Wp Convert Excel Data To Tabel And DB Security & Risk Analysis

wordpress.org/plugins/wpxlsdata

An Plugin to convert Excel files to WordPress database And manage data in your WordPress menu

90 active installs v1.2.0 PHP + WP 3.0.1+ Updated Oct 9, 2020
converterdbexcelhtmltabel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Wp Convert Excel Data To Tabel And DB Safe to Use in 2026?

Generally Safe

Score 85/100

Wp Convert Excel Data To Tabel And DB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wpxlsdata v1.2.0 plugin exhibits a concerning security posture primarily due to its significant number of unprotected AJAX handlers and a high percentage of unsanitized taint flows. While the plugin reports no known vulnerabilities and avoids dangerous functions, the presence of 5 AJAX handlers without authentication checks presents a substantial attack surface. The taint analysis revealing 4 high severity flows with unsanitized paths is a critical red flag, indicating potential for sensitive data exposure or malicious code injection through these pathways. The high volume of SQL queries (46) with a low rate of prepared statements (7%) further exacerbates the risk, potentially leading to SQL injection vulnerabilities if not handled with extreme care. Despite a 100% output escaping coverage, the fact that only 41% are properly escaped means a significant portion of output could be vulnerable to Cross-Site Scripting (XSS). The lack of known CVEs is positive, but it does not mitigate the inherent risks identified in the static and taint analysis.

Key Concerns

  • AJAX handlers without authentication checks
  • High severity taint flows with unsanitized paths
  • Low percentage of prepared statements in SQL queries
  • Low percentage of properly escaped output
Vulnerabilities
None known

Wp Convert Excel Data To Tabel And DB Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wp Convert Excel Data To Tabel And DB Code Analysis

Dangerous Functions
0
Raw SQL Queries
43
3 prepared
Unescaped Output
59
41 escaped
Nonce Checks
4
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

7% prepared46 total queries

Output Escaping

41% escaped100 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

9 flows5 with unsanitized paths
wpxlsdata_Admin_menue_db_show (inc\addmenue.php:246)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Wp Convert Excel Data To Tabel And DB Attack Surface

Entry Points6
Unprotected5

AJAX Handlers 5

authwp_ajax_wpxlsdata_exportinc\addmenue.php:15
authwp_ajax_edit_data_rowinc\addmenue.php:16
authwp_ajax_wpxlsdata_importinc\menue.php:14
authwp_ajax_wpxlsdata_add_shortcodeinc\menue.php:15
authwp_ajax_wpxlsdata_delete_shortcodeinc\menue.php:17

Shortcodes 1

[wpxlsdata] inc\shortcode.php:7
WordPress Hooks 4
actionadmin_menuinc\addmenue.php:14
actionadmin_menuinc\menue.php:12
actionadmin_enqueue_scriptsinc\menue.php:13
actionplugins_loadedwpxlsdata.php:35
Maintenance & Trust

Wp Convert Excel Data To Tabel And DB Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 9, 2020
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

Wp Convert Excel Data To Tabel And DB Developer Profile

behzadrohizadeh

5 plugins · 190 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wp Convert Excel Data To Tabel And DB

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpxlsdata/css/style.css
Script Paths
/wp-content/plugins/wpxlsdata/js/wpxlsdata.js
Version Parameters
wpxlsdata/style.css?ver=wpxlsdata/wpxlsdata.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-iddbdata-limitdata-isrowdata-rows
JS Globals
wpxlsdatathe_in_url
REST Endpoints
/wp-json/wpxlsdata/v1/items
Shortcode Output
[wpxlsdata type="tabel" iddb=
FAQ

Frequently Asked Questions about Wp Convert Excel Data To Tabel And DB