
WP Umbrella: Update Backup Restore & Monitoring Security & Risk Analysis
wordpress.org/plugins/wp-healthEverything you need to sell WordPress maintenance and manage multiple sites effortlessly: backup, update, uptime monitoring, and security.
Is WP Umbrella: Update Backup Restore & Monitoring Safe to Use in 2026?
Generally Safe
Score 97/100WP Umbrella: Update Backup Restore & Monitoring has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-health plugin version 2.22.0 exhibits a mixed security posture. While it demonstrates good practices in areas like using prepared statements for a significant portion of its SQL queries and properly escaping most output, several concerning indicators are present. The presence of 14 AJAX handlers, with one lacking any authentication checks, represents a direct and accessible attack surface. Furthermore, the taint analysis reveals three high-severity flows with unsanitized paths, indicating potential for unauthorized data access or manipulation. The plugin's vulnerability history, including a past critical vulnerability classified as PHP Remote File Inclusion, is a significant concern, suggesting a tendency towards exploitable weaknesses in file handling. Although there are no currently unpatched vulnerabilities, the pattern of past critical issues and the static analysis findings warrant caution.
In conclusion, while the plugin has strengths in data handling and output sanitization, the unsecured AJAX endpoint, high-severity taint flows, and historical critical vulnerabilities collectively present a notable risk. This requires careful consideration and mitigation, particularly given the potential for file inclusion or similar attacks given its past history. Users should be aware of these potential weaknesses.
Key Concerns
- AJAX handler without authentication
- High severity taint flows with unsanitized paths
- Previous critical vulnerability (RFI)
- Use of dangerous functions (unserialize, exec, proc_open)
WP Umbrella: Update Backup Restore & Monitoring Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
WP Umbrella: Update Backup Restore & Monitoring Release Timeline
WP Umbrella: Update Backup Restore & Monitoring Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Umbrella: Update Backup Restore & Monitoring Attack Surface
AJAX Handlers 14
WordPress Hooks 151
Maintenance & Trust
WP Umbrella: Update Backup Restore & Monitoring Maintenance & Trust
Maintenance Signals
Community Trust
WP Umbrella: Update Backup Restore & Monitoring Alternatives
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
Modular DS: Monitor, update, and backup multiple websites
modular-connector
Manage all your WordPress sites from one place. Automate updates, backups, uptime monitoring, security, maintenance reports, and more.
SiteSkite: Manage Multiple Sites, Maintenance, Backups, Updates, Sandbox, Monitoring & More
siteskite
Manage multiple WordPress sites from one dashboard. Automate backups, maintenance reports, updates, uptime monitoring, AI tools, Sandbox sites and mor …
The WP Remote WordPress Plugin
wpremote
Manage updates, backups, and more across all your WordPress sites with WP Remote.
MainWP Dashboard: Self-hosted WordPress Management for Agencies
mainwp
Run updates, backups, security and reporting across all client sites from your own server. Keep data private and prove your value with branded reports …
WP Umbrella: Update Backup Restore & Monitoring Developer Profile
1 plugin · 60K total installs
How We Detect WP Umbrella: Update Backup Restore & Monitoring
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-health/app/styles/sweetalert.css/wp-content/plugins/wp-health/dist/style.css/wp-content/plugins/wp-health/dist/app.js/wp-content/plugins/wp-health/dist/vendors.js/wp-content/plugins/wp-health/dist/app.js/wp-content/plugins/wp-health/dist/vendors.jswp-health/dist/style.css?ver=wp-health/dist/app.js?ver=wp-health/dist/vendors.js?ver=HTML / DOM Fingerprints
wp-umbrella-stylesdata-urldata-noncedata-plugin-versiondata-current-versiondata-next-update-urldata-plugin-slug+8 moreWPUMBRELLA_URLWPUMBRELLA_URL_DISTWPUMBRELLA_DIRURLWPUMBRELLA_VERSIONWPUMBRELLA_DEBUGWP_UMBRELLA_URL+5 more/wp-json/wp-umbrella/v1/logs/wp-json/wp-umbrella/v1/error_logs/wp-json/wp-umbrella/v1/uptime/wp-json/wp-umbrella/v1/check-update/wp-json/wp-umbrella/v1/sync/wp-json/wp-umbrella/v1/plugin-update/wp-json/wp-umbrella/v1/theme-update/wp-json/wp-umbrella/v1/site-health-check/wp-json/wp-umbrella/v1/backup/wp-json/wp-umbrella/v1/cancel-backup/wp-json/wp-umbrella/v1/restore-backup/wp-json/wp-umbrella/v1/get-backups/wp-json/wp-umbrella/v1/delete-backup/wp-json/wp-umbrella/v1/download-backup/wp-json/wp-umbrella/v1/schedule-backup/wp-json/wp-umbrella/v1/site-meta/wp-json/wp-umbrella/v1/site-options/wp-json/wp-umbrella/v1/get-site-option/wp-json/wp-umbrella/v1/delete-site-option/wp-json/wp-umbrella/v1/update-site-option/wp-json/wp-umbrella/v1/get-options/wp-json/wp-umbrella/v1/update-option/wp-json/wp-umbrella/v1/plugins/wp-json/wp-umbrella/v1/themes/wp-json/wp-umbrella/v1/users/wp-json/wp-umbrella/v1/check-ssl/wp-json/wp-umbrella/v1/update-settings/wp-json/wp-umbrella/v1/regenerate-api-key/wp-json/wp-umbrella/v1/delete-api-key/wp-json/wp-umbrella/v1/regenerate-log-file/wp-json/wp-umbrella/v1/get-log-file/wp-json/wp-umbrella/v1/delete-log-file/wp-json/wp-umbrella/v1/restore-default-settings/wp-json/wp-umbrella/v1/reset-cache/wp-json/wp-umbrella/v1/maintenance-mode/wp-json/wp-umbrella/v1/send-test-email