
Automatic WordPress Backup Security & Risk Analysis
wordpress.org/plugins/automatic-wordpress-backupAutomatically back up important bits of your WordPress install to Amazon S3.
Is Automatic WordPress Backup Safe to Use in 2026?
Generally Safe
Score 85/100Automatic WordPress Backup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "automatic-wordpress-backup" v2.0.3 plugin exhibits a concerning security posture primarily due to a lack of robust authentication and output escaping mechanisms. While the plugin has no recorded vulnerability history, this is overshadowed by significant risks identified in static and taint analysis. The presence of an unprotected AJAX handler, coupled with the use of dangerous functions like `shell_exec` and `unserialize`, alongside a complete absence of output escaping, creates a fertile ground for potential attacks. The lack of capability checks is also a major red flag, implying that sensitive operations might be accessible to unauthorized users. Although the absence of critical taint flows and known CVEs are positive indicators, they do not mitigate the immediate risks posed by the exposed attack surface and insecure coding practices.
Key Concerns
- Unprotected AJAX handler
- Dangerous functions used (shell_exec, exec, unserialize)
- No output escaping
- No capability checks
- SQL queries with low prepared statement usage
- Flows with unsanitized paths
Automatic WordPress Backup Security Vulnerabilities
Automatic WordPress Backup Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Automatic WordPress Backup Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Scheduled Events 2
Maintenance & Trust
Automatic WordPress Backup Maintenance & Trust
Maintenance Signals
Community Trust
Automatic WordPress Backup Alternatives
Automatic WordPress Backup Developer Profile
7 plugins · 640 total installs
How We Detect Automatic WordPress Backup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/automatic-wordpress-backup/wdc/wdc.js/wp-content/plugins/automatic-wordpress-backup/wdc/wdc.cssautomatic-wordpress-backup/wdc/wdc.js?ver=automatic-wordpress-backup/wdc/wdc.css?ver=HTML / DOM Fingerprints
awb-warningcmAWB