
BackupSavvy Child wordpress plugin Security & Risk Analysis
wordpress.org/plugins/backupsavvychildThis program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Sof …
Is BackupSavvy Child wordpress plugin Safe to Use in 2026?
Generally Safe
Score 100/100BackupSavvy Child wordpress plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "backupsavvychild" v1.0.2 plugin exhibits several critical security weaknesses, primarily stemming from its unprotected entry points and the presence of dangerous functions. The plugin exposes four REST API routes that lack any permission callbacks, meaning any unauthenticated user can potentially interact with these endpoints. Furthermore, the analysis reveals the use of dangerous functions like `popen`, `shell_exec`, and `unserialize` which, when combined with unsanitized inputs (indicated by all five analyzed taint flows having unsanitized paths), present a significant risk for remote code execution and data manipulation. The substantial number of file operations without clear sanitization in the taint analysis is also a concern, potentially leading to arbitrary file read/write vulnerabilities.
While the plugin has no recorded vulnerability history, this is not an indicator of strong security given the identified code-level risks. The absence of vulnerability history could simply mean the plugin hasn't been thoroughly scrutinized or exploited yet. The lack of nonce checks and capability checks on its entry points further amplifies the risk. The plugin's overall security posture is poor, with a high attack surface that is largely unprotected and the presence of functions that are inherently risky when not handled with extreme caution and robust input validation. The reliance on the Guzzle library, while common, doesn't mitigate the core vulnerabilities.
Key Concerns
- REST API routes without permission callbacks
- All taint flows have unsanitized paths
- Use of dangerous function: popen
- Use of dangerous function: shell_exec
- Use of dangerous function: unserialize
- No nonce checks on entry points
- No capability checks on entry points
- Low output escaping percentage
- Bundled library: Guzzle
BackupSavvy Child wordpress plugin Security Vulnerabilities
BackupSavvy Child wordpress plugin Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
BackupSavvy Child wordpress plugin Attack Surface
REST API Routes 4
WordPress Hooks 4
Maintenance & Trust
BackupSavvy Child wordpress plugin Maintenance & Trust
Maintenance Signals
Community Trust
BackupSavvy Child wordpress plugin Alternatives
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
BackupSavvy Child wordpress plugin Developer Profile
4 plugins · 40 total installs
How We Detect BackupSavvy Child wordpress plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/backupsavvychild/css/admin.css/wp-content/plugins/backupsavvychild/js/admin.js/wp-content/plugins/backupsavvychild/js/main.js/wp-content/plugins/backupsavvychild/js/admin.js/wp-content/plugins/backupsavvychild/js/main.jsbackupsavvychild/css/admin.css?ver=backupsavvychild/js/admin.js?ver=backupsavvychild/js/main.js?ver=HTML / DOM Fingerprints
backupsavvy-child-settings-wrap<!-- BackupSavvy Child Plugin -->data-bsv-pluginbackupSavvyChild/wp-json/backupsavvyapi/addsite/wp-json/backupsavvyapi/backup/wp-json/backupsavvyapi/upload/wp-json/backupsavvyapi/settings