
WP S3 Backups Security & Risk Analysis
wordpress.org/plugins/wp-s3-backupsAutomatically back up important bits of your WordPress install to Amazon S3.
Is WP S3 Backups Safe to Use in 2026?
Generally Safe
Score 85/100WP S3 Backups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-s3-backups" plugin v0.3.0 presents a concerning security posture despite a clean vulnerability history. The static analysis reveals significant weaknesses that could be exploited. Notably, the presence of the `shell_exec` function, an unescaped output for all identified outputs, and a complete lack of nonce and capability checks on its entry points are major red flags. This means that potentially any user could trigger dangerous commands or manipulate plugin behavior without proper authorization.
The taint analysis, while not identifying critical or high severity issues, did reveal flows with unsanitized paths, which is troubling given the other identified code weaknesses. The plugin's SQL queries are also not using prepared statements, increasing the risk of SQL injection vulnerabilities. Coupled with file operation capabilities and external HTTP requests, these factors indicate a high potential for unauthorized code execution, data manipulation, or information disclosure.
While the plugin has no recorded CVEs, this should not be interpreted as a sign of robust security. The identified code signals suggest that vulnerabilities are likely present and simply have not been discovered or reported. The plugin's current state, with numerous insecure coding practices, warrants a cautious approach and suggests it is not suitable for production environments without significant remediation.
Key Concerns
- Dangerous function shell_exec used
- No output escaping
- No nonce checks
- No capability checks
- SQL queries not using prepared statements
- Unsanitized paths in taint flows
- File operations present
- External HTTP requests present
WP S3 Backups Security Vulnerabilities
WP S3 Backups Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP S3 Backups Attack Surface
WordPress Hooks 5
Scheduled Events 1
Maintenance & Trust
WP S3 Backups Maintenance & Trust
Maintenance Signals
Community Trust
WP S3 Backups Alternatives
WP S3 Backups Developer Profile
7 plugins · 640 total installs
How We Detect WP S3 Backups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-s3-backups/css/style.css/wp-content/plugins/wp-s3-backups/js/s3b.js/wp-content/plugins/wp-s3-backups/js/s3b.jswp-s3-backups/css/style.css?ver=wp-s3-backups/js/s3b.js?ver=HTML / DOM Fingerprints
s3-warning<!--WPS3BU::backup() -->id="s3-warning"id="new-s3-bucket"var ajaxTarget = var nonce =