
BackUpWordPress Security & Risk Analysis
wordpress.org/plugins/backupwordpressSimple automated backups of your WordPress-powered website.
Is BackUpWordPress Safe to Use in 2026?
Mostly Safe
Score 83/100BackUpWordPress is generally safe to use though it hasn't been updated recently. 3 past CVEs were resolved.
The "backupwordpress" plugin v3.14 exhibits a mixed security posture. While it demonstrates good practices in areas like prepared SQL statements and output escaping, significant concerns arise from its attack surface and vulnerability history. The static analysis reveals a large number of unprotected AJAX handlers, representing a direct entry point for potential attackers. This is further exacerbated by two identified taint flows with unsanitized paths, indicating a risk of path traversal or unintended file access, though thankfully no critical severity taint flows were found.
The plugin's historical vulnerability data is a major red flag, with three known CVEs, including a past critical vulnerability related to path traversal and remote file inclusion. The presence of these historical issues, even if currently patched, suggests recurring weaknesses in handling file operations and authorization. The lack of currently unpatched vulnerabilities is positive, but the historical pattern necessitates caution and robust monitoring.
In conclusion, "backupwordpress" v3.14 has areas of strength in its coding practices, but its large unprotected attack surface and a history of severe vulnerabilities are significant risks. The identified taint flows warrant immediate attention. While current vulnerabilities are patched, the plugin's past suggests a potential for future security flaws if these underlying architectural weaknesses are not addressed.
Key Concerns
- 10 unprotected AJAX handlers
- 2 unsanitized path taint flows
- 3 known CVEs in history
- 1 past critical CVE
- 1 past low CVE
- 1 past medium CVE
- 1 cron event without clear auth context
BackUpWordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
BackUpWordPress <= 3.13 - Authenticated (Admin+) Directory Traversal
BackupWordPress <= 3.12 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure
BackUpWordPress <= 0.4.2b - Remote File Inclusion
BackUpWordPress Release Timeline
BackUpWordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BackUpWordPress Attack Surface
AJAX Handlers 10
WordPress Hooks 38
Scheduled Events 1
Maintenance & Trust
BackUpWordPress Maintenance & Trust
Maintenance Signals
Community Trust
BackUpWordPress Alternatives
WP BackItUp Community Edition
wp-backitup
Backup, restore, clone, duplicate or migrate your site effortlessly with the WPBackItUp backup plugin. Backup every setting, post, comment, revision, …
Backup Bolt
backup-bolt
Super simple one click backup your site and download the backup in compressed zip format. Choose between custom or full WordPress backup.
Automatic WordPress Backup
automatic-wordpress-backup
Automatically back up important bits of your WordPress install to Amazon S3.
Bamboo Migration
bamboo-migration
Easily migrate your Wordpress database from one web address to another.
WP Essentials
wp-essentials
All-in-one bundle of essential plugins and functions for all WordPress websites.
BackUpWordPress Developer Profile
1 plugin · 90K total installs
How We Detect BackUpWordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/backupwordpress/css/plugin.css/wp-content/plugins/backupwordpress/css/select2.css/wp-content/plugins/backupwordpress/js/plugin.js/wp-content/plugins/backupwordpress/js/select2.js/wp-content/plugins/backupwordpress/js/plugin.js/wp-content/plugins/backupwordpress/js/select2.jsbackupwordpress/css/plugin.css?ver=backupwordpress/css/select2.css?ver=backupwordpress/js/plugin.js?ver=backupwordpress/js/select2.js?ver=HTML / DOM Fingerprints
hmbkp-pagehmbkp-optionshmbkp-settingshmbkp_page_backupwordpressdata-hmbkp-typedata-hmbkp-idhmbkp_backup_wordpress_optionshmbkp_l10n/wp-json/backupwordpress/v1