Backup, Restore and Migrate your sites with XCloner Security & Risk Analysis

wordpress.org/plugins/xcloner-backup-and-restore

XCloner is a backup plugin that allows you to safely back up and restore your WordPress sites. You can send site backups to SFTP, Dropbox, Amazon, Goo …

10K active installs v4.8.6 PHP 7.3+ WP 5.1+ Updated Apr 8, 2026
backupcloud-backupdatabase-backupwordpress-backupwordpress-migration
76
B · Generally Safe
CVEs total16
Unpatched0
Last CVEDec 4, 2025
Safety Verdict

Is Backup, Restore and Migrate your sites with XCloner Safe to Use in 2026?

Mostly Safe

Score 76/100

Backup, Restore and Migrate your sites with XCloner is generally safe to use. 16 past CVEs were resolved.

16 known CVEsLast CVE: Dec 4, 2025Updated 1mo ago
Risk Assessment

The plugin "xcloner-backup-and-restore" v4.8.4 presents a mixed security posture. While static analysis indicates a limited attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication, and all SQL queries utilize prepared statements, there are significant concerns. The low percentage of properly escaped output (29%) is a red flag, suggesting a high potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. Furthermore, the presence of a single flow with unsanitized paths in the taint analysis, even if not classified as critical or high, warrants careful review, as it could lead to path traversal or other file manipulation issues.

The plugin's vulnerability history is a major concern, with a substantial number of known CVEs, including a significant portion classified as critical and high. The variety of vulnerability types found in the history (Exposure of Sensitive Information, Missing Authorization, Path Traversal, Code Injection, Command Injection, XSS, Improper Access Control, CSRF) suggests a systemic issue with how user input and access control are managed within the plugin. The fact that the last recorded vulnerability was in 2025 indicates that even recent versions have had security flaws.

In conclusion, despite the apparent lack of directly exposed entry points in the static analysis, the plugin's history of numerous critical and high-severity vulnerabilities, coupled with the low percentage of proper output escaping and the identified unsanitized path flow, indicates a significant risk. The plugin has a track record of severe security flaws, and the current static analysis does not fully mitigate the risks suggested by its past. Users should exercise extreme caution and prioritize updating to a version that has demonstrably addressed the historical vulnerability patterns.

Key Concerns

  • Low output escaping (29%)
  • Taint flow with unsanitized paths
  • High number of historical CVEs (16 total)
  • Significant historical critical CVEs (4)
  • Significant historical high CVEs (6)
  • Vulnerability history includes code injection
  • Vulnerability history includes path traversal
  • Vulnerability history includes missing authorization
Vulnerabilities
16 published

Backup, Restore and Migrate your sites with XCloner Security Vulnerabilities

CVEs by Year

7 CVEs in 2014
2014
3 CVEs in 2015
2015
1 CVE in 2016
2016
2 CVEs in 2020
2020
1 CVE in 2022
2022
1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
4
High
6
Medium
6

16 total CVEs

CVE-2025-11759medium · 4.3Cross-Site Request Forgery (CSRF)

Backup, Restore and Migrate your sites with XCloner <= 4.8.2 - Cross-Site Request Forgery in Xcloner_Remote_Storage:save()

Dec 4, 2025 Patched in 4.8.3 (1d)
CVE-2024-6559medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

XCloner <= 4.7.3 - Unauthenticated Full Path Disclosure

Jul 15, 2024 Patched in 4.7.4 (1d)
CVE-2022-0444critical · 9.8Missing Authorization

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.16 - Unauthenticated Plugin Settings Reset

Jun 6, 2022 Patched in 4.3.6 (596d)
CVE-2020-35948high · 8.8Missing Authorization

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin 4.2.1 - 4.2.12 - Unprotected AJAX Actions

Aug 18, 2020 Patched in 4.2.153 (1253d)
CVE-2020-35950critical · 9.8Cross-Site Request Forgery (CSRF)

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.152 - Cross-Site Request Forgery

Aug 18, 2020 Patched in 4.2.153 (1253d)
WF-9d2345d2-0bcf-46fc-a857-0ec10a1b1c26-xcloner-backup-and-restoremedium · 4.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.4 - Path Traversal to Sensitive Information Disclosure

Dec 31, 2016 Patched in 3.1.5 (2579d)
CVE-2015-4338critical · 9.8Improper Control of Generation of Code ('Code Injection')

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Remote Code Execution

May 10, 2015 Patched in 3.1.3 (3180d)
CVE-2015-4336high · 8.8Improper Neutralization of Special Elements used in a Command ('Command Injection')

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Remote Command Execution

May 10, 2015 Patched in 3.1.3 (3180d)
CVE-2015-4337medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Cross-Site Scripting

May 10, 2015 Patched in 3.1.3 (3180d)
CVE-2014-8604high · 7.5Exposure of Sensitive Information to an Unauthorized Actor

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure

Oct 17, 2014 Patched in 3.1.2 (3385d)
CVE-2014-8605high · 7.5Improper Access Control

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Improper Access Control to Information Disclosure

Oct 17, 2014 Patched in 3.1.2 (3385d)
CVE-2014-8606medium · 4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Directory Traversal

Oct 17, 2014 Patched in 3.1.2 (3385d)
CVE-2014-8603high · 7.2Improper Control of Generation of Code ('Code Injection')

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Remote Code Execution

Oct 17, 2014 Patched in 3.1.2 (3385d)
CVE-2014-8607high · 7.2Exposure of Sensitive Information to an Unauthorized Actor

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure

Oct 17, 2014 Patched in 3.1.2 (3385d)
CVE-2014-2579critical · 9.6Cross-Site Request Forgery (CSRF)

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 - Multiple Cross-Site Request Forgery

Apr 9, 2014 Patched in 3.1.1 (3576d)
CVE-2014-2340medium · 5.4Cross-Site Request Forgery (CSRF)

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 - Cross-Site Request Forgery

Apr 2, 2014 Patched in 3.1.1 (3583d)
Version History

Backup, Restore and Migrate your sites with XCloner Release Timeline

v4.8.6Current
v4.8.5
v4.8.4
v4.8.3
v4.8.21 CVE
v4.8.11 CVE
v4.8.01 CVE
v4.7.91 CVE
v4.7.81 CVE
v4.7.71 CVE
v4.7.61 CVE
v4.7.51 CVE
v4.7.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Backup, Restore and Migrate your sites with XCloner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
390
156 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
3

Bundled Libraries

DataTablesGuzzlejQuery

Output Escaping

29% escaped546 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<xcloner_manage_backups_page> (admin\partials\xcloner_manage_backups_page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Backup, Restore and Migrate your sites with XCloner Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Backup, Restore and Migrate your sites with XCloner Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 8, 2026
PHP min version7.3
Downloads1.4M

Community Trust

Rating84/100
Number of ratings129
Active installs10K
Developer Profile

Backup, Restore and Migrate your sites with XCloner Developer Profile

watchful

3 plugins · 14K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
2457 days
View full developer profile
Detection Fingerprints

How We Detect Backup, Restore and Migrate your sites with XCloner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xcloner-backup-and-restore/admin/css/materialize.min.css/wp-content/plugins/xcloner-backup-and-restore/admin/css/jquery.dataTables.min.css/wp-content/plugins/xcloner-backup-and-restore/admin/css/responsive.dataTables.css/wp-content/plugins/xcloner-backup-and-restore/vendor/vakata/jstree/dist/themes/default/style.min.css/wp-content/plugins/xcloner-backup-and-restore/admin/css/xcloner-admin.css/wp-content/plugins/xcloner-backup-and-restore/admin/js/jquery.dataTables.min.js/wp-content/plugins/xcloner-backup-and-restore/admin/js/xcloner-admin.js/wp-content/plugins/xcloner-backup-and-restore/admin/js/xcloner.js+1 more
Generator Patterns
XCloner - Site Backup and Restore 4.8.4
Script Paths
//fonts.googleapis.com/icon?family=Material+Icons
Version Parameters
xcloner-backup-and-restore/admin/css/materialize.min.css?ver=xcloner-backup-and-restore/admin/css/jquery.dataTables.min.css?ver=xcloner-backup-and-restore/admin/css/responsive.dataTables.css?ver=xcloner-backup-and-restore/vendor/vakata/jstree/dist/themes/default/style.min.css?ver=xcloner-backup-and-restore/admin/css/xcloner-admin.css?ver=xcloner-backup-and-restore/admin/js/jquery.dataTables.min.js?ver=xcloner-backup-and-restore/admin/js/xcloner-admin.js?ver=xcloner-backup-and-restore/admin/js/xcloner.js?ver=xcloner-backup-and-restore/vendor/js/jquery.datetimepicker.full.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
xcloner-backup-and-restore
HTML Comments
<!-- XCloner notices --><!-- Begin XCloner Admin Panel --><!-- End XCloner Admin Panel --><!-- End XCloner notices -->+1 more
Data Attributes
data-xcloner-iddata-xcloner-action
JS Globals
XclonerxclonerXclonerSettings
REST Endpoints
/wp-json/xcloner/v1
FAQ

Frequently Asked Questions about Backup, Restore and Migrate your sites with XCloner