
Market Exporter Security & Risk Analysis
wordpress.org/plugins/market-exporterПлагин для экспорта товарных предложений из WooCommerce в YML файл для Яндекс Маркет.
Is Market Exporter Safe to Use in 2026?
Generally Safe
Score 96/100Market Exporter has a strong security track record. Known vulnerabilities have been patched promptly.
The market-exporter plugin, version 2.0.23, presents a mixed security posture. While it demonstrates good practices in output escaping and the absence of dangerous functions or external HTTP requests, significant concerns remain regarding its attack surface and historical vulnerability patterns. The static analysis revealed three AJAX handlers lacking authentication checks, representing a direct and potentially exploitable entry point for attackers. Furthermore, the plugin's entire SQL query is executed without prepared statements, posing a risk of SQL injection if any user-controlled data is involved in constructing that query. The vulnerability history indicates a recurring pattern of Cross-Site Request Forgery (CSRF) and Missing Authorization vulnerabilities, suggesting systemic issues in how user actions and permissions are handled. Although there are no currently unpatched CVEs, the prevalence of past vulnerabilities, particularly high and medium severity ones, warrants caution. Overall, while the plugin has some strengths, the identified unauthenticated entry points and the history of authorization-related vulnerabilities create a considerable security risk.
Key Concerns
- 3 unprotected AJAX handlers
- 1 SQL query without prepared statements
- History of high/medium severity vulnerabilities
Market Exporter Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Market Exporter <= 2.0.22 - Cross-Site Request Forgery
Market Exporter <= 2.0.21 - Missing Authorization
Market Exporter <= 2.0.19 - Missing Authorization to Arbitrary File Deletion
Market Exporter Code Analysis
SQL Query Safety
Output Escaping
Market Exporter Attack Surface
AJAX Handlers 7
WordPress Hooks 12
Scheduled Events 3
Maintenance & Trust
Market Exporter Maintenance & Trust
Maintenance Signals
Community Trust
Market Exporter Alternatives
YML for Yandex Market
yml-for-yandex-market
Creates a YML-feed to upload to Yandex Market and not only.
Mergado Pack
mergado-marketing-pack
Connect your online store to the e-commerce world and get even more from hundreds shopping channels
Import from YML
import-from-yml
Import products from YML-feed to WooCommerce.
XML for Avito
xml-for-avito
Создаёт XML-feed для загрузки на Авито.
XML for Hotline
xml-for-hotline
Creates a XML-feed to upload to Hotline.ua.
Market Exporter Developer Profile
2 plugins · 2K total installs
How We Detect Market Exporter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/market-exporter/admin/css/market-exporter.min.css/wp-content/plugins/market-exporter/admin/js/market-exporter-i18n.min.js/wp-content/plugins/market-exporter/admin/js/market-exporter.min.js/wp-content/plugins/market-exporter/admin/js/market-exporter-i18n.min.js/wp-content/plugins/market-exporter/admin/js/market-exporter.min.jsmarket-exporter.min.css?ver=market-exporter-i18n.min.js?ver=market-exporter.min.js?ver=HTML / DOM Fingerprints
id="svg"id="svgg"id="path0"ajax_stringswooyaI18n/wp-json/market-exporter/v1/