
Jetpack VaultPress Security & Risk Analysis
wordpress.org/plugins/vaultpress(DEPRECATED: Please install "Jetpack VaultPress Backup" instead) Jetpack VaultPress offers real-time backups, one-click restores, and premiu …
Is Jetpack VaultPress Safe to Use in 2026?
Generally Safe
Score 97/100Jetpack VaultPress has a strong security track record. Known vulnerabilities have been patched promptly.
The VaultPress plugin v4.0.6 exhibits a mixed security posture. On one hand, it demonstrates good security practices with a low attack surface, with all identified entry points protected by authentication checks. The high percentage of prepared statements in SQL queries and properly escaped output are also positive indicators. However, several concerns arise from the static analysis and vulnerability history. The presence of dangerous functions like 'exec' and 'unserialize', coupled with taint analysis revealing flows with unsanitized paths, is a significant red flag. While no critical taint flows were found, the two high severity flows warrant attention. The plugin's history of two critical Common Vulnerabilities and Exploits (CVEs), specifically related to code injection, further amplifies these concerns, suggesting a recurring vulnerability pattern despite the last known vulnerability being in 2017. The plugin's strengths lie in its controlled entry points and output handling, but the potential for code execution and insecure deserialization due to dangerous functions and unsanitized data flows presents a notable risk.
Key Concerns
- High severity taint flows with unsanitized paths
- Presence of dangerous functions (exec, unserialize)
- Historical critical CVEs
- Historical high CVEs
- Taint analysis shows unsanitized paths
Jetpack VaultPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
VaultPress <=1.9 - Remote Code Execution
VaultPress <= 1.8.6 - Remote Code Execution
Jetpack VaultPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Jetpack VaultPress Attack Surface
AJAX Handlers 1
WordPress Hooks 93
Scheduled Events 2
Maintenance & Trust
Jetpack VaultPress Maintenance & Trust
Maintenance Signals
Community Trust
Jetpack VaultPress Alternatives
NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall
ninjafirewall
A true Web Application Firewall to protect and secure WordPress.
NinjaScanner – Virus & Malware scan
ninjascanner
A lightweight, fast and powerful virus scanner for WordPress.
Malcure Malware Shield — Removal, Repair, Monitor
wp-malware-removal
Fast malware removal & security shield. Fix hacks, stop redirects, clean SEO spam. Real-time threat intelligence. No bloat.
Virusdie – One-click website security
virusdie
Malware scanning & removal, website hardening, patching vulnerabilities, real-time protection against online attacks, blacklist monitoring in a click!
Shieldfy Security Firewall and Anti Virus
shieldfy
Shieldfy is a cloud-based security shield for your website to protect it from web attacks and malwares.
Jetpack VaultPress Developer Profile
213 plugins · 19.2M total installs
How We Detect Jetpack VaultPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vaultpress/vaultpress.css/wp-content/plugins/vaultpress/vaultpress.js/wp-content/plugins/vaultpress/vaultpress.jsvaultpress/vaultpress.css?ver=vaultpress/vaultpress.js?ver=HTML / DOM Fingerprints
vaultpress-branding<!-- VaultPress -->data-vp-connection-statusdata-vp-registeredVaultPressvp/wp-json/vaultpress/v1/status