
Clone Security & Risk Analysis
wordpress.org/plugins/wp-clone-by-wp-academy100% FREE clone and migration
Is Clone Safe to Use in 2026?
Generally Safe
Score 93/100Clone has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-clone-by-wp-academy plugin v2.4.8 exhibits several concerning security practices, despite some positive indications. The presence of two AJAX handlers without authentication checks is a significant immediate risk, potentially allowing unauthorized users to trigger sensitive operations. While the taint analysis found no critical or high-severity issues, the overall code signals are mixed. The use of 'unserialize' is a known dangerous function that, if combined with other weaknesses, could lead to severe vulnerabilities. Furthermore, a substantial percentage of SQL queries are not using prepared statements, increasing the risk of SQL injection. The plugin's history of five CVEs, including one critical and one high severity, is a major red flag. This pattern suggests a recurring struggle with fundamental security principles, particularly around deserialization, authorization, and exposure of sensitive information. While the absence of currently unpatched vulnerabilities and the presence of nonce checks are positive, the combination of insecure code practices and a history of past vulnerabilities warrants a cautious approach.
Key Concerns
- AJAX handlers without auth checks
- SQL queries not using prepared statements
- Dangerous function: unserialize
- Significant percentage of unescaped output
- Past critical CVE
- Past high CVE
- Past medium CVEs (x3)
Clone Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Clone <= 2.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialized_replace'
Clone <= 2.4.5 - Missing Authorization
WP Clone <= 2.4.2 - Sensitive Information Exposure
Clone <= 2.3.7 - Cross-Site Request Forgery via wp_ajax_tifm_save_decision
Clone <= 2.3.7 - Missing Authorization via wp_ajax_tifm_save_decision
Clone Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Clone Attack Surface
AJAX Handlers 15
WordPress Hooks 25
Maintenance & Trust
Clone Maintenance & Trust
Maintenance Signals
Community Trust
Clone Alternatives
WPvivid — Backup, Migration & Staging
wpvivid-backuprestore
Migrate, staging, backup WordPress, all in one.
InstaWP Connect – 1-click WP Staging & Migration
instawp-connect
Create a staging WordPress site from production (live site). Ideal for testing updates, version change or re-write. Sync back only the changes.
Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups
trinity-backup
Backup, migrate, clone, and restore WordPress sites of any size. Scheduled, pre-update backups, email notifications, WP-CLI, white label, encryption.
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Prime Mover – Migrate WordPress Website & Backups
prime-mover
The simplest all-around WordPress migration tool/backup plugin. These support multisite backup/migration or clone WP site/multisite subsite.
Clone Developer Profile
2 plugins · 250K total installs
How We Detect Clone
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-clone-by-wp-academy/lib/css/style.css/wp-content/plugins/wp-clone-by-wp-academy/lib/js/backupmanager.js/wp-content/plugins/wp-clone-by-wp-academy/lib/js/clipboard.min.js/wp-content/plugins/wp-clone-by-wp-academy/modules/backupModal/css/style.min.css/wp-content/plugins/wp-clone-by-wp-academy/lib/js/backupmanager.js/wp-content/plugins/wp-clone-by-wp-academy/lib/js/clipboard.min.jswp-clone-by-wp-academy/lib/css/style.css?ver=wp-clone-by-wp-academy/lib/js/backupmanager.js?ver=wp-clone-by-wp-academy/lib/js/clipboard.min.js?ver=wp-clone-by-wp-academy/modules/backupModal/css/style.min.css?ver=HTML / DOM Fingerprints
wpclone_main_wrapwpclone_top_menuwpclone_backup_btnwpclone_backup_listwpclone_backup_itemwpclone_restore_backupwpclone_delete_backupwpclone_install_new_backup<!-- JS --><!-- Modal Structure --><!-- Backup Modal --><!-- Close Button -->+20 moredata-target="#backupModal"data-toggle="modal"data-backup-iddata-backup-namedata-backup-datedata-backup-size+3 morewpclone