Product Excel Import & Export for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-product-excel-importer

WordPress Plugin to Import Products and Export Products for Woocommerce in Bulk with Excel.

2K active installs v7.0.4 PHP 8.1+ WP 3.0.1+ Updated Jan 21, 2026
bulk-importexcel-importimport-productsproduct-exportproduct-import
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product Excel Import & Export for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Product Excel Import & Export for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "woo-product-excel-importer" plugin v7.0.4 exhibits a mixed security posture. While it demonstrates good practices like 100% usage of prepared statements for SQL queries and a complete absence of recorded vulnerabilities, significant concerns arise from its attack surface. A substantial portion of its AJAX handlers, 8 out of 10, lack authentication checks, creating a wide entry point for potential unauthorized actions. The presence of the `unserialize` function is a notable risk, as it can lead to Remote Code Execution if used with untrusted input, although the taint analysis does not currently show any exploitable flows. The plugin also shows room for improvement in output escaping, with only 57% of outputs being properly escaped, which could lead to Cross-Site Scripting vulnerabilities.

Key Concerns

  • 8 AJAX handlers without auth checks
  • Unescaped output detected
  • Use of unserialize() function
Vulnerabilities
None known

Product Excel Import & Export for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Product Excel Import & Export for WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
98
128 escaped
Nonce Checks
10
Capability Checks
6
File Operations
100
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$this->{$key} = unserialize(serialize($val));Classes\phpoffice\phpspreadsheet\src\PhpSpreadsheet\Worksheet\Worksheet.php:3492

Output Escaping

57% escaped226 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
woopei_process (import.php:147)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

Product Excel Import & Export for WooCommerce Attack Surface

Entry Points10
Unprotected8

AJAX Handlers 10

authwp_ajax_woopei_processwoo-product-excel-importer.php:80
noprivwp_ajax_woopei_processwoo-product-excel-importer.php:81
authwp_ajax_woopei_exportProductswoo-product-excel-importer.php:82
noprivwp_ajax_woopei_exportProductswoo-product-excel-importer.php:83
noprivwp_ajax_woopei_extensionswoo-product-excel-importer.php:265
authwp_ajax_woopei_extensionswoo-product-excel-importer.php:266
noprivwp_ajax_woopei_push_notwoo-product-excel-importer.php:463
authwp_ajax_woopei_push_notwoo-product-excel-importer.php:464
noprivwp_ajax_woopei_hide_ratingwoo-product-excel-importer.php:472
authwp_ajax_woopei_hide_ratingwoo-product-excel-importer.php:473
WordPress Hooks 9
actioninitincludes\class-wpfactory-wc-peie.php:65
actionbefore_woocommerce_initincludes\class-wpfactory-wc-peie.php:68
actioninitincludes\class-wpfactory-wc-peie.php:127
actionadmin_menuincludes\class-wpfactory-wc-peie.php:130
actionplugins_loadedwoo-product-excel-importer.php:40
actionadmin_enqueue_scriptswoo-product-excel-importer.php:74
actionadmin_footerwoo-product-excel-importer.php:85
filtercodecabin_deactivate_feedback_form_pluginswoo-product-excel-importer.php:415
actionadmin_noticeswoo-product-excel-importer.php:435
Maintenance & Trust

Product Excel Import & Export for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version8.1
Downloads171K

Community Trust

Rating66/100
Number of ratings29
Active installs2K
Developer Profile

Product Excel Import & Export for WooCommerce Developer Profile

WPFactory

63 plugins · 136K total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
90 days
View full developer profile
Detection Fingerprints

How We Detect Product Excel Import & Export for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-product-excel-importer/css/woo-importer.css/wp-content/plugins/woo-product-excel-importer/js/xlsx.js/wp-content/plugins/woo-product-excel-importer/js/filesaver.js/wp-content/plugins/woo-product-excel-importer/js/woo-importer.js/wp-content/plugins/woo-product-excel-importer/js/tableexport.js
Script Paths
/wp-content/plugins/woo-product-excel-importer/js/xlsx.js/wp-content/plugins/woo-product-excel-importer/js/filesaver.js/wp-content/plugins/woo-product-excel-importer/js/woo-importer.js/wp-content/plugins/woo-product-excel-importer/js/tableexport.js
Version Parameters
woo-product-excel-importer/css/woo-importer.css?v=woo-product-excel-importer/js/woo-importer.js?v=

HTML / DOM Fingerprints

CSS Classes
importer-wrapuploaderwoopeiFilenav-tab-activepremiumprowp_extensionsget_ajax+2 more
Data Attributes
data-action='woopei_process'data-action='woopei_exportProducts'
JS Globals
woopei
REST Endpoints
/wp-json/wpfactory_wc_peie/v1/get_products
FAQ

Frequently Asked Questions about Product Excel Import & Export for WooCommerce