Migrate Import Export WooCommerce Store with Excel Security & Risk Analysis

wordpress.org/plugins/store-migration-products-orders-import-export-with-excel

Import Orders Export Orders WooCommerce Products Subscriptions with Excel WordPress Plugin is a Store Migration solution to Migrate from/to WooCommerc …

100 active installs v3.0.3 PHP 8.1+ WP 3.0.1+ Updated Oct 13, 2025
excelimport-ordersmigrateorder-exportproduct-export
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Migrate Import Export WooCommerce Store with Excel Safe to Use in 2026?

Generally Safe

Score 100/100

Migrate Import Export WooCommerce Store with Excel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "store-migration-products-orders-import-export-with-excel" v3.0.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has a high percentage of properly escaped output. Furthermore, its vulnerability history is clean, with no known CVEs, which suggests a history of stable and secure development. This lack of past vulnerabilities is a strong indicator of a generally well-maintained codebase.

However, significant concerns arise from the attack surface analysis. With 18 AJAX handlers, all of which are unprotected by authentication checks, there is a substantial entry point for potential malicious activity. While there are 32 nonce checks and 16 capability checks present in the code, the fact that none of the identified AJAX handlers appear to leverage these makes them effectively useless for protecting these critical entry points. The taint analysis, while having a low total number of flows, did identify 2 flows with unsanitized paths, with 2 classified as high severity. These high-severity taint flows, particularly when combined with the unprotected AJAX handlers, represent the most critical immediate risks. This suggests a high likelihood of vulnerabilities like Cross-Site Scripting (XSS) or even Remote Code Execution (RCE) if these flows are indeed exploitable through the identified AJAX endpoints.

In conclusion, while the plugin has a clean track record and good practices in areas like SQL and output escaping, the overwhelming lack of authentication on its numerous AJAX handlers, coupled with high-severity unsanitized taint flows, presents a serious security risk. The developers need to prioritize securing these AJAX endpoints immediately. The absence of past vulnerabilities is a strength, but it does not negate the immediate dangers posed by the current code analysis.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized taint flows
Vulnerabilities
None known

Migrate Import Export WooCommerce Store with Excel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Migrate Import Export WooCommerce Store with Excel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
75
453 escaped
Nonce Checks
32
Capability Checks
16
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

86% escaped528 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

8 flows2 with unsanitized paths
importCoupons_process (includes\coupons.php:178)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
18 unprotected

Migrate Import Export WooCommerce Store with Excel Attack Surface

Entry Points18
Unprotected18

AJAX Handlers 18

noprivwp_ajax_import_processstore-migration-excel.php:90
authwp_ajax_import_processstore-migration-excel.php:91
authwp_ajax_export_processstore-migration-excel.php:93
noprivwp_ajax_export_processstore-migration-excel.php:94
authwp_ajax_exportUsers_processstore-migration-excel.php:96
noprivwp_ajax_exportUsers_processstore-migration-excel.php:97
authwp_ajax_exportCoupons_processstore-migration-excel.php:99
noprivwp_ajax_exportCoupons_processstore-migration-excel.php:100
authwp_ajax_exportOrders_processstore-migration-excel.php:102
noprivwp_ajax_exportOrders_processstore-migration-excel.php:103
authwp_ajax_importCustomers_processstore-migration-excel.php:105
noprivwp_ajax_importCustomers_processstore-migration-excel.php:106
authwp_ajax_importCoupons_processstore-migration-excel.php:108
noprivwp_ajax_importCoupons_processstore-migration-excel.php:109
authwp_ajax_importOrders_processstore-migration-excel.php:111
noprivwp_ajax_importOrders_processstore-migration-excel.php:112
noprivwp_ajax_push_notstore-migration-excel.php:135
authwp_ajax_push_notstore-migration-excel.php:136
WordPress Hooks 15
actioninitincludes\class-wpfactory-wc-procm.php:65
actionbefore_woocommerce_initincludes\class-wpfactory-wc-procm.php:68
actioninitincludes\class-wpfactory-wc-procm.php:127
filteradmin_menuincludes\class-wpfactory-wc-procm.php:130
actionuser_registerincludes\customers.php:502
actionpersonal_options_updateincludes\customers.php:503
actionedit_user_profile_updateincludes\customers.php:504
actionplugins_loadedstore-migration-excel.php:45
actionadmin_initstore-migration-excel.php:77
actionadmin_enqueue_scriptsstore-migration-excel.php:79
actionwpfactory_wc_procm_output_settingsstore-migration-excel.php:81
actionadmin_footerstore-migration-excel.php:83
filterwoocommerce_order_data_store_cpt_get_orders_querystore-migration-excel.php:114
filtercodecabin_deactivate_feedback_form_pluginsstore-migration-excel.php:119
actionadmin_noticesstore-migration-excel.php:134
Maintenance & Trust

Migrate Import Export WooCommerce Store with Excel Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 13, 2025
PHP min version8.1
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Migrate Import Export WooCommerce Store with Excel Developer Profile

WPFactory

63 plugins · 136K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
98 days
View full developer profile
Detection Fingerprints

How We Detect Migrate Import Export WooCommerce Store with Excel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/store-migration-products-orders-import-export-with-excel/css/backend.css/wp-content/plugins/store-migration-products-orders-import-export-with-excel/css/jquery-ui.css/wp-content/plugins/store-migration-products-orders-import-export-with-excel/js/xlsx.js/wp-content/plugins/store-migration-products-orders-import-export-with-excel/js/filesaver.js/wp-content/plugins/store-migration-products-orders-import-export-with-excel/js/tableexport.js/wp-content/plugins/store-migration-products-orders-import-export-with-excel/css/font-awesome.min.css
Script Paths
/wp-content/plugins/store-migration-products-orders-import-export-with-excel/js/xlsx.js/wp-content/plugins/store-migration-products-orders-import-export-with-excel/js/filesaver.js/wp-content/plugins/store-migration-products-orders-import-export-with-excel/js/tableexport.js
Version Parameters
store-migration-products-orders-import-export-with-excel/css/backend.css?v=olustore-migration-products-orders-import-export-with-excel/css/jquery-ui.cssstore-migration-products-orders-import-export-with-excel/js/xlsx.jsstore-migration-products-orders-import-export-with-excel/js/filesaver.jsstore-migration-products-orders-import-export-with-excel/js/tableexport.jsstore-migration-products-orders-import-export-with-excel/css/font-awesome.min.css

HTML / DOM Fingerprints

CSS Classes
eshopMigrationWooCommerce_notification
HTML Comments
<!-- StoreMigrationWooCommerce class. --><!-- Deactivation survey -->
JS Globals
window.eshopMigrationWooCommerce_signup
FAQ

Frequently Asked Questions about Migrate Import Export WooCommerce Store with Excel