WPS Menu Exporter Security & Risk Analysis

wordpress.org/plugins/wps-menu-exporter

WPS Menu Exporter lets you export only your WordPress menus via the WordPress Export page.

10K active installs v1.3.7.2 PHP + WP 4.2+ Updated Jun 24, 2025
exportexportermenumenuswordpress-menus
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WPS Menu Exporter Safe to Use in 2026?

Generally Safe

Score 100/100

WPS Menu Exporter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The wps-menu-exporter plugin version 1.3.7.2 exhibits a generally strong security posture based on the provided static analysis. There are no identified critical or high severity vulnerabilities in taint analysis, no known CVEs, and a very limited attack surface with no exposed entry points that lack authentication or capability checks. The plugin also avoids dangerous functions and file operations, which are common vectors for exploitation.

However, there are several areas of concern that temper this positive outlook. The most significant weakness lies in the output escaping, where only 29% of outputs are properly escaped. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, 78% of SQL queries use prepared statements, which is good, but 22% do not, potentially exposing the site to SQL injection if these queries handle user-supplied data without further sanitization.

The lack of any recorded vulnerabilities in the plugin's history is a positive sign, suggesting a diligent development team or simply a lack of targeted attacks. Nevertheless, the identified weaknesses in output escaping and raw SQL queries represent actionable security concerns that should be addressed to further strengthen the plugin's security.

Key Concerns

  • Low percentage of properly escaped output
  • SQL queries without prepared statements detected
Vulnerabilities
None known

WPS Menu Exporter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPS Menu Exporter Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
7 prepared
Unescaped Output
37
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

78% prepared9 total queries

Output Escaping

29% escaped52 total outputs
Attack Surface

WPS Menu Exporter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionload-export.phpclasses\plugin.php:10
actionload-export.phpclasses\plugin.php:11
actionadmin_noticesclasses\plugin.php:13
actionplugins_loadedwps-menu-exporter.php:34
Maintenance & Trust

WPS Menu Exporter Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 24, 2025
PHP min version
Downloads195K

Community Trust

Rating74/100
Number of ratings44
Active installs10K
Developer Profile

WPS Menu Exporter Developer Profile

NicolasKulka

9 plugins · 149K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
1444 days
View full developer profile
Detection Fingerprints

How We Detect WPS Menu Exporter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Generator Patterns
WPS Menu Exporter
Version Parameters
wps-menu-exporter

HTML / DOM Fingerprints

HTML Comments
<!-- This is a WordPress eXtended RSS file generated by WordPress as an export of your site. --><!-- It contains information about your site's posts, pages, comments, categories, and other content. --><!-- You may use this file to transfer that content from one site to another. --><!-- This file is not intended to be a complete backup of your site. -->+11 more
FAQ

Frequently Asked Questions about WPS Menu Exporter