Export WordPress Menus Security & Risk Analysis

wordpress.org/plugins/wp-export-menus

Export WordPress Menus plugin allows you to export your WordPress Menus. You can also export menus month wise. A filter is provided to export menus fo …

1K active installs v1.2 PHP 5.6+ WP 1.4+ Updated Mar 12, 2021
exportexportermenuswordpress-menus
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Export WordPress Menus Safe to Use in 2026?

Generally Safe

Score 85/100

Export WordPress Menus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wp-export-menus plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks significantly limits its attack surface. Furthermore, the code utilizes prepared statements for all SQL queries and has a high percentage of properly escaped output, which are excellent security practices. The lack of file operations and external HTTP requests also reduces potential vulnerabilities. The plugin's vulnerability history is completely clean, with zero recorded CVEs, indicating a consistent track record of secure development. The only minor area for potential improvement, albeit not a direct security flaw given the zero attack surface, is the presence of only one nonce check. While not a concern currently due to the lack of entry points requiring them, a more robust approach might include nonce checks on any future additions to the plugin's functionality, even if protected by capability checks.

Overall, this plugin appears to be well-secured with no immediate critical or high-severity risks identified from the static analysis or vulnerability history. The developers have implemented robust practices for data handling and sanitization. The plugin's strengths lie in its minimal attack surface and diligent use of secure coding techniques for database interactions and output. The absence of any known vulnerabilities further reinforces its secure standing. The plugin's current security is excellent, with no significant weaknesses evident from the data provided.

Vulnerabilities
None known

Export WordPress Menus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Export WordPress Menus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
8
69 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared9 total queries

Output Escaping

90% escaped77 total outputs
Attack Surface

Export WordPress Menus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionexport_filterswp-export-menus.php:35
filterexport_argswp-export-menus.php:36
actionadmin_headwp-export-menus.php:37
actioninitwp-export-menus.php:40
filterts_deativate_plugin_questionswp-export-menus.php:44
filterts_tracker_datawp-export-menus.php:45
filterts_tracker_opt_out_datawp-export-menus.php:46
actionadmin_initwp-export-menus.php:47
Maintenance & Trust

Export WordPress Menus Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 12, 2021
PHP min version5.6
Downloads67K

Community Trust

Rating70/100
Number of ratings24
Active installs1K
Developer Profile

Export WordPress Menus Developer Profile

tychesoftwares

20 plugins · 160K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
232 days
View full developer profile
Detection Fingerprints

How We Detect Export WordPress Menus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Generator Patterns
WordPress eXtended RSS file generated by WordPress

HTML / DOM Fingerprints

CSS Classes
nav-menu-item-filterslabel-responsive
HTML Comments
This is a WordPress eXtended RSS file generated by WordPress as an export of your site.It contains information about your site's posts, pages, comments, categories, and other content.You may use this file to transfer that content from one site to another.This file is not intended to serve as a complete backup of your site.+11 more
Data Attributes
name="content"id="nav-menu-item-start-date"name="nav_menu_item_start_date"id="nav-menu-item-end-date"name="nav-menu-item_end_date"
JS Globals
jQuery
FAQ

Frequently Asked Questions about Export WordPress Menus