
Tiny Backup Security & Risk Analysis
wordpress.org/plugins/tiny-backupSimple and minimal backup plugin for WordPress. Create database and files backups with one click.
Is Tiny Backup Safe to Use in 2026?
Generally Safe
Score 100/100Tiny Backup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tiny-backup plugin v1.1.1 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices in output escaping, with 99% of outputs properly escaped, and has no recorded history of vulnerabilities (CVEs). Furthermore, the code analysis shows no critical or high severity taint flows and a low percentage of SQL queries not using prepared statements, suggesting robust handling of data manipulation and preventing common injection attacks. The absence of external HTTP requests also reduces the attack surface from external services.
However, a significant concern lies in the unprotected attack surface. The plugin exposes three AJAX handlers without any authentication or authorization checks. This presents a direct and substantial risk, as any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure depending on their functionality. While the plugin has a good number of nonce and capability checks overall, their absence on these specific AJAX entry points is a critical oversight. The lack of reported vulnerabilities historically might be misleading; the current design of unprotected AJAX handlers could easily harbor exploitable flaws that haven't been discovered or disclosed yet.
In conclusion, while tiny-backup v1.1.1 benefits from strong output sanitization and a clean vulnerability history, the presence of unprotected AJAX handlers represents a serious security weakness. This oversight could lead to significant security issues if these handlers are not properly secured. The plugin's strengths in other areas are overshadowed by this critical flaw in its entry point security.
Key Concerns
- AJAX handlers without auth checks
- 3 unprotected AJAX entry points
Tiny Backup Security Vulnerabilities
Tiny Backup Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Tiny Backup Attack Surface
AJAX Handlers 3
WordPress Hooks 8
Maintenance & Trust
Tiny Backup Maintenance & Trust
Maintenance Signals
Community Trust
Tiny Backup Alternatives
BackUpWordPress
backupwordpress
Simple automated backups of your WordPress-powered website.
WP Database Backup – Unlimited Database & Files Backup by Backup for WP
wp-database-backup
Create & Restore Database Backup easily on single click. Manual or automated backups (backup to Dropbox, Google drive, Amazon s3,FTP,Email).
Zippy
zippy
Incredibly easy solution to archive pages and posts as zip file and unpack them back even on the other website!
The Hack Repair Guy's Plugin Archiver
hackrepair-plugin-archiver
Disable Plugins Without Deleting — Archive and Restore in One Click
Remote Database Backup
remote-database-backup
Lets you create and download SQL dumps of your wordpress database for backup.
Tiny Backup Developer Profile
5 plugins · 230 total installs
How We Detect Tiny Backup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tiny-backup/assets/css/admin.css/wp-content/plugins/tiny-backup/assets/js/admin.js/wp-content/plugins/tiny-backup/assets/js/admin.jstiny-backup/assets/css/admin.css?ver=tiny-backup/assets/js/admin.js?ver=HTML / DOM Fingerprints
tnbu-backup-togglestnbu-file-relatedtnbu-files-uitnbu-files-treetnbu-target-dirtnbu-wraptnbu-settings-formtnbuOptionKeytnbuPresetItemswindow.tnbuFilesNoncewindow.tnbuAjaxNoncewindow.ajaxurlwindow.tnbuOptionKeywindow.tnbuPresetItems