The Hack Repair Guy's Plugin Archiver Security & Risk Analysis

wordpress.org/plugins/hackrepair-plugin-archiver

Disable Plugins Without Deleting — Archive and Restore in One Click

300 active installs v3.1.1 PHP 7.4+ WP 6.6+ Updated Sep 11, 2025
adminbackupdatabaseperformancesecurity
97
A · Safe
CVEs total2
Unpatched0
Last CVESep 16, 2025
Safety Verdict

Is The Hack Repair Guy's Plugin Archiver Safe to Use in 2026?

Generally Safe

Score 97/100

The Hack Repair Guy's Plugin Archiver has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Sep 16, 2025Updated 8mo ago
Risk Assessment

The "hackrepair-plugin-archiver" v3.1.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a strong reliance on prepared statements for SQL queries, a good number of capability checks, and the presence of nonce checks. There's also a high percentage of properly escaped output, mitigating common XSS vulnerabilities. Furthermore, the absence of a significant attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events is a positive indicator.

However, the plugin's vulnerability history raises significant concerns. It has a history of two known CVEs, including a high and a medium severity vulnerability. The common vulnerability types, Cross-Site Request Forgery (CSRF) and Path Traversal, are particularly worrying as they can lead to unauthorized actions or file system compromise. The taint analysis, while not flagging critical or high severity flows, did identify two flows with unsanitized paths, which could be a precursor to path traversal issues if not handled carefully. The file operations count is also worth noting.

In conclusion, while the plugin demonstrates good practices in its core code structure regarding SQL and output sanitization, its past security incidents, particularly concerning CSRF and Path Traversal, coupled with the presence of unsanitized paths in taint flows, suggest a need for continued vigilance. The fact that there are no currently unpatched vulnerabilities is a positive sign, but the historical pattern warrants careful consideration and ongoing monitoring.

Key Concerns

  • Past high severity vulnerability
  • Past medium severity vulnerability
  • Taint flows with unsanitized paths
  • High percentage of unescaped output
  • History of Path Traversal vulnerabilities
  • History of CSRF vulnerabilities
Vulnerabilities
2 published

The Hack Repair Guy's Plugin Archiver Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-10188medium · 5.4Cross-Site Request Forgery (CSRF)

The Hack Repair Guy's Plugin Archiver <= 2.0.4 - Cross-Site Request Forgery to Arbitrary Directory Deletion in /wp-content

Sep 16, 2025 Patched in 3.1.1 (1d)
CVE-2025-10176high · 7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The Hack Repair Guy's Plugin Archiver <= 2.0.4 - Authenticated (Administrator+) Arbitrary File Deletion

Sep 12, 2025 Patched in 3.1.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

The Hack Repair Guy's Plugin Archiver Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
75 escaped
Nonce Checks
2
Capability Checks
21
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped105 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
admin_notice (hackrepair-plugin-archiver.php:469)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

The Hack Repair Guy's Plugin Archiver Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninithackrepair-plugin-archiver.php:19
actionadmin_menuhackrepair-plugin-archiver.php:37
filterplugin_action_linkshackrepair-plugin-archiver.php:51
actionadmin_menuhackrepair-plugin-archiver.php:54
filtercustom_menu_orderhackrepair-plugin-archiver.php:55
actionload-plugins_page_hackrepair-plugin-archiverhackrepair-plugin-archiver.php:56
actionadmin_noticeshackrepair-plugin-archiver.php:57
filterviews_pluginshackrepair-plugin-archiver.php:58
actionadmin_enqueue_scriptshackrepair-plugin-archiver.php:110
filterhackrepair_plugin_archiver_pointershackrepair-plugin-archiver.php:111
actionadmin_footer-plugins.phpincludes\bulk.php:37
actionload-plugins.phpincludes\bulk.php:38
actionadmin_noticesincludes\bulk.php:39
actionadmin_print_footer_scriptsincludes\pointers.php:38
Maintenance & Trust

The Hack Repair Guy's Plugin Archiver Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 11, 2025
PHP min version7.4
Downloads9K

Community Trust

Rating100/100
Number of ratings11
Active installs300
Developer Profile

The Hack Repair Guy's Plugin Archiver Developer Profile

The Hack Repair Guy

2 plugins · 400 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect The Hack Repair Guy's Plugin Archiver

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hackrepair-plugin-archiver/js/archive.js/wp-content/plugins/hackrepair-plugin-archiver/js/pointers.js/wp-content/plugins/hackrepair-plugin-archiver/css/style.css
Script Paths
/wp-content/plugins/hackrepair-plugin-archiver/js/archive.js/wp-content/plugins/hackrepair-plugin-archiver/js/pointers.js
Version Parameters
hackrepair-plugin-archiver/js/archive.js?ver=hackrepair-plugin-archiver/js/pointers.js?ver=hackrepair-plugin-archiver/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
plugin-archiver-wrapplugin-archive-restoreplugin-archive-delete
HTML Comments
<!-- Plugin Archiver --><!-- Archived Plugins --><!-- Hack Repair Guy's Plugin Archiver -->
Data Attributes
data-plugin-archive-slugdata-plugin-archive-actiondata-plugin-archive-nonce
JS Globals
hackrepair_plugin_archiver_ajax_object
FAQ

Frequently Asked Questions about The Hack Repair Guy's Plugin Archiver