SafeSnap – Effortless WordPress Backups Security & Risk Analysis

wordpress.org/plugins/safesnap

Effortless WordPress backups with automatic daily backups, one-click restore, and 7-day retention. Both database AND files backed up!

0 active installs v2.0.2 PHP 7.4+ WP 5.6+ Updated Feb 7, 2026
backupclouddatabaserestoresecurity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SafeSnap – Effortless WordPress Backups Safe to Use in 2026?

Generally Safe

Score 100/100

SafeSnap – Effortless WordPress Backups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The safesnap v2.0.2 plugin exhibits a generally strong security posture based on the static analysis. It has a total of 5 AJAX entry points, but importantly, all of them appear to have authentication checks. Furthermore, the plugin demonstrates good practices by implementing nonce checks on all identified entry points and utilizing capability checks for authorization. The SQL query usage is also encouraging, with a high percentage (75%) employing prepared statements, reducing the risk of SQL injection vulnerabilities. There are no known historical vulnerabilities or CVEs associated with this plugin, which suggests a history of responsible development and maintenance.

However, a significant concern arises from the taint analysis, which revealed two flows with unsanitized paths. While no critical or high severity issues were flagged in the taint analysis, unsanitized paths represent a potential entry point for attackers to manipulate file operations or other sensitive processes. Additionally, the output escaping is only at 56%, meaning over half of the plugin's outputs are not properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of file operations without further context on their sanitization or purpose also warrants caution. Despite these weaknesses, the overall security is bolstered by the lack of known vulnerabilities and the robust handling of entry points.

In conclusion, safesnap v2.0.2 has several strengths, particularly in its handling of AJAX entry points and the general adoption of security best practices like nonce and capability checks. The absence of historical vulnerabilities is a positive indicator. However, the presence of unsanitized paths in the taint analysis and the suboptimal output escaping require attention. These areas represent the most immediate risks that could be exploited if not addressed.

Key Concerns

  • Unsanitized paths in taint analysis
  • Low output escaping rate (56%)
Vulnerabilities
None known

SafeSnap – Effortless WordPress Backups Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SafeSnap – Effortless WordPress Backups Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
6 prepared
Unescaped Output
12
15 escaped
Nonce Checks
5
Capability Checks
4
File Operations
8
External Requests
0
Bundled Libraries
0

SQL Query Safety

75% prepared8 total queries

Output Escaping

56% escaped27 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ajax_restore_backup (safesnap.php:606)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SafeSnap – Effortless WordPress Backups Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_safesnap_manual_backupsafesnap.php:38
authwp_ajax_safesnap_restore_backupsafesnap.php:39
authwp_ajax_safesnap_restore_latestsafesnap.php:40
authwp_ajax_safesnap_delete_backupsafesnap.php:41
authwp_ajax_safesnap_dismiss_reviewsafesnap.php:42
WordPress Hooks 7
actioninitsafesnap.php:31
filtercron_schedulessafesnap.php:32
actionadmin_menusafesnap.php:33
actionadmin_enqueue_scriptssafesnap.php:34
actionadmin_noticessafesnap.php:35
actionsafesnap_daily_backupsafesnap.php:45
actionsafesnap_monitor_changessafesnap.php:46

Scheduled Events 2

safesnap_daily_backup
safesnap_monitor_changes
Maintenance & Trust

SafeSnap – Effortless WordPress Backups Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 7, 2026
PHP min version7.4
Downloads360

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SafeSnap – Effortless WordPress Backups Developer Profile

PluginJoy

5 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SafeSnap – Effortless WordPress Backups

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/safesnap/assets/admin.css/wp-content/plugins/safesnap/assets/admin.js
Script Paths
/wp-content/plugins/safesnap/assets/admin.js
Version Parameters
safesnap/assets/admin.css?ver=safesnap/assets/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
safesnap-adminsafesnap-headersafesnap-header-contentsafesnap-taglinesafesnap-version-badgesafesnap-containersafesnap-statssafesnap-stat+20 more
HTML Comments
<!-- Header --><!-- Stats Cards --><!-- Manual Backup --><!-- Restore Options -->+1 more
Data Attributes
safesnap-manual-backup-btnsafesnap-restore-btnsafesnap-delete-backup-btnsafesnap-backup-download-btnsafesnap-backup-restore-btnsafesnap-backup-delete-btn+1 more
JS Globals
safesnapAjax
REST Endpoints
/wp-json/safesnap/v1/backups/wp-json/safesnap/v1/settings/wp-json/safesnap/v1/restore/wp-json/safesnap/v1/backup/wp-json/safesnap/v1/delete
FAQ

Frequently Asked Questions about SafeSnap – Effortless WordPress Backups