
The Hack Repair Guy's Plugin Archiver Security & Risk Analysis
wordpress.org/plugins/hackrepair-plugin-archiverDisable Plugins Without Deleting — Archive and Restore in One Click
Is The Hack Repair Guy's Plugin Archiver Safe to Use in 2026?
Generally Safe
Score 97/100The Hack Repair Guy's Plugin Archiver has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "hackrepair-plugin-archiver" v3.1.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a strong reliance on prepared statements for SQL queries, a good number of capability checks, and the presence of nonce checks. There's also a high percentage of properly escaped output, mitigating common XSS vulnerabilities. Furthermore, the absence of a significant attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events is a positive indicator.
However, the plugin's vulnerability history raises significant concerns. It has a history of two known CVEs, including a high and a medium severity vulnerability. The common vulnerability types, Cross-Site Request Forgery (CSRF) and Path Traversal, are particularly worrying as they can lead to unauthorized actions or file system compromise. The taint analysis, while not flagging critical or high severity flows, did identify two flows with unsanitized paths, which could be a precursor to path traversal issues if not handled carefully. The file operations count is also worth noting.
In conclusion, while the plugin demonstrates good practices in its core code structure regarding SQL and output sanitization, its past security incidents, particularly concerning CSRF and Path Traversal, coupled with the presence of unsanitized paths in taint flows, suggest a need for continued vigilance. The fact that there are no currently unpatched vulnerabilities is a positive sign, but the historical pattern warrants careful consideration and ongoing monitoring.
Key Concerns
- Past high severity vulnerability
- Past medium severity vulnerability
- Taint flows with unsanitized paths
- High percentage of unescaped output
- History of Path Traversal vulnerabilities
- History of CSRF vulnerabilities
The Hack Repair Guy's Plugin Archiver Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
The Hack Repair Guy's Plugin Archiver <= 2.0.4 - Cross-Site Request Forgery to Arbitrary Directory Deletion in /wp-content
The Hack Repair Guy's Plugin Archiver <= 2.0.4 - Authenticated (Administrator+) Arbitrary File Deletion
The Hack Repair Guy's Plugin Archiver Release Timeline
The Hack Repair Guy's Plugin Archiver Code Analysis
Output Escaping
Data Flow Analysis
The Hack Repair Guy's Plugin Archiver Attack Surface
WordPress Hooks 14
Maintenance & Trust
The Hack Repair Guy's Plugin Archiver Maintenance & Trust
Maintenance Signals
Community Trust
The Hack Repair Guy's Plugin Archiver Alternatives
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
InfiniteWP Client
iwp-client
Install this plugin on unlimited sites and manage them all from a central dashboard. This plugin communicates with your InfiniteWP Admin Panel.
Keep Backup Daily
keep-backup-daily
Keep Backup Daily backup your wordpress database and email to you daily, weekly, monthly and even yearly according to the settings.
Better By Default
better-by-default
Boost your WordPress site with the Better By Default Plugin for simplicity, security, and performance, ensuring a clean and efficient experience.
The Hack Repair Guy's Plugin Archiver Developer Profile
2 plugins · 400 total installs
How We Detect The Hack Repair Guy's Plugin Archiver
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hackrepair-plugin-archiver/js/archive.js/wp-content/plugins/hackrepair-plugin-archiver/js/pointers.js/wp-content/plugins/hackrepair-plugin-archiver/css/style.css/wp-content/plugins/hackrepair-plugin-archiver/js/archive.js/wp-content/plugins/hackrepair-plugin-archiver/js/pointers.jshackrepair-plugin-archiver/js/archive.js?ver=hackrepair-plugin-archiver/js/pointers.js?ver=hackrepair-plugin-archiver/css/style.css?ver=HTML / DOM Fingerprints
plugin-archiver-wrapplugin-archive-restoreplugin-archive-delete<!-- Plugin Archiver --><!-- Archived Plugins --><!-- Hack Repair Guy's Plugin Archiver -->data-plugin-archive-slugdata-plugin-archive-actiondata-plugin-archive-noncehackrepair_plugin_archiver_ajax_object