. Find and replace content with support for serialized data.
Customizer Export/Import
customizer-export-import
Easily export or import your WordPress customizer settings!
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Export Without Shortcodes: convert to pure HTML the exported content Developer Profile
56 plugins · 26K total installs
How We Detect Export Without Shortcodes: convert to pure HTML the exported content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/export-without-shortcodes/css/style.css/wp-content/plugins/export-without-shortcodes/js/script.js/wp-content/plugins/export-without-shortcodes/js/script.jsexport-without-shortcodes/css/style.css?ver=export-without-shortcodes/js/script.js?ver=