
WP Export Users Security & Risk Analysis
wordpress.org/plugins/wp-export-usersAllows for custom csv user data output. It allows you to customize the Field Separators and Encapsulators. It gives you a preview of your data that …
Is WP Export Users Safe to Use in 2026?
Generally Safe
Score 85/100WP Export Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-export-users" v1.4 plugin exhibits a generally concerning security posture, despite the absence of publicly known vulnerabilities and a seemingly small attack surface. The static analysis reveals significant weaknesses in its code. Notably, 100% of its SQL queries are not using prepared statements, which is a critical risk for SQL injection vulnerabilities. Furthermore, none of the output operations are properly escaped, posing a high risk of cross-site scripting (XSS) attacks. The taint analysis also found two flows with unsanitized paths, which, although not classified as critical or high severity in this instance, indicate potential vulnerabilities if they were to involve sensitive data or be exploited in conjunction with other weaknesses.
The lack of nonce checks and capability checks on any entry points, combined with the unescaped output, creates a very insecure environment for user interaction and data handling within the plugin. While the plugin has no recorded CVEs, this could be due to a lack of thorough security auditing or a small user base. The absence of any security best practices like prepared statements and output escaping is a significant red flag. Overall, while the plugin doesn't present an immediate, known critical threat based on its history, the internal code analysis reveals fundamental security flaws that expose it to significant risks of SQL injection and XSS vulnerabilities.
Key Concerns
- Raw SQL without prepared statements
- Unescaped output
- No nonce checks
- No capability checks
- Taint flows with unsanitized paths
WP Export Users Security Vulnerabilities
WP Export Users Release Timeline
WP Export Users Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Export Users Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Export Users Maintenance & Trust
Maintenance Signals
Community Trust
WP Export Users Alternatives
WP Export Users Plus
wp-export-users-plus
This "Plus" version allows those users who have installed the WP-Members plugin (the one by Chad Butler) to export additional fields for the …
Export and Import Users and Customers
users-customers-import-export-for-wp-woocommerce
Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.
Import Users from CSV
import-users-from-csv
Import users from a CSV into WordPress
User Import with meta – WP Ultimate CSV Importer Add-on
import-users
Import and export WordPress and WooCommerce users with full user meta, custom fields, billing & shipping details, and membership data.
WP All Export – User Export Add-On
export-wp-users-xml-csv
Drag & drop to export users and all user data to a completely custom CSV, Excel, or XML of any format. Supports roles, metadata, custom fields, wi …
WP Export Users Developer Profile
2 plugins · 40 total installs
How We Detect WP Export Users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapoptionsredblue