PiWeb Export Customers Users & Guest customer to CSV for WooCommerce Security & Risk Analysis

wordpress.org/plugins/export-woocommerce-customer-list

Export WooCommerce customer list CSV, export WooCommerce guest customer list CSV, export WordPress users CSV, Product Customer List for WooCommerce

1K active installs v2.2.2 PHP + WP 3.0.1+ Updated Mar 12, 2026
customer-listexport-userexport-usersuser-exportusermeta
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 3, 2022
Safety Verdict

Is PiWeb Export Customers Users & Guest customer to CSV for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

PiWeb Export Customers Users & Guest customer to CSV for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 3, 2022Updated 22d ago
Risk Assessment

The 'export-woocommerce-customer-list' plugin v2.2.2 demonstrates a generally good security posture with several positive indicators. The absence of critical or high-severity vulnerabilities in past CVEs and the current lack of unpatched vulnerabilities are encouraging. The code analysis reveals no dangerous functions and all SQL queries are properly prepared, indicating a strong defense against SQL injection. Furthermore, the plugin has a good rate of output escaping and implements nonce and capability checks on its entry points. The presence of a single external HTTP request is common for plugins interacting with external services. However, there is one identified flow with an unsanitized path, which, while not classified as critical or high, warrants attention. The plugin's history shows a previous medium-severity vulnerability related to CSV formula element neutralization, suggesting potential for nuanced input validation issues that might not always be caught by static analysis alone. The limited attack surface and the protection of all entry points are strengths, but the single unsanitized path and past CSV-related vulnerability are areas to monitor for potential improvements.

Key Concerns

  • Flow with unsanitized path
  • Previous medium severity CSV vulnerability
Vulnerabilities
1

PiWeb Export Customers Users & Guest customer to CSV for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-3603medium · 4.8Improper Neutralization of Formula Elements in a CSV File

Export customers list csv for WooCommerce <= 2.0.67 - CSV Injection

Nov 3, 2022 Patched in 2.0.69 (446d)
Code Analysis
Analyzed Mar 16, 2026

PiWeb Export Customers Users & Guest customer to CSV for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
39
276 escaped
Nonce Checks
4
Capability Checks
3
File Operations
12
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

88% escaped315 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
handle_tracker_action (admin\class-analytics.php:74)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

PiWeb Export Customers Users & Guest customer to CSV for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_pisol_ewcl_export_guest_dataadmin\class-pisol-ewcl-ajax-guest-data-extractor.php:5
authwp_ajax_pisol_ewcl_export_registered_dataadmin\class-pisol-ewcl-ajax-registered-data-extractor.php:5
WordPress Hooks 24
actionadmin_enqueue_scriptsadmin\class-analytics.php:34
actionadmin_footer-plugins.phpadmin\class-analytics.php:35
actionadmin_noticesadmin\class-analytics.php:38
actionadmin_noticesadmin\class-notification.php:5
actionadmin_initadmin\class-pisol-ewcl-admin.php:17
actionwpadmin\class-pisol-ewcl-admin.php:19
actionpisol_ewcl_clear_old_filesadmin\class-pisol-ewcl-admin.php:20
actionwp_loadedadmin\class-pisol-ewcl-ajax-guest-data-extractor.php:7
actioninitadmin\class-pisol-ewcl-email.php:31
filtercron_schedulesadmin\class-pisol-ewcl-email.php:52
actioninitadmin\class-pisol-ewcl-guest.php:145
actionadmin_menuadmin\class-pisol-ewcl-menu.php:12
actioninitadmin\class-pisol-ewcl-option.php:150
actionplugins_loadedincludes\class-pisol-ewcl.php:145
actionadmin_enqueue_scriptsincludes\class-pisol-ewcl.php:160
actionadmin_enqueue_scriptsincludes\class-pisol-ewcl.php:161
actionwp_enqueue_scriptsincludes\class-pisol-ewcl.php:176
actionwp_enqueue_scriptsincludes\class-pisol-ewcl.php:177
actionadmin_footerincludes\pisol.class.form.php:408
actionafter_plugin_row_export-woocommerce-customer-list-pro/pisol-ewcl.phpincludes\Pro_Warning.php:17
actionadmin_noticesincludes\review.php:106
actionadmin_noticespisol-ewcl.php:38
actionadmin_noticespisol-ewcl.php:51
actionbefore_woocommerce_initpisol-ewcl.php:95

Scheduled Events 1

pisol_ewcl_clear_old_files
Maintenance & Trust

PiWeb Export Customers Users & Guest customer to CSV for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version
Downloads260K

Community Trust

Rating94/100
Number of ratings30
Active installs1K
Developer Profile

PiWeb Export Customers Users & Guest customer to CSV for WooCommerce Developer Profile

PI Web Solution

30 plugins · 93K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
235 days
View full developer profile
Detection Fingerprints

How We Detect PiWeb Export Customers Users & Guest customer to CSV for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/export-woocommerce-customer-list/admin/css/bootstrap.css/wp-content/plugins/export-woocommerce-customer-list/admin/css/jquery-ui.css/wp-content/plugins/export-woocommerce-customer-list/admin/css/pisol-ewcl-admin.css
Script Paths
/wp-content/plugins/export-woocommerce-customer-list/admin/js/pisol-ewcl-admin.js/wp-content/plugins/export-woocommerce-customer-list/admin/js/pisol-guest-ajax-exporter.js/wp-content/plugins/export-woocommerce-customer-list/admin/js/pisol-registered-ajax-exporter.js
Version Parameters
pisol-ewcl-admin.js?ver=pisol-guest-ajax-exporter.js?ver=pisol-registered-ajax-exporter.js?ver=jquery-ui.css?ver=pisol-ewcl-admin.css?ver=bootstrap.css?ver=

HTML / DOM Fingerprints

CSS Classes
pisol-ewcl-admin
HTML Comments
<!-- IMPORTANT: Do not edit the file directly. -->
Data Attributes
data-plugin-name="pisol-ewcl"data-version="2.2.2"
JS Globals
window.pi_ewcl_custom_variable
FAQ

Frequently Asked Questions about PiWeb Export Customers Users & Guest customer to CSV for WooCommerce