
Bhairav Scheduled Cloud Backup Security & Risk Analysis
wordpress.org/plugins/bhairav-scheduled-cloud-backupAutomated cloud backups to multiple cloud storage providers. Schedule backups and auto-delete old backups.
Is Bhairav Scheduled Cloud Backup Safe to Use in 2026?
Generally Safe
Score 100/100Bhairav Scheduled Cloud Backup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bhairav-scheduled-cloud-backup" plugin v1.0.5 presents a mixed security posture. On the positive side, it demonstrates strong adherence to output escaping practices, with 99% of outputs being properly escaped, which significantly mitigates cross-site scripting (XSS) risks. The absence of critical or high severity taint flows is also a positive indicator, suggesting that unsanitized data is not being directly passed to sensitive operations. Furthermore, the plugin has no recorded historical vulnerabilities, which could imply robust development practices or simply a lack of past discovery.
However, a significant concern arises from the plugin's attack surface. All four identified AJAX handlers lack authentication checks, creating a direct and open pathway for unauthenticated attackers. This is a critical oversight, as any functionality exposed through these handlers could be exploited without requiring a user to be logged in. While SQL queries use prepared statements a reasonable percentage of the time (33%), the presence of raw SQL without preparation is a potential risk, especially if sensitive data is involved or if the input influencing these queries is not thoroughly validated. The substantial number of file operations and external HTTP requests also warrants attention, as these could become vectors for other vulnerabilities if not handled with extreme care, although no specific issues were flagged in the static analysis.
In conclusion, while the plugin excels in output sanitization and has a clean vulnerability history, the unprotected AJAX endpoints represent a serious and immediate security risk. The absence of authentication on these entry points overshadows the otherwise good practices observed in other areas. Addressing the unprotected AJAX handlers should be the highest priority.
Key Concerns
- AJAX handlers without auth checks
- SQL queries with prepared statements not used
Bhairav Scheduled Cloud Backup Security Vulnerabilities
Bhairav Scheduled Cloud Backup Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bhairav Scheduled Cloud Backup Attack Surface
AJAX Handlers 4
WordPress Hooks 16
Scheduled Events 2
Maintenance & Trust
Bhairav Scheduled Cloud Backup Maintenance & Trust
Maintenance Signals
Community Trust
Bhairav Scheduled Cloud Backup Alternatives
WP-Stateless – Google Cloud Storage
wp-stateless
Upload and serve your WordPress media files from Google Cloud Storage.
Automatic WordPress Backup
automatic-wordpress-backup
Automatically back up important bits of your WordPress install to Amazon S3.
CYAN Backup
cyan-backup
Backup your entire WordPress site and its database into a zip file on a schedule. Remote storage options include FTP, SFTP and FTPS.
DBC Backup 2
dbc-backup-2
DBC Backup 2 is a safe & simple way to schedule regular WordPress database backups using the wp-cron batch jobs.
WP-QINIU (WordPress连接到七牛云存储)
wp-qiniu
备份WordPress到七牛云存储,把七牛云存储作为网站附件存储空间。
Bhairav Scheduled Cloud Backup Developer Profile
6 plugins · 180 total installs
How We Detect Bhairav Scheduled Cloud Backup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bhairav-scheduled-cloud-backup/assets/css/admin.css/wp-content/plugins/bhairav-scheduled-cloud-backup/assets/js/admin.js/wp-content/plugins/bhairav-scheduled-cloud-backup/assets/js/admin.jsbhairav-scheduled-cloud-backup/assets/css/admin.css?ver=bhairav-scheduled-cloud-backup/assets/js/admin.js?ver=HTML / DOM Fingerprints
<!-- IMPORTANT: This plugin automatically excludes itself from backup operations --><!-- phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound --><!-- Silence is golden. -->data-plugin-version="1.0.5"data-nonce-valuewindow.NANDANNSCHBACKUP_AJAX_OBJECTNANDANNSCHBACKUP_AJAX_OBJECT/wp-json/scheduledcloudbackups/v1/status