{"id":365303,"date":"2026-09-09T19:41:18","date_gmt":"2026-09-09T19:41:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/beardo-multisite-user-export\/"},"modified":"2026-09-09T19:41:04","modified_gmt":"2026-09-09T19:41:04","slug":"beardo-multisite-user-export","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/beardo-multisite-user-export\/","author":23519436,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3","stable_tag":"1.3","tested":"7.1","requires":"5.8","requires_php":"8.0","requires_plugins":null,"header_name":"Beardo Multisite User Export","header_author":"Beardo.Tools","header_description":"Export users from WordPress multisite network by role, site, status, and date range. Supports CSV and Excel formats with comprehensive security measures.","assets_banners_color":"f8fbfd","last_updated":"2026-09-09 19:41:04","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/beardo.tools\/donate\/","header_plugin_uri":"https:\/\/beardo.tools\/plugins\/multisite-user-export\/","header_author_uri":"https:\/\/beardo.tools","rating":0,"author_block_rating":0,"active_installs":0,"downloads":34,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.3":{"tag":"1.3","author":"beardotools","date":"2026-09-09 19:41:04","revision":3688923}},"upgrade_notice":{"1.3":"<p>Rebrand release: the plugin is now Beardo Multisite User Export. Internal option keys changed, so the export history from earlier versions is not carried over and the retention window returns to its 90-day default.<\/p>","1.2.1":"<p>Visual polish: the admin screen now follows your admin color scheme, including dark-mode admin themes.<\/p>","1.2":"<p>Security hardening release (admin XSS fix, input validation, CSV escaping). Update recommended for all networks.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.gif":{"filename":"icon-128x128.gif","revision":3688923,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.gif":{"filename":"icon-256x256.gif","revision":3688923,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3688923,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3688923,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3688923,"resolution":"1","location":"assets","locale":"","width":2062,"height":1308},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3688923,"resolution":"2","location":"assets","locale":"","width":2065,"height":1273},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3688923,"resolution":"3","location":"assets","locale":"","width":2059,"height":1231},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3688923,"resolution":"4","location":"assets","locale":"","width":2095,"height":1041}},"screenshots":{"1":"Export Users by Site: choose a site and its real roles load, with user counts","2":"Export Users by Role: network-wide role selection with unique user counts","3":"Field selection, status filter, registration date range, and format","4":"Export History Log: the full audit trail, downloadable as CSV"}},"plugin_section":[],"plugin_tags":[567,28272,441,325,154044],"plugin_category":[51],"plugin_contributors":[271446],"plugin_business_model":[],"class_list":["post-365303","plugin","type-plugin","status-publish","hentry","plugin_tags-csv","plugin_tags-export-users","plugin_tags-multisite","plugin_tags-network","plugin_tags-user-export","plugin_category-multisite","plugin_contributors-beardotools","plugin_committers-beardotools"],"banners":{"banner":"https:\/\/ps.w.org\/beardo-multisite-user-export\/assets\/banner-772x250.png?rev=3688923","banner_2x":"https:\/\/ps.w.org\/beardo-multisite-user-export\/assets\/banner-1544x500.png?rev=3688923","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/beardo-multisite-user-export\/assets\/icon-128x128.gif?rev=3688923","icon_2x":"https:\/\/ps.w.org\/beardo-multisite-user-export\/assets\/icon-256x256.gif?rev=3688923","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/beardo-multisite-user-export\/assets\/screenshot-1.png?rev=3688923","caption":"Export Users by Site: choose a site and its real roles load, with user counts"},{"src":"https:\/\/ps.w.org\/beardo-multisite-user-export\/assets\/screenshot-2.png?rev=3688923","caption":"Export Users by Role: network-wide role selection with unique user counts"},{"src":"https:\/\/ps.w.org\/beardo-multisite-user-export\/assets\/screenshot-3.png?rev=3688923","caption":"Field selection, status filter, registration date range, and format"},{"src":"https:\/\/ps.w.org\/beardo-multisite-user-export\/assets\/screenshot-4.png?rev=3688923","caption":"Export History Log: the full audit trail, downloadable as CSV"}],"raw_content":"<!--section=description-->\n<p><strong>A user export tool built for multisite network admins.<\/strong><\/p>\n\n<p>Beardo Multisite User Export treats your network as a whole rather than as a set of separate sites. Pick a site and export its users, or pick roles and export every matching user across the entire network in a single file, with each person listed exactly once and every site they belong to in the same row.<\/p>\n\n<p>Everything runs inside your own WordPress installation. There is no account to create, no API key, and no third-party service. The plugin makes zero external requests, and the only thing that ever leaves your server is the file you download.<\/p>\n\n<h4>Export the network, or export one site<\/h4>\n\n<ul>\n<li><strong>Export by Role<\/strong> exports across the entire network. Choose one or more roles, see a live count of unique users for each, and download one deduplicated list with a Sites column showing everywhere each user belongs.<\/li>\n<li><strong>Export by Site<\/strong> exports a single subsite. Select the site and the plugin loads the roles that actually exist there, including custom roles that only that site's theme or plugins define, so you export precisely the users you meant to.<\/li>\n<\/ul>\n\n<h4>Filter to exactly the users you need<\/h4>\n\n<ul>\n<li>One or more roles, each with a user count<\/li>\n<li>Account status: active, spam, or deleted<\/li>\n<li>Registration date range<\/li>\n<li>Your choice of fields: user ID, username, email, first name, last name, role(s), registration date, sites, and status<\/li>\n<\/ul>\n\n<h4>Formats that open cleanly<\/h4>\n\n<ul>\n<li><strong>CSV<\/strong>, UTF-8 with BOM, so accented names and non-Latin scripts open correctly in Excel, Numbers, and Google Sheets<\/li>\n<li><strong>Excel<\/strong> (.xls, Excel 2003 XML Spreadsheet format), opens directly in Microsoft Excel and LibreOffice<\/li>\n<\/ul>\n\n<h4>Security built in, not bolted on<\/h4>\n\n<p>User exports are personal data. This plugin was written to keep them safe by default and hardened against the mistakes that have gotten other export plugins removed from the directory.<\/p>\n\n<ul>\n<li>Exports are available only to super admins, only over HTTPS, and only with a valid security nonce<\/li>\n<li>Every submitted value is validated server-side against an allowlist: roles, fields, format, site ID, and dates<\/li>\n<li>Every exported cell is protected against CSV formula injection, so a username like <code>=HYPERLINK(...)<\/code> opens as text, not as a live formula<\/li>\n<li>Role names coming from subsites are escaped before they reach the admin screen<\/li>\n<li>No external requests, ever. Nothing is uploaded, synced, or phoned home<\/li>\n<\/ul>\n\n<h4>Built for real networks<\/h4>\n\n<ul>\n<li>Users are queried in batches of 1,000, so large networks export without timeouts<\/li>\n<li>Role lists are gathered from every subsite, not just the main site<\/li>\n<li>Users who belong to several sites appear once, with all of their sites listed<\/li>\n<li>The admin screen follows your admin color scheme, including dark-mode themes<\/li>\n<\/ul>\n\n<h4>A complete audit trail<\/h4>\n\n<p>Every export is recorded: who ran it, which roles, which site, how many users, and in which format. The Export History tab shows the log, lets you download it as CSV, and prunes entries older than 90 days automatically. Developers can change the retention window through the <code>beardo_mue_history_retention_days<\/code> network option.<\/p>\n\n<h4>What it does not do (yet)<\/h4>\n\n<p>This is a focused export tool. It does not import users, and it exports the core user fields listed above rather than arbitrary user meta or WooCommerce data. If you need those, a general-purpose import\/export plugin is a better fit. If you run a network and need a clean, safe, network-aware export, this plugin is built for that.<\/p>\n\n<h4>Part of the Beardo.Tools family<\/h4>\n\n<p>Beardo Multisite User Export is one of a set of lightweight, security-first tools for WordPress multisite networks from Beardo.Tools. Each does one job well, follows WordPress coding standards, and ships with a full test suite.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>In <strong>Network Admin &gt; Plugins &gt; Add New<\/strong>, search for \"Beardo Multisite User Export\" and install it, or upload the <code>beardo-multisite-user-export<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li><strong>Network Activate<\/strong> the plugin.<\/li>\n<li>Go to <strong>Network Admin &gt; Users &gt; Export Users<\/strong>.<\/li>\n<\/ol>\n\n<p>Requirements: WordPress Multisite, HTTPS enabled on the network admin, and a super admin account.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20work%20on%20a%20single-site%20wordpress%20install%3F\"><h3>Does this work on a single-site WordPress install?<\/h3><\/dt>\n<dd><p>No. It is built specifically for multisite networks and requires multisite to be enabled. On a single site it shows an admin notice and does nothing else.<\/p><\/dd>\n<dt id=\"why%20is%20the%20export%20button%20disabled%3F\"><h3>Why is the Export button disabled?<\/h3><\/dt>\n<dd><p>Exports require HTTPS. Enable SSL\/TLS on your network and the button becomes available. This is deliberate: user data should never travel over an unencrypted connection.<\/p><\/dd>\n<dt id=\"who%20can%20export%20users%3F\"><h3>Who can export users?<\/h3><\/dt>\n<dd><p>Only super admins, meaning users with the <code>manage_network<\/code> capability. Administrators of individual subsites cannot see or use the export tool.<\/p><\/dd>\n<dt id=\"what%20happens%20with%20users%20who%20belong%20to%20several%20sites%3F\"><h3>What happens with users who belong to several sites?<\/h3><\/dt>\n<dd><p>In network-wide exports each user appears exactly once, with a Sites column listing every site they belong to. Site-specific exports list only that site's users.<\/p><\/dd>\n<dt id=\"a%20subsite%20uses%20custom%20roles.%20will%20they%20show%20up%3F\"><h3>A subsite uses custom roles. Will they show up?<\/h3><\/dt>\n<dd><p>Yes. Role lists are collected from every subsite in the network, so roles that a theme or plugin defines on one site only are included, with their correct labels.<\/p><\/dd>\n<dt id=\"can%20i%20export%20custom%20user%20meta%20or%20woocommerce%20customer%20data%3F\"><h3>Can I export custom user meta or WooCommerce customer data?<\/h3><\/dt>\n<dd><p>Not in this version. The export covers user ID, username, email, first name, last name, roles, registration date, sites, and account status.<\/p><\/dd>\n<dt id=\"can%20i%20import%20users%20with%20this%20plugin%3F\"><h3>Can I import users with this plugin?<\/h3><\/dt>\n<dd><p>No. It is export-only by design.<\/p><\/dd>\n<dt id=\"are%20exports%20logged%3F\"><h3>Are exports logged?<\/h3><\/dt>\n<dd><p>Yes. Every export is recorded in the Export History tab with the user who ran it, the roles, the site, the row count, and the format. Entries are kept for 90 days by default, and the log itself can be downloaded as CSV. Developers can change the retention window through the <code>beardo_mue_history_retention_days<\/code> network option.<\/p><\/dd>\n<dt id=\"does%20any%20user%20data%20leave%20my%20server%3F\"><h3>Does any user data leave my server?<\/h3><\/dt>\n<dd><p>No. The plugin makes no external requests of any kind. Exports are generated on your server and streamed straight to your browser as a download.<\/p><\/dd>\n<dt id=\"is%20the%20csv%20safe%20to%20open%20in%20excel%3F\"><h3>Is the CSV safe to open in Excel?<\/h3><\/dt>\n<dd><p>Yes. Every cell is checked for formula-injection characters (<code>=<\/code>, <code>+<\/code>, <code>-<\/code>, <code>@<\/code>, tab, and carriage return) and escaped so spreadsheet applications treat them as text rather than executable formulas.<\/p><\/dd>\n<dt id=\"which%20excel%20format%20is%20the%20.xls%20file%3F\"><h3>Which Excel format is the .xls file?<\/h3><\/dt>\n<dd><p>Excel 2003 XML Spreadsheet, which Excel and LibreOffice open directly. Excel may show a one-time notice that the file format and extension differ. Click Yes and the file opens normally. If you prefer a plain format, choose CSV.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20uninstall%20the%20plugin%3F\"><h3>What happens when I uninstall the plugin?<\/h3><\/dt>\n<dd><p>All plugin data is removed: its network options (retention setting, batch size, cache expiry, export history) and cached transients. Nothing is left behind. Files you already downloaded are of course unaffected.<\/p><\/dd>\n<dt id=\"what%20versions%20of%20wordpress%20and%20php%20are%20required%3F\"><h3>What versions of WordPress and PHP are required?<\/h3><\/dt>\n<dd><p>WordPress 5.8 or later and PHP 8.0 or later, with multisite enabled.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3<\/h4>\n\n<ul>\n<li>Rebrand: Plugin is now <strong>Beardo Multisite User Export<\/strong>, published by Beardo.Tools; the slug and text domain are now <code>beardo-multisite-user-export<\/code><\/li>\n<li>Rename: All classes, constants, options, transients, hooks, and asset handles now use the <code>Beardo_MUE<\/code> \/ <code>beardo_mue_<\/code> prefix, matching the Beardo plugin family<\/li>\n<li>Cleanup: Removed six obsolete <code>class_alias()<\/code> backwards-compatibility shims<\/li>\n<li>Fix: Corrected the minimum PHP version in composer.json to 8.0, matching the plugin header<\/li>\n<li>Note: Because the option keys changed, settings and export history from earlier versions are not carried over<\/li>\n<li>Fix: Export, history-export, and site-roles AJAX handlers were registered under the old <code>msue_<\/code> action names after the rename, so every request silently did nothing; all three now match the <code>beardo_mue_<\/code> actions the forms and script send, with a test that pins them together<\/li>\n<li>Improvement: All admin-script messages are now translatable via wp_localize_script instead of hardcoded English<\/li>\n<li>Improvement: Uninstall cleanup now also runs under WP-CLI, which has no logged-in user<\/li>\n<li>Cleanup: Removed unused sub-tab CSS and prefixed the required-field marker class<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Improvement: Admin screen now inherits colors from WordPress core and admin themes (dark-mode compatible) \u2014 removed hardcoded palette colors from plugin CSS<\/li>\n<li>Improvement: Export information box now renders as a native WordPress notice<\/li>\n<\/ul>\n\n<h4>1.2<\/h4>\n\n<ul>\n<li>Security: Escape role names\/keys\/counts at the HTML insertion point in admin JS (prevents stored XSS via subsite-defined role names)<\/li>\n<li>Security: Validate posted site IDs against existing network sites (AJAX and export paths)<\/li>\n<li>Security: Apply CSV formula-injection escaping to the history CSV export (matching the main export)<\/li>\n<li>Security: Unslash and strictly sanitize all request input; strict Y-m-d validation for date filters<\/li>\n<li>Compliance: Full WordPress Coding Standards alignment \u2014 naming, escaping, and i18n on all output; class files renamed to WPCS conventions with previous class names aliased for backwards compatibility<\/li>\n<li>Compliance: All user-facing strings internationalized with the beardo-multisite-user-export text domain<\/li>\n<li>Refactor: New Beardo_MUE_Security class centralizes capability\/nonce constants, CSV escaping, and site validation<\/li>\n<li>Performance: Site dropdown no longer switches blogs per site; network role counts cached for 5 minutes; per-site role counts use count_users()<\/li>\n<li>Cleanup: Removed dead transient references, a no-op JS branch, and inline styles (moved to CSS classes)<\/li>\n<li>Requires PHP 8.0<\/li>\n<\/ul>\n\n<h4>1.1<\/h4>\n\n<ul>\n<li>Maintenance: Updated plugin tooling baseline and test coverage pipeline<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Maintenance: Minor revision update<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Maintenance: Minor revision update<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fix: Plugin Check\/PHPCS escaping warnings in Excel export output<\/li>\n<li>Fix: Removed direct database query from uninstall routine<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>CSV and Excel export support<\/li>\n<li>Multi-role and multi-site filtering with per-role user counts<\/li>\n<li>User status filtering (active, spam, deleted)<\/li>\n<li>Registration date range filtering<\/li>\n<li>Export history tracking with configurable retention<\/li>\n<li>CSV formula-injection prevention and HTTPS enforcement<\/li>\n<li>Chunked query processing for large networks<\/li>\n<\/ul>","raw_excerpt":"Export users from your whole multisite network, or one site, by role, status, and date. CSV or Excel. Deduplicated, audited, HTTPS-only.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/365303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=365303"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/beardotools"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=365303"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=365303"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=365303"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=365303"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=365303"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=365303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}