
JetBackup – Backup, Restore & Migrate Security & Risk Analysis
wordpress.org/plugins/backupBackup, restore, and migrate WordPress sites fast. Supports TAR, remote backups, multi schedules, and full multisite compatibility.
Is JetBackup – Backup, Restore & Migrate Safe to Use in 2026?
Generally Safe
Score 95/100JetBackup – Backup, Restore & Migrate has a strong security track record. Known vulnerabilities have been patched promptly.
This plugin exhibits a mixed security posture, with several positive indicators but also significant areas of concern. The code analysis reveals a substantial attack surface with two AJAX handlers, both lacking authentication checks. This is a critical weakness, as it allows any unauthenticated user to potentially trigger these handlers, leading to unauthorized actions. While the plugin demonstrates good practices in other areas, such as a high percentage of prepared statements for SQL queries and properly escaped output, the unprotected entry points are a glaring vulnerability. The taint analysis shows no critical or high severity flows with unsanitized paths, which is a positive sign. However, the presence of dangerous functions like `unserialize`, `exec`, and `shell_exec`, even if not currently exploited in taint flows, indicates potential for future severe vulnerabilities if input is not meticulously handled. The plugin's vulnerability history is concerning, with a total of 9 known CVEs, including a past critical vulnerability. The common types of vulnerabilities like XSS, unrestricted uploads, exposure of sensitive information, and missing authorization highlight a recurring pattern of security flaws. While there are currently no unpatched CVEs, the history suggests a tendency to develop vulnerabilities that require patches.
Key Concerns
- Unprotected AJAX handlers
- Use of dangerous functions (unserialize, exec, shell_exec)
- History of 9 known CVEs
- Past critical CVE
- History of high severity CVEs
- History of medium severity CVEs
- Missing authorization vulnerability history
- Cross-Site Request Forgery vulnerability history
- Unrestricted upload vulnerability history
- Exposure of sensitive information vulnerability history
- Cross-site Scripting vulnerability history
JetBackup – Backup, Restore & Migrate Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
JetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory Listing
Backup Guard <= 1.6.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Backup Guard <= 1.5.9 - Authenticated Arbitrary File Upload
JetBackup – WP Backup, Migrate & Restore <= 1.4.0 - Sensitive Information Disclosure
JetBackup – WP Backup, Migrate & Restore <= 1.4.1 - Missing Authorization to Unauthorized Backup Location Change
JetBackup – WP Backup, Migrate & Restore <= 1.3.9 - Cross-Site Request Forgery to Arbitrary File Upload
BackupGuard <= 1.1.46 - Reflected Cross-Site Scripting
Backup Guard <= 1.1.46 - Cross-Site Scripting
WordPress Backup and Migrate Plugin – Backup Guard < 1.0.3 - Arbitrary File Upload
JetBackup – Backup, Restore & Migrate Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
JetBackup – Backup, Restore & Migrate Attack Surface
AJAX Handlers 2
WordPress Hooks 18
Maintenance & Trust
JetBackup – Backup, Restore & Migrate Maintenance & Trust
Maintenance Signals
Community Trust
JetBackup – Backup, Restore & Migrate Alternatives
Backuply – Backup, Restore, Migrate and Clone
backuply
Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …
BackWPup – WordPress Backup & Restore Plugin
backwpup
Create a complete WordPress backup easily. Schedule automatic backups, store securely, and restore effortlessly with the best WordPress backup plugin!
WP STAGING – WordPress Backup, Restore & Migration
wp-staging
Backup, restore, staging, and migration for WordPress. Create full-site backups and test updates safely.
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
boldgrid-backup
Automated backups, remote backup to Amazon S3 and Google Drive, stop website crashes before they happen and more. Total Upkeep is the backup solution …
WP Umbrella: Update Backup Restore & Monitoring
wp-health
Everything you need to sell WordPress maintenance and manage multiple sites effortlessly: backup, update, uptime monitoring, and security.
JetBackup – Backup, Restore & Migrate Developer Profile
1 plugin · 100K total installs
How We Detect JetBackup – Backup, Restore & Migrate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/backup/public/libraries/main.js/wp-content/plugins/backup/public/images/eddie-menu.svg/wp-content/plugins/backup/public/css/common.css/wp-content/plugins/backup/public/css/checkbox.min.css/wp-content/plugins/backup/public/libraries/angular-loading-bar/loading-bar.css/wp-content/plugins/backup/public/libraries/angular-moment-picker/angular-moment-picker.min.css/wp-content/plugins/backup/public/libraries/bootstrap/css/bootstrap.min.css/wp-content/plugins/backup/public/libraries/fontawesome/css/all.min.css+2 more/wp-content/plugins/backup/public/libraries/main.jsHTML / DOM Fingerprints
update-pluginsplugin-countdata-jetbackup-url