
MSTW CSV EXPORTER Security & Risk Analysis
wordpress.org/plugins/mstw-csv-exporterExports MSTW custom data types to CSV format files for backup, upgrade, and migration across installs.
Is MSTW CSV EXPORTER Safe to Use in 2026?
Mostly Safe
Score 70/100MSTW CSV EXPORTER is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "mstw-csv-exporter" v1.4 plugin exhibits a mixed security posture. While it demonstrates positive practices such as using prepared statements for all SQL queries and performing capability checks on some functions, significant concerns remain. The static analysis reveals a worrying lack of proper output escaping, with only 13% of outputs being correctly handled, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified two flows with unsanitized paths, indicating potential vulnerabilities in how external data is processed. The vulnerability history is particularly concerning, showing a known medium-severity CVE that is currently unpatched, specifically related to missing authorization. This pattern suggests a recurring issue with authorization controls within the plugin's development. Although the attack surface appears small and no unprotected entry points were directly identified in this scan, the combination of unpatched vulnerabilities, inadequate output escaping, and unsanitized data flows presents a tangible risk. Mitigation of the unpatched CVE and addressing the output escaping and taint flow issues are critical for improving the plugin's security.
Key Concerns
- Unpatched CVE (Medium Severity)
- Low percentage of properly escaped output
- Unsanitized paths in taint flows
- Lack of nonce checks on entry points
MSTW CSV EXPORTER Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
MSTW CSV EXPORTER <= 1.4 - Missing Authorization
MSTW CSV EXPORTER Code Analysis
Output Escaping
Data Flow Analysis
MSTW CSV EXPORTER Attack Surface
WordPress Hooks 5
Maintenance & Trust
MSTW CSV EXPORTER Maintenance & Trust
Maintenance Signals
Community Trust
MSTW CSV EXPORTER Alternatives
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
WP All Export – Product Export Add-On for WooCommerce
product-export-for-woocommerce
Drag & drop to export products to CSV, Excel, or XML files of any format. Supports variations, images, attributes, brands, and more with powerful …
Export All Posts, Products, Orders, Refunds & Users
wp-ultimate-exporter
Export any WordPress website including WooCommerce data seamlessly with our powerful export plugin. Save records as CSV, XML, or Excel file for secure …
Export Plugin Details
export-plugin-details
Simple way to export your installed plugins list in CSV format.
Export Users Data CSV
export-users-data-csv
Export Users Data Plugin allows you to export users information with important meta data in CSV file format.
MSTW CSV EXPORTER Developer Profile
7 plugins · 550 total installs
How We Detect MSTW CSV EXPORTER
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mstw-csv-exporter/css/mstw-csvx-styles.css/wp-content/plugins/mstw-csv-exporter/js/ss-csv-cpt-type.jsHTML / DOM Fingerprints
MSTW_CSVX_JS_URL