
WP All Export – Order Export for WooCommerce Security & Risk Analysis
wordpress.org/plugins/order-export-for-woocommerceDrag & drop to export orders to CSV, Excel, or XML files of any format. Supports customer data, line items, date range filtering, and more with po …
Is WP All Export – Order Export for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100WP All Export – Order Export for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "order-export-for-woocommerce" plugin, at version 1.0.5, exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding output escaping, with all identified outputs being properly escaped. The plugin also avoids making external HTTP requests and doesn't appear to have vulnerabilities recorded in its history, which is a strong indicator of a stable and well-maintained codebase. The absence of shortcodes, cron events, and REST API routes also limits the potential attack surface in these common areas. However, the presence of two instances of the `unserialize` function is a significant concern. When an attacker can control the serialized data passed to `unserialize`, it can lead to remote code execution vulnerabilities. While the static analysis didn't flag critical taint flows, the mere presence of `unserialize` without clear evidence of input sanitization or authentication checks for its input points to a potential risk that requires further scrutiny. Furthermore, the lack of any nonce checks or capability checks, combined with zero unprotected entry points, suggests that any potential exploitation of `unserialize` might not be immediately mitigated by standard WordPress security mechanisms.
Despite the lack of known CVEs and the generally clean code signals in other areas, the `unserialize` function represents a notable security weakness. The fact that 100% of outputs are escaped is commendable, but it does not negate the inherent dangers of deserializing untrusted data. The absence of historical vulnerabilities could mean that this specific vector hasn't been exploited or discovered yet, or that the data passed to `unserialize` is implicitly trusted within the plugin's context. However, as a security analyst, the principle of least privilege and input validation dictates caution. The plugin's strength lies in its clean output handling and lack of external dependencies, but its weakness is the potential for deserialization vulnerabilities, making its overall security posture moderately concerning.
Key Concerns
- Dangerous function: unserialize detected
- No nonce checks on entry points
- No capability checks on entry points
- Flows with unsanitized paths detected
WP All Export – Order Export for WooCommerce Security Vulnerabilities
WP All Export – Order Export for WooCommerce Release Timeline
WP All Export – Order Export for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP All Export – Order Export for WooCommerce Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP All Export – Order Export for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WP All Export – Order Export for WooCommerce Alternatives
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel
wp-ultimate-csv-importer
The #1 WordPress import export plugin. Bulk import CSV, XML & Excel into WordPress — WooCommerce products, posts, users, ACF fields, and more. Free.
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
woocommerce-exporter
Export WooCommerce products, orders, customers, categories, tags, subscriptions & more into formatted files like CSV, XML, Excel 2007, XLS, XLSX.
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export
wp-ultimate-exporter
Export WooCommerce products, orders, users, and any WordPress content to CSV, XML, or Excel. Bulk export posts, pages, custom post types, and more.
Import WooCommerce Suite for Products, Orders, Coupons, Reviews, and Customers | WP Ultimate CSV Importer
import-woocommerce
Import WooCommerce products, orders, coupons, customers, and reviews from CSV, XML, or Excel files. An add-on for WP Ultimate CSV Importer.
WP All Export – Order Export for WooCommerce Developer Profile
22 plugins · 217K total installs
How We Detect WP All Export – Order Export for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-export-for-woocommerce/vendor/wp-ali/wp-ali-core/assets/css/vendors/select2.css/wp-content/plugins/order-export-for-woocommerce/vendor/wp-ali/wp-ali-core/assets/js/vendors/select2.js/wp-content/plugins/order-export-for-woocommerce/assets/css/vendors/jquery-ui.css/wp-content/plugins/order-export-for-woocommerce/assets/js/vendors/jquery-ui.js/wp-content/plugins/order-export-for-woocommerce/assets/css/pmwoe-admin-page.css/wp-content/plugins/order-export-for-woocommerce/assets/js/pmwoe-admin-page.js/wp-content/plugins/order-export-for-woocommerce/assets/js/pmwoe-export-settings.js/wp-content/plugins/order-export-for-woocommerce/assets/js/pmwoe-order-fields.js+2 more/wp-content/plugins/order-export-for-woocommerce/vendor/wp-ali/wp-ali-core/assets/js/vendors/select2.js/wp-content/plugins/order-export-for-woocommerce/assets/js/vendors/jquery-ui.js/wp-content/plugins/order-export-for-woocommerce/assets/js/pmwoe-admin-page.js/wp-content/plugins/order-export-for-woocommerce/assets/js/pmwoe-export-settings.js/wp-content/plugins/order-export-for-woocommerce/assets/js/pmwoe-order-fields.js/wp-content/plugins/order-export-for-woocommerce/assets/js/pmwoe-plugin-settings.js+1 moreorder-export-for-woocommerce/vendor/wp-ali/wp-ali-core/assets/css/vendors/select2.css?ver=order-export-for-woocommerce/vendor/wp-ali/wp-ali-core/assets/js/vendors/select2.js?ver=order-export-for-woocommerce/assets/css/vendors/jquery-ui.css?ver=order-export-for-woocommerce/assets/js/vendors/jquery-ui.js?ver=order-export-for-woocommerce/assets/css/pmwoe-admin-page.css?ver=order-export-for-woocommerce/assets/js/pmwoe-admin-page.js?ver=order-export-for-woocommerce/assets/js/pmwoe-export-settings.js?ver=order-export-for-woocommerce/assets/js/pmwoe-order-fields.js?ver=order-export-for-woocommerce/assets/js/pmwoe-plugin-settings.js?ver=order-export-for-woocommerce/assets/js/pmwoe-users.js?ver=HTML / DOM Fingerprints
pmwoe-admin-pagepmwoe-export-settingspmwoe-order-fieldspmwoe-plugin-settingspmwoe-users<!-- Plugin root dir with forward slashes as directory separator regardless of actuall DIRECTORY_SEPARATOR value --><!-- Plugin root url for referencing static content --><!-- Plugin prefix for making names unique (be aware that this variable is used in conjuction with naming convention, -->
* i.e. in order to change it one must not only modify this constant but also rename all constants, classes and functions which
* names composed using this prefix) --><!-- Main plugin file, Introduces MVC pattern -->+12 moredata-prefix="pmwoe_"PMWOE_ROOT_DIRPMWOE_ROOT_URLPMWOE_PREFIXPMWOE_VERSIONPMWOE_EDITIONpmwoe_admin_page+5 more