Simple WC order Export/Import Security & Risk Analysis

wordpress.org/plugins/simple-wc-order-exportimport

Simple WC order Export/Import is a plugin for export and import orders of woocommerce. While importing Products sometime products get new ID's so …

10 active installs v1.1 PHP 5.2.4+ WP 4.4+ Updated Jan 25, 2018
csvexportimportorderwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple WC order Export/Import Safe to Use in 2026?

Generally Safe

Score 85/100

Simple WC order Export/Import has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "simple-wc-order-exportimport" v1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, critical or high severity taint flows, and the proper use of prepared statements for all SQL queries are significant strengths. Furthermore, the total lack of unprotected entry points, including AJAX handlers, REST API routes, shortcodes, and cron events, suggests a conscious effort to implement robust access controls. However, there are areas for improvement. The percentage of properly escaped output is only 66%, indicating a potential for cross-site scripting (XSS) vulnerabilities if certain outputs are not handled with sufficient care. Additionally, while capability checks are present, the limited number (2) in conjunction with the 4 AJAX handlers might suggest that not all potential privilege escalation vectors have been thoroughly addressed, though the absence of unprotected AJAX handlers mitigates this risk significantly in this specific version.

Overall, the plugin demonstrates good security practices in critical areas like SQL injection prevention and access control. The vulnerability history being clear of any past issues is a positive indicator of developer diligence. The primary area of concern lies in the output escaping, which requires attention to prevent potential XSS. While the number of capability checks is low, the strict enforcement on all entry points provides a strong defense for now. The conclusion is that this plugin is likely safe for use, but a review and enhancement of output escaping mechanisms would further strengthen its security.

Key Concerns

  • Output escaping is not fully implemented (66%)
Vulnerabilities
None known

Simple WC order Export/Import Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple WC order Export/Import Release Timeline

v1.1Current
Code Analysis
Analyzed Apr 16, 2026

Simple WC order Export/Import Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
16 prepared
Unescaped Output
21
41 escaped
Nonce Checks
4
Capability Checks
2
File Operations
14
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared16 total queries

Output Escaping

66% escaped62 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
SWOEI_render_submenu_pages (woo_order_imex.php:105)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple WC order Export/Import Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_SWOEI_orderMappinginc/ajax_request.php:50
noprivwp_ajax_SWOEI_orderMappinginc/ajax_request.php:51
authwp_ajax_SWOEI_dbBackupinc/ajax_request.php:120
noprivwp_ajax_SWOEI_dbBackupinc/ajax_request.php:121
WordPress Hooks 4
actionadmin_initwoo_order_imex.php:43
actionadmin_menuwoo_order_imex.php:46
actionadmin_enqueue_scriptswoo_order_imex.php:49
actionadmin_noticeswoo_order_imex.php:62
Maintenance & Trust

Simple WC order Export/Import Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 25, 2018
PHP min version5.2.4
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Simple WC order Export/Import Developer Profile

webman technologies

5 plugins · 420 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple WC order Export/Import

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-wc-order-exportimport/assets/css/style.css/wp-content/plugins/simple-wc-order-exportimport/assets/js/script.js/wp-content/plugins/simple-wc-order-exportimport/assets/js/jquery.validate.min.js/wp-content/plugins/simple-wc-order-exportimport/assets/js/jquery.dataTables.min.js/wp-content/plugins/simple-wc-order-exportimport/assets/js/dataTables.buttons.min.js/wp-content/plugins/simple-wc-order-exportimport/assets/js/jszip.min.js/wp-content/plugins/simple-wc-order-exportimport/assets/js/pdfmake.min.js/wp-content/plugins/simple-wc-order-exportimport/assets/js/vfs_fonts.js+2 more
Script Paths
/wp-content/plugins/simple-wc-order-exportimport/assets/js/script.js
Version Parameters
simple-wc-order-exportimport/assets/css/style.css?ver=simple-wc-order-exportimport/assets/js/script.js?ver=simple-wc-order-exportimport/assets/js/jquery.validate.min.js?ver=simple-wc-order-exportimport/assets/js/jquery.dataTables.min.js?ver=simple-wc-order-exportimport/assets/js/dataTables.buttons.min.js?ver=simple-wc-order-exportimport/assets/js/jszip.min.js?ver=simple-wc-order-exportimport/assets/js/pdfmake.min.js?ver=simple-wc-order-exportimport/assets/js/vfs_fonts.js?ver=simple-wc-order-exportimport/assets/js/buttons.html5.min.js?ver=simple-wc-order-exportimport/assets/js/buttons.print.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
SWOEI_noticeSWOEI_export_wrappertabtablinkstabcontentdb_backup_wrapperdbbackup_button
Data Attributes
data-tab
JS Globals
SWOEI_openTab
FAQ

Frequently Asked Questions about Simple WC order Export/Import