Sextant Export & Import Security & Risk Analysis

wordpress.org/plugins/sextant-export

Export and import WooCommerce products via Excel. Edit your products in Excel, then import changes straight back. Free, no account required.

0 active installs v2.0.0 PHP 8.0+ WP 5.8+ Updated Mar 29, 2026
excelexportimportwoocommercexlsx
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sextant Export & Import Safe to Use in 2026?

Generally Safe

Score 100/100

Sextant Export & Import has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "sextant-export" v2.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any exposed AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code demonstrates excellent adherence to security best practices, with 100% of SQL queries using prepared statements and all output correctly escaped. The presence of nonce and capability checks also indicates a commitment to authorization and preventing unauthorized actions.

Despite the overall positive findings, the taint analysis reveals two flows with unsanitized paths. While these are not classified as critical or high severity, they represent a potential area of concern that warrants further investigation. The complete lack of documented vulnerabilities, including CVEs, suggests a mature and well-maintained codebase. However, it's important to note that the absence of historical vulnerabilities doesn't guarantee future security, and the identified unsanitized paths should be addressed proactively.

In conclusion, "sextant-export" v2.0.0 appears to be a secure plugin with a very low risk profile. Its strengths lie in its minimal attack surface and robust implementation of secure coding practices. The only noted weakness is the presence of unsanitized paths in the taint analysis, which, while not currently critical, should be treated as a minor area for improvement to achieve a completely hardened security profile.

Key Concerns

  • Taint flow with unsanitized path
  • Taint flow with unsanitized path
Vulnerabilities
None known

Sextant Export & Import Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sextant Export & Import Release Timeline

v2.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Sextant Export & Import Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
266 escaped
Nonce Checks
6
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped267 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
sxex_import_admin_page (sextant-export.php:366)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sextant Export & Import Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuincludes/class-error-reporter.php:140
actionadmin_post_sxex_send_reportincludes/class-error-reporter.php:141
actionplugins_loadedsextant-export.php:87
actionbefore_woocommerce_initsextant-export.php:90
actionadmin_noticessextant-export.php:100
actionadmin_menusextant-export.php:112
actionadmin_post_sxex_exportsextant-export.php:113
actionadmin_post_sxex_import_previewsextant-export.php:114
actionadmin_post_sxex_import_executesextant-export.php:115
Maintenance & Trust

Sextant Export & Import Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 29, 2026
PHP min version8.0
Downloads60

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sextant Export & Import Developer Profile

astraiosplugins

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sextant Export & Import

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sextant-export/assets/css/admin-styles.css/wp-content/plugins/sextant-export/assets/js/admin-scripts.js
Script Paths
/wp-content/plugins/sextant-export/assets/js/admin-scripts.js
Version Parameters
sextant-export/assets/css/admin-styles.css?ver=sextant-export/assets/js/admin-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
sxex-admin-wrapsxex-buttonsxex-export-formsxex-import-formsxex-notice-wrapsxex-radio-group
HTML Comments
<!-- Sextant Export & Import --><!-- Admin Interface --><!-- Export Form --><!-- Import Form -->
Data Attributes
data-sxex-fielddata-sxex-type
JS Globals
sxex_admin_params
REST Endpoints
/wp-json/sxex/v1/products/wp-json/sxex/v1/categories/wp-json/sxex/v1/tags
FAQ

Frequently Asked Questions about Sextant Export & Import