
Backuply – Backup, Restore, Migrate and Clone Security & Risk Analysis
wordpress.org/plugins/backuplyBackup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …
Is Backuply – Backup, Restore, Migrate and Clone Safe to Use in 2026?
Generally Safe
Score 90/100Backuply – Backup, Restore, Migrate and Clone has a strong security track record. Known vulnerabilities have been patched promptly.
The Backuply plugin exhibits a mixed security posture. While it demonstrates good practices in using prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. A large number of unprotected AJAX handlers (24 out of 34) present a substantial entry point for attackers to potentially exploit vulnerabilities. The presence of the `unserialize` function, especially in conjunction with unsanitized paths identified in the taint analysis, raises red flags for potential remote code execution or arbitrary file read/write vulnerabilities. The plugin's historical vulnerability record, with 5 known CVEs including a critical and a high-severity issue, further exacerbates these concerns. The fact that the last vulnerability was in 2025-09-25, and there are currently no unpatched vulnerabilities, suggests a potential for past issues being fixed but also highlights the plugin's track record. Overall, the plugin's large attack surface and historical issues warrant careful consideration, despite some positive coding practices.
Key Concerns
- Large number of unprotected AJAX handlers
- Use of unserialize function
- Taint flows with unsanitized paths
- History of 5 known CVEs
- History of 1 critical CVE
- History of 1 high CVE
Backuply – Backup, Restore, Migrate and Clone Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Backuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File Deletion
Backuply – Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injection
Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Directory Traversal
Backuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service
Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrator+) Directory Traversal
Backuply – Backup, Restore, Migrate and Clone Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Backuply – Backup, Restore, Migrate and Clone Attack Surface
AJAX Handlers 34
WordPress Hooks 21
Scheduled Events 7
Maintenance & Trust
Backuply – Backup, Restore, Migrate and Clone Maintenance & Trust
Maintenance Signals
Community Trust
Backuply – Backup, Restore, Migrate and Clone Alternatives
BackWPup – WordPress Backup & Restore Plugin
backwpup
Create a complete WordPress backup easily. Schedule automatic backups, store securely, and restore effortlessly with the best WordPress backup plugin!
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
boldgrid-backup
Automated backups, remote backup to Amazon S3 and Google Drive, stop website crashes before they happen and more. Total Upkeep is the backup solution …
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
WP Database Backup – Unlimited Database & Files Backup by Backup for WP
wp-database-backup
Create & Restore Database Backup easily on single click. Manual or automated backups (backup to Dropbox, Google drive, Amazon s3,FTP,Email).
Backuply – Backup, Restore, Migrate and Clone Developer Profile
10 plugins · 4.1M total installs
How We Detect Backuply – Backup, Restore, Migrate and Clone
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/backuply/core/assets/js/backuply.js/wp-content/plugins/backuply/core/assets/css/backuply.css/wp-content/plugins/backuply/core/assets/css/backuply-custom.css/wp-content/plugins/backuply/core/assets/js/backuply.jsbackuply/core/assets/css/backuply.css?ver=backuply/core/assets/js/backuply.js?ver=HTML / DOM Fingerprints
backuply-settings-mainbackuply-backup-btnbackuply-log-wrapperbackuply-modal-content<!-- Backuply Admin Init --><!-- Trial Promo --><!-- Trial Promo Ends here --><!-- Last Backup Notice Start -->+15 moredata-backuply-modal-iddata-backuply-close-modalbackuply_optionsbackuply_ajax_url