
Custom Post Exporter Security & Risk Analysis
wordpress.org/plugins/wp-exporterExport single or multiple posts, pages with comments, custom fields, categories, tags and more to an export file.
Is Custom Post Exporter Safe to Use in 2026?
Generally Safe
Score 92/100Custom Post Exporter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-exporter v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin has a minimal attack surface, with only one AJAX handler, and importantly, this handler appears to be protected (zero unprotected entry points). The code signals further reinforce this positive assessment, showing no dangerous functions, a complete absence of SQL queries (thus none without prepared statements), and a very high percentage of properly escaped output. The presence of nonce checks adds another layer of security. Taint analysis indicates no identified vulnerabilities related to unsanitized data flows.
The plugin's vulnerability history is also remarkably clean, with no recorded CVEs of any severity. This lack of historical vulnerabilities, combined with the positive static analysis findings, suggests that the developers have prioritized security in its development. However, it's worth noting the absence of capability checks. While the AJAX handler might be protected by nonces, it doesn't explicitly state whether it checks user roles or permissions before executing. This could be a potential oversight, though without further details on the AJAX handler's functionality, it's a minor concern in an otherwise robust security profile.
In conclusion, wp-exporter v1.0.0 appears to be a secure plugin. Its strengths lie in its limited attack surface, secure coding practices regarding SQL and output, and lack of historical vulnerabilities. The only area for potential, albeit minor, improvement would be the explicit addition of capability checks to further harden its entry points.
Key Concerns
- Missing capability checks on AJAX handler
Custom Post Exporter Security Vulnerabilities
Custom Post Exporter Release Timeline
Custom Post Exporter Code Analysis
Output Escaping
Custom Post Exporter Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Custom Post Exporter Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Exporter Alternatives
Export Single Post Page
single-post-page-export
Export (an XML file) a single post or page using WordPress' eXtended RSS (WXR). There's no need to export your entire database anymore!
Simple Export Import for ACF Data
simple-export-import-for-acf-data
With this plugin you simply export and import page, post and custom post. This plugin supports ACF fields.
Post Export Import with Media
post-export-import-with-media
Easily export and import WP posts, pages, media, widgets, menus, themes, plugins & settings with their media files- secure, fast, and with real-ti …
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies
postpage-import-export-with-custom-fields-taxonomies
Export and import WordPress posts & pages as JSON files with full support for custom fields, taxonomies, ACF fields, and featured images.
QuickExport: Single & Bulk Post/Page Exporter
quickexport-single-bulk-post-page
Easily export single or bulk posts/pages to clean WordPress XML with Elementor support, AJAX operations & customizable export fields.
Custom Post Exporter Developer Profile
2 plugins · 3K total installs
How We Detect Custom Post Exporter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-exporter/js/admin.js/wp-content/plugins/wp-exporter/js/admin.jscp-exporter-admin?ver=HTML / DOM Fingerprints
data-cp-exporter-noncecpExporter<select name="post_ids[]" size="8" multiple="multiple">