
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Security & Risk Analysis
wordpress.org/plugins/duplicatorThe best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
Is Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Safe to Use in 2026?
Generally Safe
Score 87/100Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More has a strong security track record. Known vulnerabilities have been patched promptly.
Duplicator v1.5.15 presents a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and a significant number of nonce and capability checks, several areas raise concerns. The presence of dangerous functions like 'exec', 'popen', and 'shell_exec' inherently increases risk, especially when combined with unescaped output and potential for code injection or path traversal vulnerabilities, as hinted by the taint analysis. The plugin's history of 15 known CVEs, including critical and high-severity issues, is a significant red flag, indicating a recurring pattern of exploitable weaknesses. Even though there are currently no unpatched CVEs, the sheer volume and nature of past vulnerabilities suggest a need for continued vigilance and careful review of updates. The substantial number of AJAX handlers without authentication checks is also a notable attack vector that requires attention.
Key Concerns
- Dangerous functions (exec, popen, shell_exec) present
- Unsanitized paths in taint flows
- Large number of AJAX entry points without auth checks
- Significant vulnerability history (15 CVEs)
- High percentage of past critical/high severity CVEs
- Potentially unsafely handled file operations
- Only 50% of outputs properly escaped
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Security Vulnerabilities
CVEs by Year
Severity Breakdown
15 total CVEs
Duplicator <= 1.5.9 - Full Path Disclosure
Duplicator <= 1.5.7 - Cross-Site Request Forgery via views/tools/diagnostics/information.php
Duplicator < 1.3.0 - Unauthenticated Remote Code Execution
Duplicator <= 1.5.7 AND Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Information Exposure
Duplicator – WordPress Migration Plugin <= 1.4.7 - Sensitive Information Disclosure
Duplicator – WordPress Migration Plugin <= 1.4.7 - Unauthenticated Backup Download
Duplicator < 1.3.28 - Directory Traversal
Duplicator <= 1.2.41 - Sensitive Information Disclosure leading to Remote Code Execution
Duplicator <= 1.2.32 - Cross-Site Scripting
Duplicator <= 1.2.28 – Unauthenticated Stored Cross-Site Scripting
Duplicator < 1.1.4 - Cross-Site Request Forgery
Duplicator <= 0.5.26 - Authenticated (Admin+) Cross-Site Scripting
Duplicator <= 0.5.14 - SQL Injection
Duplicator < 0.5.10 - Arbitrary Backup Creation and Download
Duplicator – WordPress Migration Plugin <= 0.4.4 - Cross-Site Scripting
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Attack Surface
AJAX Handlers 17
WordPress Hooks 63
Maintenance & Trust
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Maintenance & Trust
Maintenance Signals
Community Trust
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Alternatives
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Backup, Restore and Migrate your sites with XCloner
xcloner-backup-and-restore
XCloner is a backup plugin that allows you to safely back up and restore your WordPress sites. You can send site backups to SFTP, Dropbox, Amazon, Goo …
Backuply – Backup, Restore, Migrate and Clone
backuply
Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …
BackWPup – WordPress Backup & Restore Plugin
backwpup
Create a complete WordPress backup easily. Schedule automatic backups, store securely, and restore effortlessly with the best WordPress backup plugin!
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
boldgrid-backup
Automated backups, remote backup to Amazon S3 and Google Drive, stop website crashes before they happen and more. Total Upkeep is the backup solution …
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More Developer Profile
94 plugins · 23.5M total installs
How We Detect Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duplicator/assets/css/modal.cssHTML / DOM Fingerprints
duplicator-modalduplicator-modal-deactivation-feedbackduplicator-modal-dialogduplicator-modal-bodyduplicator-modal-panelduplicator-modal-reasonduplicator-modal-internal-messagedata-input-typedata-input-placeholderDuplicatorPhpVersionCheck