WPtools.io Cloud Backup & Restore Plugin Security & Risk Analysis

wordpress.org/plugins/wptio-backups

WPtools.io Cloud Backup & Restore Plugin (Beta)

0 active installs v1.2.2 PHP 5.2.4+ WP 4.6+ Updated Apr 4, 2018
backupcloud-backupdatabase-backuprestorewptools
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPtools.io Cloud Backup & Restore Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

WPtools.io Cloud Backup & Restore Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "wptio-backups" v1.2.2 plugin presents a mixed security posture. While the absence of known CVEs and a clean taint analysis are positive indicators, significant concerns arise from the static code analysis. A notable weakness is the presence of an unprotected AJAX handler, which represents a direct entry point into the plugin's functionality that could be exploited without proper authentication or authorization.

The plugin's code signals also reveal areas for improvement. A substantial number of file operations and SQL queries are present, and while a portion of SQL queries use prepared statements, the overall percentage could be higher. More critically, 100% of the observed output is not properly escaped, indicating a high risk of cross-site scripting (XSS) vulnerabilities if user-supplied data or dynamic content is ever rendered directly in the output. The limited number of nonces and capability checks, coupled with the unprotected AJAX handler, further exacerbates these risks.

Given the lack of historical vulnerabilities, it's difficult to infer patterns. However, this absence does not negate the present risks. The plugin has strengths in its lack of external HTTP requests and the absence of dangerous functions and critical taint flows. Nevertheless, the identified unprotected AJAX handler and the universal lack of output escaping are significant security weaknesses that require immediate attention to mitigate potential exploits.

Key Concerns

  • Unprotected AJAX handler detected
  • 100% of output is unescaped
  • Limited nonce checks
  • Limited capability checks
  • 33% of SQL queries not prepared
Vulnerabilities
None known

WPtools.io Cloud Backup & Restore Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WPtools.io Cloud Backup & Restore Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
20
10 prepared
Unescaped Output
19
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
35
External Requests
0
Bundled Libraries
0

SQL Query Safety

33% prepared30 total queries

Output Escaping

0% escaped19 total outputs
Attack Surface
1 unprotected

WPtools.io Cloud Backup & Restore Plugin Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wptio_apiinit.php:34
WordPress Hooks 5
actionadmin_menuinit.php:35
actionadmin_enqueue_scriptsinit.php:36
actionplugins_loadedinit.php:37
filtercron_schedulesinit.php:39
actionwptio_every_30_secondsinit.php:43

Scheduled Events 1

wptio_every_30_seconds
Maintenance & Trust

WPtools.io Cloud Backup & Restore Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 4, 2018
PHP min version5.2.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WPtools.io Cloud Backup & Restore Plugin Developer Profile

hasanhalabi

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPtools.io Cloud Backup & Restore Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wptio-backups/bootstrap/css/bootstrap.min.css/wp-content/plugins/wptio-backups/js/wptio.ajax.js/wp-content/plugins/wptio-backups/js/wptio.drivebtn.js/wp-content/plugins/wptio-backups/icon/icon.png
Script Paths
/wp-content/plugins/wptio-backups/js/wptio.ajax.js/wp-content/plugins/wptio-backups/js/wptio.drivebtn.js
Version Parameters
wptio-backups/bootstrap/css/bootstrap.min.css?ver=wptio-backups/js/wptio.ajax.js?ver=wptio-backups/js/wptio.drivebtn.js?ver=

HTML / DOM Fingerprints

CSS Classes
wptio-backup-btn
Data Attributes
data-wp-nonce
JS Globals
WPTIO_VERSION
FAQ

Frequently Asked Questions about WPtools.io Cloud Backup & Restore Plugin