Auto-Backup & One-Click Restore Security & Risk Analysis

wordpress.org/plugins/auto-backup-one-click-restore

Complete WordPress backup and restore solution with real-time progress tracking, AJAX interface, and email notifications.

10 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Oct 8, 2025
automaticbackupdatabaserestoresecurity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto-Backup & One-Click Restore Safe to Use in 2026?

Generally Safe

Score 100/100

Auto-Backup & One-Click Restore has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The auto-backup-one-click-restore plugin version 1.0.0 exhibits a generally good security posture with several strengths. The code demonstrates a strong adherence to secure coding practices, with a high percentage of properly escaped outputs and a significant majority of SQL queries utilizing prepared statements. The absence of known CVEs and a clean vulnerability history are also positive indicators, suggesting a well-maintained and secure codebase.

However, a notable concern arises from the presence of an unprotected AJAX handler. This creates a direct entry point for potential attackers to interact with the plugin's functionality without proper authentication, which could lead to unauthorized actions or data manipulation depending on what that handler performs. While taint analysis shows no immediate critical or high-severity issues related to unsanitized paths, the presence of unprotected AJAX is a significant risk that needs immediate attention. The plugin also has a moderate number of file operations, and while no specific risks are highlighted, this area can sometimes be a source of vulnerabilities if not handled carefully.

In conclusion, the plugin is built on a foundation of good security practices. The lack of historical vulnerabilities is reassuring. However, the single unprotected AJAX handler represents a critical weakness that substantially elevates the overall risk. Addressing this specific vulnerability is paramount to improving the plugin's security.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Auto-Backup & One-Click Restore Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Auto-Backup & One-Click Restore Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
6 prepared
Unescaped Output
5
117 escaped
Nonce Checks
12
Capability Checks
8
File Operations
19
External Requests
0
Bundled Libraries
0

SQL Query Safety

75% prepared8 total queries

Output Escaping

96% escaped122 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<backup-page> (admin\backup-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Auto-Backup & One-Click Restore Attack Surface

Entry Points8
Unprotected1

AJAX Handlers 8

authwp_ajax_abocr_create_backupauto-backup-one-click-restore.php:72
authwp_ajax_abocr_backup_progressauto-backup-one-click-restore.php:73
authwp_ajax_abocr_clear_backup_progressauto-backup-one-click-restore.php:74
authwp_ajax_abocr_restore_backupauto-backup-one-click-restore.php:75
authwp_ajax_abocr_restore_progressauto-backup-one-click-restore.php:76
authwp_ajax_abocr_refresh_dataauto-backup-one-click-restore.php:77
authwp_ajax_abocr_delete_backupauto-backup-one-click-restore.php:78
authwp_ajax_abocr_test_emailauto-backup-one-click-restore.php:79
WordPress Hooks 10
actionadmin_noticesauto-backup-one-click-restore.php:56
actioninitauto-backup-one-click-restore.php:66
actionadmin_menuauto-backup-one-click-restore.php:67
actionadmin_enqueue_scriptsauto-backup-one-click-restore.php:68
actionadmin_initauto-backup-one-click-restore.php:69
actionabocr_daily_backupauto-backup-one-click-restore.php:82
actionabocr_weekly_backupauto-backup-one-click-restore.php:83
actionabocr_monthly_backupauto-backup-one-click-restore.php:84
actionabocr_clear_backup_progressauto-backup-one-click-restore.php:85
actionadmin_initincludes\class-settings.php:11

Scheduled Events 2

abocr_clear_backup_progress
abocr_clear_backup_progress
Maintenance & Trust

Auto-Backup & One-Click Restore Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 8, 2025
PHP min version7.4
Downloads242

Community Trust

Rating100/100
Number of ratings7
Active installs10
Developer Profile

Auto-Backup & One-Click Restore Developer Profile

Dcastalia LTD

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto-Backup & One-Click Restore

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-backup-one-click-restore/assets/css/admin.css/wp-content/plugins/auto-backup-one-click-restore/assets/js/admin.js
Script Paths
/wp-content/plugins/auto-backup-one-click-restore/assets/js/admin.js
Version Parameters
auto-backup-one-click-restore/assets/css/admin.css?ver=auto-backup-one-click-restore/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
abocr-backup-pageabocr-backup-containerabocr-settings-pageabocr-restore-pageabocr-progress-barabocr-backup-listabocr-backup-itemabocr-backup-actions+4 more
Data Attributes
data-backup-iddata-backup-filenamedata-action-url
JS Globals
abocr_ajax_objectabocr_vars
REST Endpoints
/wp-json/abocr/v1/backup/wp-json/abocr/v1/restore/wp-json/abocr/v1/progress
FAQ

Frequently Asked Questions about Auto-Backup & One-Click Restore