
Static Site Exporter Security & Risk Analysis
wordpress.org/plugins/jekyll-exporterFeatures
Is Static Site Exporter Safe to Use in 2026?
Generally Safe
Score 100/100Static Site Exporter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jekyll-exporter" plugin v3.1.1 presents a generally strong security posture based on the provided static analysis. It has a zero-attack surface for AJAX handlers and REST API routes, and importantly, no unprotected entry points were identified. The plugin also demonstrates good practices with 100% of its SQL queries utilizing prepared statements, and it has no known historical vulnerabilities. This indicates a diligent approach to security development and maintenance by the authors.
However, a notable area of concern is the output escaping, where only 44% of outputs are properly escaped. This leaves a significant portion of potentially user-controlled data vulnerable to cross-site scripting (XSS) attacks if not handled carefully within the plugin's logic or theme integration. While taint analysis shows no critical or high severity flows, the incomplete output escaping remains a potential vector for client-side attacks. The absence of nonce checks on AJAX handlers and capability checks on all potential entry points (though the attack surface is zero) are also minor points of attention for a truly hardened plugin.
In conclusion, "jekyll-exporter" v3.1.1 benefits from a clean vulnerability history and a small, well-protected attack surface. Its primary weakness lies in the incomplete output escaping, which requires careful monitoring and mitigation. While not indicative of immediate critical risks due to the lack of identified taint flows, it represents a notable area for improvement to ensure comprehensive security.
Key Concerns
- Incomplete output escaping
Static Site Exporter Security Vulnerabilities
Static Site Exporter Code Analysis
SQL Query Safety
Output Escaping
Static Site Exporter Attack Surface
WordPress Hooks 21
Maintenance & Trust
Static Site Exporter Maintenance & Trust
Maintenance Signals
Community Trust
Static Site Exporter Alternatives
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Widget Importer & Exporter
widget-importer-exporter
Import and export your widgets.
WP Migrate Lite – Migration Made Easy
wp-migrate-db
Migrate your database. Export full sites including media, themes, and plugins. Find and replace content with support for serialized data.
Customizer Export/Import
customizer-export-import
Easily export or import your WordPress customizer settings!
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Static Site Exporter Developer Profile
7 plugins · 3K total installs
How We Detect Static Site Exporter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jekyll-exporter/css/admin.css/wp-content/plugins/jekyll-exporter/js/jekyll-exporter.js/wp-content/plugins/jekyll-exporter/js/jekyll-exporter.jsjekyll-exporter/css/admin.css?ver=jekyll-exporter/js/jekyll-exporter.js?ver=