
WebTotem Backups Security & Risk Analysis
wordpress.org/plugins/wt-backupsWebTotem Backups - this plugin provides a set of tools for creating, managing, and restoring backups of your website.
Is WebTotem Backups Safe to Use in 2026?
Generally Safe
Score 92/100WebTotem Backups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wt-backups" plugin version 1.0.1 exhibits a significant security concern due to its extensive attack surface being entirely unprotected by authentication checks. All 19 identified AJAX handlers lack proper authorization, meaning any user, regardless of their role or logged-in status, could potentially trigger these functions. While the code analysis shows no dangerous functions, raw SQL queries, or unescaped output, and the vulnerability history is clean, the sheer number of unprotected entry points presents a high risk of privilege escalation or unauthorized actions if a vulnerability exists within these handlers. The presence of Guzzle, a bundled library, could also be a concern if it's outdated, though no specific information on its version is provided.
Despite the lack of recorded vulnerabilities and positive indicators like prepared statements and output escaping, the complete absence of capability checks and nonce checks on AJAX handlers is a critical oversight. This makes the plugin highly susceptible to various attacks, including Cross-Site Request Forgery (CSRF) and unauthorized function execution, assuming the handlers perform sensitive operations. The clean vulnerability history might suggest a lack of active exploitation or a very new plugin, but it does not mitigate the immediate risks posed by the unprotected attack surface.
In conclusion, while "wt-backups" v1.0.1 demonstrates good practices in areas like SQL and output handling, its fundamental flaw lies in the complete lack of security for its AJAX endpoints. This drastically elevates the risk profile, overshadowing the positive aspects. Immediate remediation by implementing proper authentication and authorization for all AJAX handlers is strongly recommended.
Key Concerns
- 19 AJAX handlers without auth checks
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
- Bundled Guzzle library (potential outdatedness)
WebTotem Backups Security Vulnerabilities
WebTotem Backups Release Timeline
WebTotem Backups Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WebTotem Backups Attack Surface
AJAX Handlers 19
WordPress Hooks 14
Scheduled Events 4
Maintenance & Trust
WebTotem Backups Maintenance & Trust
Maintenance Signals
Community Trust
WebTotem Backups Alternatives
Clone
wp-clone-by-wp-academy
100% FREE clone and migration
InstaWP Connect – 1-click WP Staging & Migration
instawp-connect
Create a staging WordPress site from production (live site). Ideal for testing updates, version change or re-write. Sync back only the changes.
Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups
trinity-backup
Backup, migrate, clone, and restore WordPress sites of any size. Scheduled, pre-update backups, email notifications, WP-CLI, white label, encryption.
1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone
1-click-migration
Free WordPress migration plugin for backup, restore, clone, and site transfer with zero downtime. Migrate WordPress site easily.
DeltaBackups – backup & migration
deltabackups
DeltaBackups is a plugin for backing up content files and database
WebTotem Backups Developer Profile
2 plugins · 910 total installs
How We Detect WebTotem Backups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wt-backups/wt-backups/style.css?ver=HTML / DOM Fingerprints
Protected By WebTotem! Dependencies are not metProtected By WebTotem! ABSPATH constant is not available