
Webuilders Import Export Security & Risk Analysis
wordpress.org/plugins/webuilders-import-exportImport and export WordPress data with field mapping support.
Is Webuilders Import Export Safe to Use in 2026?
Generally Safe
Score 100/100Webuilders Import Export has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "webuilders-import-export" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by properly escaping all output and using prepared statements for a high percentage of its SQL queries. The lack of known vulnerabilities in its history is also a strong positive indicator, suggesting a generally secure development approach.
However, the static analysis reveals critical areas of concern. The presence of the `unserialize` function is a significant risk, especially when combined with two taint analysis flows identified as having "unsanitized paths." While the plugin doesn't expose these via REST API or shortcodes, the AJAX handlers, even though they have nonce checks in this version, could still be vulnerable if the unserialized data originates from an untrusted source. The absence of capability checks on entry points is another weakness that could potentially be exploited if an attacker can trigger these AJAX handlers without proper user authorization.
In conclusion, while the plugin has a clean vulnerability history and good output handling, the identified risks associated with `unserialize` and unsanitized taint flows in AJAX handlers warrant careful attention. The lack of capability checks further exacerbates this potential risk.
Key Concerns
- Taint flow with unsanitized path (High severity)
- Taint flow with unsanitized path (High severity)
- Dangerous function: unserialize
- No capability checks on entry points
Webuilders Import Export Security Vulnerabilities
Webuilders Import Export Release Timeline
Webuilders Import Export Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Webuilders Import Export Attack Surface
AJAX Handlers 3
WordPress Hooks 3
Maintenance & Trust
Webuilders Import Export Maintenance & Trust
Maintenance Signals
Community Trust
Webuilders Import Export Alternatives
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Export Import Menus
export-import-menus
A plugin that lets you export and import your WordPress menus in our own website under Appearance section to Export/Import Menus.
Customizer Backup & Reset
customizer-reset-by-wpzoom
Reset theme customizations made via WordPress Customizer with backup, export, and import features.
Menu Backup & Restore + Import/Export
menu-backup-restore
Protect WordPress menus with automatic backups, one-click restore, and import/export. Transfer menus between sites with ease.
Transfer Press – The Ultimate WordPress Plugin Zip Downloader, Activator
transfer-press
Easily download and transfer plugins zip between WordPress sites without FTP/Manual file handling.
Webuilders Import Export Developer Profile
1 plugin · 0 total installs
How We Detect Webuilders Import Export
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webuilders-import-export/css/admin-style.css/wp-content/plugins/webuilders-import-export/js/admin-script.js/wp-content/plugins/webuilders-import-export/js/admin-script.jswebuilders-import-export/css/admin-style.css?ver=webuilders-import-export/js/admin-script.js?ver=HTML / DOM Fingerprints
webim-cardwebim-meta-cardwebim-card-titlewebim-meta-gridwebim-selection-itemwebim_ajaxwebim_ajax