
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Security & Risk Analysis
wordpress.org/plugins/postpage-import-export-with-custom-fields-taxonomiesExport and import WordPress posts & pages as JSON files with full support for custom fields, taxonomies, ACF fields, and featured images.
Is Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Safe to Use in 2026?
Generally Safe
Score 98/100Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'postpage-import-export-with-custom-fields-taxonomies' plugin v2.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has a high percentage of properly escaped output. The attack surface, while having two AJAX handlers, correctly implements nonce checks for both and also has capability checks on one handler, indicating an awareness of access control. The absence of critical or high severity taint flows is also a positive indicator.
However, several concerns warrant attention. The presence of two AJAX handlers without any explicit authorization checks (only nonce checks are mentioned) creates a potential avenue for attack if the nonce check is insufficient or can be bypassed. The fact that the plugin has a history of two known CVEs, with one high and one medium severity vulnerability in the past, is a significant red flag. The common vulnerability types, 'Unrestricted Upload of File with Dangerous Type' and 'Exposure of Sensitive Information to an Unauthorized Actor,' are serious issues that require careful attention to prevent recurrence. While there are currently no unpatched vulnerabilities, the past patterns suggest a potential for recurring security weaknesses.
In conclusion, the plugin has strengths in its secure SQL handling and output escaping. Nevertheless, the presence of unprotected AJAX entry points and a history of severe vulnerabilities necessitate a cautious approach. Continued vigilance and robust security audits are recommended to address potential risks.
Key Concerns
- AJAX handlers without explicit auth checks
- History of high severity CVE (1)
- History of medium severity CVE (1)
- File operations present
- External HTTP requests present
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Post/Page Copying Tool to Export and Import post/page for Cross site Migration <= 2.0.3 - Authenticated (Contributor+) Arbitrary File Upload
Post/Page Copying Tool <= 2.0.0 - Unauthenticated Sensitive Information Exposure
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Release Timeline
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Code Analysis
Output Escaping
Data Flow Analysis
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Maintenance & Trust
Maintenance Signals
Community Trust
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Alternatives
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
Duplicate Post
copy-delete-posts
Duplicate post
WP Scraper
wp-scraper
This Wordpress Scraper allows you to move a non-Wordpress website into a Wordpress site.
Quick Copy – Duplicate Posts & Pages
duplicator-post-page
Easily duplicate any post or page, including all metadata and taxonomies, with just one click.
Magic Export & Import
magic-export-import
The ultimate tool to migrate any content including posts, terms, users, comments, WooCommerce shop orders, menus and ACF Options pages.
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies Developer Profile
11 plugins · 1K total installs
How We Detect Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/postpage-import-export-with-custom-fields-taxonomies/assets/css/pp_wpspin_custom_style.css/wp-content/plugins/postpage-import-export-with-custom-fields-taxonomies/assets/js/pp_wpspin_custom.jsassets/js/pp_wpspin_custom.jspp_wpspin_css?ver=pp_wpspin_js?ver=HTML / DOM Fingerprints
data-nonce="pp_wpspin_ajax-nonce"pp_wpspin_ajax