Plugin Pulse
← Pulse

Import and export users and customers

by Javier Carazo · Content & Feeds

Also makes 2 other plugins · 70.8K+ installs across the portfolio →

Bulk import and export WordPress users and WooCommerce customers from CSV, including roles, passwords and any custom meta.

How scoring works →
90 Health · A
Maintenance 100/100
Rating quality 92/100
Support 70/100

90 health vs 60 average across 779 Content & Feeds plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

98 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 92/100
Listing tuning 100/100
Support resolution 100/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-8% vs prior 30d
1.3KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

166.5K

now · peak 259.0K

166.1K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Import and export us · #583 you Import Users from CS · #1527 WP All Export · #4619 Export Users Data CS · #6013

Rating trend

Star average over time · dips mark rough releases

4.7Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

2.4Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

33

releases in the last 12 months

2mo ago

latest release · v2.4.1

373

tagged releases on record

Recent releases

2.4.1 · 2mo ago2.4 · 2mo ago2.3.9 · 2mo ago2.3.8 · 2mo ago2.3.7 · 2mo ago2.3.6 · 2mo ago2.3.5 · 3mo ago2.3.4 · 3mo ago2.3.3 · 3mo ago2.3.2 · 3mo ago2.3.1 · 3mo ago2.3 · 3mo ago2.2.3 · 3mo ago2.2.2 · 3mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 37% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v2.4 37%
v1.29 16%
v2.3 9.3%
v2.0 6.1%
v1.27 5.4%
v1.28 5.2%
Older / other versions 20%

Estimated active installs

The public count shows “70K+”. Our estimate pins where the real number sits.

tracked estimate
70K–80K ≈77K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-03-27 · 1,478 observations

70KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
2.4.13
Last updated
11d ago
Added
2014-07-14 · 12 yrs old
Requires WP
5.5
Tested up to
7.0.4
Requires PHP

Recent reviews

All reviews on wp.org ↗
  1. kentsmythe
    3mo ago

    The plugin did exactly what I needed. Support was quick and friendly. Solved my one issue immediately.

    Read on wp.org ↗
  2. pendle666
    3mo ago

    I was having an issue with some settings for users, and all I wanted was a list of all my users and what each setting was. Although it gave me loads of columns, I found what I was looking for and was able to do my changes without having to look at each individual user.

    Read on wp.org ↗
  3. felixsh
    4mo ago

    This plugin is very useful and works well for our user import workflow.The developer was very helpful, responsive, and open to feedback. It is great to see that the plugin is actively maintained and improved. Looking forward to using it in the future. Thanks Javier! 🙂

    Read on wp.org ↗
  4. wpnovice2
    12mo ago

    I’ve used this for years, importing classlists and updating classlists each term with my courses. Lots of detailed options, I haven’t tried them all, but the ones I have used have all worked well, especially related to user roles and custom fields.

    Read on wp.org ↗
  5. Arischvaran Puvanesvaran
    1.2y ago

    Used this on a client site, since WP All Import Export free version is actually not “free” at all. It even managed to import the custom roles that I created using the Members plugin. Thanks for the great work!

    Read on wp.org ↗
  6. Paolo Beccari
    1.2y ago

    I had to transfer 900+ users of an old website (not WP), furthermore the target project is full of custom fields, extra user roles and further data. After exporting some test users on a CSV file I checked and edited all the field names in order to match my new WP website structure.The final import of all 900+ users was quick and precise.Everything smooth like oil. Anything you can imagine to export on a CSV file can be easily imported into WP, you just need to be very precise and careful with the names of the columns you need to import.Just remember: username and email columns MUST be the first ones in any import file!

    Read on wp.org ↗
  7. natashaconnectedmarketing
    1.3y ago

    This plugin did exactly what I needed in 5 minutes and didn’t crash my site like some other plugins. I highly recommend.

    Read on wp.org ↗
  8. Henry Douglas
    1.3y ago

    Great plugin.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 2.4.4 Security fix: the BuddyPress/BuddyBoss bp_avatar CSV import now also rejects link-local ( 169.254.0.0/16 ), carrier-grade NAT ( 100.64.0.0/10 , 198.18.0.0/15 ) and other private IP ranges after resolving the URL’s host, 2.4.4
  2. Version 2.4.3 Security fix: the BuddyPress/BuddyBoss bp_avatar CSV import now fetches remote URLs with wp_safe_remote_get() instead of file_get_contents() , preventing a Server-Side Request Forgery that let an admin-supplied URL make 2.4.3
  3. Version 2.4.2 Security fix: added current_user_can('promote_users') check (plus filtering against the actor’s editable roles) before applying any role during import, preventing a user with only create_users from creating or promoting 2.4.2
  4. Version 2.4.1 Security fix: the acui_email_template_selected AJAX handler now requires edit_others_posts (filterable via acui_capability ) and verifies the requested post’s post_type is acui_email_template , preventing a low-privilege 2.4.1
  5. Version 2.4 Security fix: added current_user_can('edit_user', $user_id) check before every wp_set_password() call during import, preventing a user with create_users access from resetting passwords of accounts they are not authorised 2.4
  6. Version 2.3.9 Fixed fatal error “array_intersect(): Argument #1 must be of type array, bool given” in async cron step 2+ when the roles_appeared transient had expired 2.3.9

Known vulnerabilities

via Wordfence Intelligence

25 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-07-24 CVE-2025-15673 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 2.4.3 Patched in 2.4.3
  2. 2026-07-09 CVE-2026-15026 Missing Authorization Affects <= 2.4.0 Patched in 2.4.1
  3. 2026-05-01 CVE-2026-7641 Improper Privilege Management Affects <= 2.0.8 Patched in 2.0.9
  4. 2026-03-21 CVE-2026-3629 Improper Privilege Management Affects <= 1.29.7 Patched in 2.0
  5. 2025-01-27 CVE-2025-24689 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.27.12 Patched in 1.27.13
  6. 2024-10-24 CVE-2024-50413 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.27.5 Patched in 1.27.6
  7. 2024-08-07 CVE-2024-38787 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.26.8 Patched in 1.26.9
  8. 2024-05-14 CVE-2024-4734 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.26.6.1 Patched in 1.26.7
  9. 2024-05-14 CVE-2024-4656 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.26.6.1 Patched in 1.26.7
  10. 2024-05-09 CVE-2024-34815 Missing Authorization Affects <= 1.26.5 Patched in 1.26.6
  11. 2024-05-03 CVE-2024-1050 Missing Authorization Affects <= 1.26.5 Patched in 1.26.6
  12. 2024-04-22 CVE-2024-32817 Deserialization of Untrusted Data Affects <= 1.26.2 Patched in 1.26.3
  13. 2024-01-16 CVE-2024-22151 Missing Authorization Affects <= 1.24.6 Patched in 1.24.7
  14. 2023-12-11 CVE-2023-6624 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.24.3 Patched in 1.24.4
  15. 2023-12-08 CVE-2023-6583 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 1.24.2 Patched in 1.24.3
  16. 2022-10-17 CVE-2022-3558 Improper Neutralization of Formula Elements in a CSV File Affects <= 1.20.4 Patched in 1.20.5
  17. 2022-04-11 CVE-2022-1255 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.19.2.1 Patched in 1.19.2.1
  18. 2020-11-20 CVE-2020-22277 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 1.16.3.5 Patched in 1.16.3.6
  19. 2020-01-01 Improper Privilege Management Affects 1.15 Patched in 1.15.0.1
  20. 2019-06-22 CVE-2019-14683 Cross-Site Request Forgery (CSRF) Affects <= 1.14.1.3 Patched in 1.14.2.2
  21. 2019-06-20 CVE-2019-15326 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 1.14.2.1 Patched in 1.14.2.2
  22. 2019-06-20 CVE-2019-15327 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.14.1.2 Patched in 1.14.1.3
  23. 2019-03-14 CVE-2019-15328 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.14.0.3 Patched in 1.14.0.3
  24. 2019-03-14 CVE-2019-15329 Cross-Site Request Forgery (CSRF) Affects < 1.14.0.3 Patched in 1.14.0.3
  25. 2018-12-11 CVE-2018-20101 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.12.1 Patched in 1.12.1

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 14 languages, 2 at 90% or more

German 98%
German (Formal) 90%
Spanish (Ecuador) 49%
German (Austria) 46%
Spanish (Spain) 37%
Spanish (Colombia) 36%
Spanish (Mexico) 36%
Spanish (Venezuela) 36%
Japanese 35%
Swedish 27%
Spanish (Argentina) 24%
Dutch 10%
Italian 9%
Chinese (China) 8%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-04-15 80K+ → 70K+ down after 436 days in tier
  2. 2025-02-03 70K+ → 80K+ up after 13 days in tier
  3. 2025-01-21 80K+ → 70K+ down after 707 days in tier
  4. 2023-02-14 70K+ → 80K+ up after 2 days in tier
  5. 2023-02-12 80K+ → 70K+ down after 1 days in tier
  6. 2023-02-11 70K+ → 80K+ up after 1 days in tier
  7. 2023-02-10 80K+ → 70K+ down after 1 days in tier
  8. 2023-02-09 70K+ → 80K+ up

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Import and export users and customers into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/import-users-from-csv-with-meta" width="480" height="300" style="border:0" loading="lazy" title="Import and export users and customers — Plugin Pulse"></iframe>
Preview card ↗

Import and export users and customers: 70K+ active installs, 4.7★ (256 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/import-users-from-csv-with-meta