WPGeared Better Export Security & Risk Analysis

wordpress.org/plugins/wpgeared-better-export

Filter and export posts, pages, or custom post types to WXR or CSV with precise date, taxonomy, author, and field controls.

30 active installs v1.2.4 PHP 7.4+ WP 5.0+ Updated Nov 26, 2025
csvexportmigrationpostswxr
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPGeared Better Export Safe to Use in 2026?

Generally Safe

Score 100/100

WPGeared Better Export has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "wpgeared-better-export" plugin v1.2.4 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified CVEs and its clean vulnerability history are significant strengths, indicating a well-maintained and likely secure codebase over time. The code analysis reveals a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. Furthermore, the plugin demonstrates good practice by using prepared statements for all SQL queries and implementing nonce and capability checks for its identified entry points, albeit limited. The high percentage of properly escaped output is also a positive indicator against cross-site scripting vulnerabilities.

However, a minor concern arises from the presence of one file operation without further details on its nature or context. While the taint analysis shows no critical or high-severity unsanitized flows, the limited scope of analyzed flows (zero) means that deeper, more complex vulnerabilities might have been missed. The lack of external HTTP requests is a positive, reducing the risk of server-side request forgery or compromised update mechanisms. Overall, the plugin appears to be developed with security in mind, but the single file operation warrants attention, and a broader taint analysis might provide greater confidence.

Key Concerns

  • File operations without further context
Vulnerabilities
None known

WPGeared Better Export Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPGeared Better Export Release Timeline

v1.2.4Current
Code Analysis
Analyzed Mar 16, 2026

WPGeared Better Export Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
169 escaped
Nonce Checks
2
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped190 total outputs
Attack Surface

WPGeared Better Export Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuwpgeared-better-export.php:22
actionadmin_enqueue_scriptswpgeared-better-export.php:23
actionadmin_post_spe_export_postswpgeared-better-export.php:24
actionadmin_post_spe_export_datawpgeared-better-export.php:25
Maintenance & Trust

WPGeared Better Export Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 26, 2025
PHP min version7.4
Downloads287

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

WPGeared Better Export Developer Profile

WPGeared

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPGeared Better Export

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
/wpgeared-better-export/v1.2.4

HTML / DOM Fingerprints

CSS Classes
spe-containerspe-headerspe-cardspe-card-headerspe-card-bodyspe-form-sectionspe-form-section-titlespe-form-row+5 more
Data Attributes
data-spe-export-nonce
JS Globals
wpgeared_better_export_params
FAQ

Frequently Asked Questions about WPGeared Better Export