Import Users & Customers | Export Users with Excel for WordPress & WooCommerce Security & Risk Analysis

wordpress.org/plugins/users-import-export-with-excel-for-wp

WordPress Plugin to import Users and export Users with Excel for WordPress and WooCommerce Customers Import Export

100 active installs v1.6 PHP 8.1+ WP 3.0.1+ Updated Nov 25, 2024
customers-importexport-exceluser-exportuser-importusers-import
90
A · Safe
CVEs total1
Unpatched0
Last CVEOct 7, 2024
Download
Safety Verdict

Is Import Users & Customers | Export Users with Excel for WordPress & WooCommerce Safe to Use in 2026?

Generally Safe

Score 90/100

Import Users & Customers | Export Users with Excel for WordPress & WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 7, 2024Updated 1yr ago
Risk Assessment

This plugin presents a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries, performs nonce checks on all its AJAX handlers, and properly escapes a high percentage of its output. There are no critical or high-severity taint analysis findings, nor are there any raw SQL queries or file operations that raise immediate red flags.

However, a significant concern is the presence of 8 AJAX handlers, with 6 of them lacking authentication checks. This creates a substantial attack surface, as unauthorized users could potentially trigger these functions. While there's only one past high-severity vulnerability related to XML External Entity Reference, and it is patched, this history, combined with the current lack of authentication on numerous entry points, suggests a potential for future vulnerabilities if not managed carefully. The plugin's strengths lie in its secure handling of data processing, but its susceptibility to unauthorized access through unprotected AJAX endpoints is a notable weakness.

Key Concerns

  • 6 unprotected AJAX handlers
  • 1 historical high-severity CVE
  • 22% improperly escaped output
Vulnerabilities
1

Import Users & Customers | Export Users with Excel for WordPress & WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-45293high · 7.5Improper Restriction of XML External Entity Reference

PHPSpreadsheet Library < 2.3.0 - XXE Injection

Oct 7, 2024 Patched in 1.6 (183d)
Code Analysis
Analyzed Mar 16, 2026

Import Users & Customers | Export Users with Excel for WordPress & WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
16
57 escaped
Nonce Checks
8
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

78% escaped73 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
imue_process (users-customers-import-export-excel-wp_users.php:440)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Import Users & Customers | Export Users with Excel for WordPress & WooCommerce Attack Surface

Entry Points8
Unprotected6

AJAX Handlers 8

authwp_ajax_imue_processusers-customers-import-export-excel-wp.php:80
noprivwp_ajax_imue_processusers-customers-import-export-excel-wp.php:81
authwp_ajax_imue_exportUsersusers-customers-import-export-excel-wp.php:85
noprivwp_ajax_imue_exportUsersusers-customers-import-export-excel-wp.php:86
noprivwp_ajax_imue_push_notusers-customers-import-export-excel-wp.php:313
authwp_ajax_imue_push_notusers-customers-import-export-excel-wp.php:314
noprivwp_ajax_imue_extensionsusers-customers-import-export-excel-wp.php:335
authwp_ajax_imue_extensionsusers-customers-import-export-excel-wp.php:336
WordPress Hooks 8
actionplugins_loadedusers-customers-import-export-excel-wp.php:26
actionadmin_noticesusers-customers-import-export-excel-wp.php:44
actionadmin_enqueue_scriptsusers-customers-import-export-excel-wp.php:76
actionadmin_menuusers-customers-import-export-excel-wp.php:99
actionadmin_footerusers-customers-import-export-excel-wp.php:257
filtercodecabin_deactivate_feedback_form_pluginsusers-customers-import-export-excel-wp.php:263
actionadmin_noticesusers-customers-import-export-excel-wp.php:285
actionbefore_woocommerce_initusers-customers-import-export-excel-wp.php:323
Maintenance & Trust

Import Users & Customers | Export Users with Excel for WordPress & WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 25, 2024
PHP min version8.1
Downloads6K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Import Users & Customers | Export Users with Excel for WordPress & WooCommerce Developer Profile

WPFactory

63 plugins · 136K total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
90 days
View full developer profile
Detection Fingerprints

How We Detect Import Users & Customers | Export Users with Excel for WordPress & WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/users-import-export-with-excel-for-wp/css/imue.css/wp-content/plugins/users-import-export-with-excel-for-wp/css/font-awesome.min.css/wp-content/plugins/users-import-export-with-excel-for-wp/js/xlsx.js/wp-content/plugins/users-import-export-with-excel-for-wp/js/filesaver.js/wp-content/plugins/users-import-export-with-excel-for-wp/js/imue.js/wp-content/plugins/users-import-export-with-excel-for-wp/images/users-customers-import-export-excel-wp-woocommerce-pro.png
Script Paths
/wp-content/plugins/users-import-export-with-excel-for-wp/js/xlsx.js/wp-content/plugins/users-import-export-with-excel-for-wp/js/filesaver.js/wp-content/plugins/users-import-export-with-excel-for-wp/js/imue.js
Version Parameters
/wp-content/plugins/users-import-export-with-excel-for-wp/css/imue.css?v=olu

HTML / DOM Fingerprints

CSS Classes
imuenav-tab-activepremmainWrapperrightToLeftproVersioncenterpremium_img+3 more
HTML Comments
<!-- RUN IMPORT BATCH --><!-- RUN EXPORT BATCH --><!-- ON ACTIVATION OF FREE , DEACTIVE THE PRO IF ENABLED --><!-- ADD MENU LINK AND PAGE FOR WOOCOMMERCE IMPORTER -->+1 more
Data Attributes
data-tab
JS Globals
imue
REST Endpoints
/wp-json/users-import-export-with-excel-for-wp/v1/data
FAQ

Frequently Asked Questions about Import Users & Customers | Export Users with Excel for WordPress & WooCommerce