
BackWPup – WordPress Backup & Restore Plugin Security & Risk Analysis
wordpress.org/plugins/backwpupCreate a complete WordPress backup easily. Schedule automatic backups, store securely, and restore effortlessly with the best WordPress backup plugin!
Is BackWPup – WordPress Backup & Restore Plugin Safe to Use in 2026?
Mostly Safe
Score 83/100BackWPup – WordPress Backup & Restore Plugin is generally safe to use. 10 past CVEs were resolved. Keep it updated.
BackWPup v5.6.6 presents a mixed security posture. While the plugin demonstrates good practices in areas like SQL prepared statements and output escaping, a significant concern arises from its attack surface. A considerable number of AJAX handlers lack proper authentication checks, creating potential entry points for unauthorized actions if exploited. The taint analysis, fortunately, did not reveal any critical or high severity unsanitized path flows, which is a positive sign. However, the plugin's vulnerability history is a major red flag. With 10 known CVEs, including one critical and five high-severity vulnerabilities, and common types like missing authorization, path traversal, and information exposure, it indicates a recurring pattern of security weaknesses. The presence of past critical and high-severity issues, despite the absence of currently unpatched vulnerabilities, suggests a need for heightened vigilance and potentially deeper code auditing. The last recorded vulnerability in 2026 also indicates a recent history of security issues, making proactive patching and hardening crucial.
Key Concerns
- Unprotected AJAX handlers
- High number of known CVEs
- Past critical severity CVEs
- Past high severity CVEs
- Bundled library (Guzzle)
BackWPup – WordPress Backup & Restore Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
BackWPup 5.0.0 - 5.6.2 - Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary Options Update
BackWPup 5 - 5.5.0 - Missing Authorization to Sensitive Information Exposure
BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal
BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Password
BackWPup <= 4.0.3 - Sensitive Information Exposure
BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal
BackWPup <= 3.4.1 - Unauthenticated Backup Download
BackWPup < 3.0.13 - Cross-Site Scripting
BackWPup <= 1.7.1 - Remote File Inclusion
BackWPup – WordPress Backup Plugin < 1.4.1 - Directory Traversal
BackWPup – WordPress Backup & Restore Plugin Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
BackWPup – WordPress Backup & Restore Plugin Attack Surface
AJAX Handlers 6
REST API Routes 4
WordPress Hooks 72
Scheduled Events 18
Maintenance & Trust
BackWPup – WordPress Backup & Restore Plugin Maintenance & Trust
Maintenance Signals
Community Trust
BackWPup – WordPress Backup & Restore Plugin Alternatives
Backuply – Backup, Restore, Migrate and Clone
backuply
Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
boldgrid-backup
Automated backups, remote backup to Amazon S3 and Google Drive, stop website crashes before they happen and more. Total Upkeep is the backup solution …
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
WP Database Backup – Unlimited Database & Files Backup by Backup for WP
wp-database-backup
Create & Restore Database Backup easily on single click. Manual or automated backups (backup to Dropbox, Google drive, Amazon s3,FTP,Email).
BackWPup – WordPress Backup & Restore Plugin Developer Profile
8 plugins · 2.0M total installs
How We Detect BackWPup – WordPress Backup & Restore Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/backwpup/assets/css/main.min.css/wp-content/plugins/backwpup/assets/js/backwpup-generate.js/wp-content/plugins/backwpup/assets/css/backwpup-admin.css/wp-content/plugins/backwpup/assets/js/backwpup-admin.js/wp-content/plugins/backwpup/assets/js/general.js/wp-content/plugins/backwpup/assets/js/vendor/clipboard.min.js/wp-content/plugins/backwpup/assets/js/backwpup-generate.js/wp-content/plugins/backwpup/assets/js/backwpup-admin.js/wp-content/plugins/backwpup/assets/js/general.js/wp-content/plugins/backwpup/assets/js/vendor/clipboard.min.jsbackwpup/assets/css/main.min.css?ver=backwpup/assets/js/backwpup-generate.js?ver=backwpup/assets/css/backwpup-admin.css?ver=backwpup/assets/js/backwpup-admin.js?ver=backwpup/assets/js/general.js?ver=backwpup/assets/js/vendor/clipboard.min.js?ver=HTML / DOM Fingerprints
backwpup_job_logbackwpup_job_run_info<!-- BackWPup Job --><!-- BackWPup Job Log --><!-- BackWPup Job Output --><!-- BackWPup Job Settings -->+1 moredata-backwpup-job-iddata-backwpup-job-statusbackwpupbackwpupApi/wp-json/backwpup/v1/jobs/wp-json/backwpup/v1/jobs/(?P<id>\d+)