
Really Simple Backup Security & Risk Analysis
wordpress.org/plugins/really-simple-backupA simple backup of your Theme, Uploads, Plugins and Database - proceed at your own risk...
Is Really Simple Backup Safe to Use in 2026?
Generally Safe
Score 85/100Really Simple Backup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "really-simple-backup" v1.3.5 plugin exhibits a mixed security posture. On the positive side, it has no known CVEs and a clean vulnerability history, indicating a commitment to security or a lack of prior exploitation. Furthermore, all SQL queries are properly prepared, and there are no external HTTP requests, which are excellent security practices. However, the static analysis reveals significant concerns. The presence of a 'system' function call is a critical red flag, especially when combined with a critical severity taint flow involving unsanitized paths. This suggests a potential for arbitrary code execution or command injection if an attacker can influence the path input to this function.
The limited attack surface with zero unprotected entry points is a strong positive. However, the 16 file operations, coupled with only 33% of outputs being properly escaped, raise concerns about potential directory traversal or information disclosure vulnerabilities. While nonce and capability checks are present, their limited count in relation to the file operations and the identified taint flow is insufficient to fully mitigate the risks associated with the 'system' function and unsanitized paths.
In conclusion, while the plugin benefits from a clean vulnerability record and good SQL practices, the identified critical taint flow and the use of the 'system' function alongside potentially unescaped file operations present a tangible risk. The limited number of security checks relative to the potential impact of these code signals warrants careful consideration.
Key Concerns
- Critical taint flow with unsanitized path
- Use of dangerous 'system' function
- Low output escaping percentage (33%)
- Multiple file operations
Really Simple Backup Security Vulnerabilities
Really Simple Backup Release Timeline
Really Simple Backup Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Really Simple Backup Attack Surface
WordPress Hooks 2
Maintenance & Trust
Really Simple Backup Maintenance & Trust
Maintenance Signals
Community Trust
Really Simple Backup Alternatives
No alternatives data available yet.
Really Simple Backup Developer Profile
3 plugins · 11K total installs
How We Detect Really Simple Backup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/really-simple-backup/backup/HTML / DOM Fingerprints
wrapid="database"name="database"id="uploadsall"name="uploadsall"name="uploads[]"id="uploads_.*"