
Backup, Restore and Migrate your sites with XCloner Security & Risk Analysis
wordpress.org/plugins/xcloner-backup-and-restoreXCloner is a backup plugin that allows you to safely back up and restore your WordPress sites. You can send site backups to SFTP, Dropbox, Amazon, Goo …
Is Backup, Restore and Migrate your sites with XCloner Safe to Use in 2026?
Mostly Safe
Score 76/100Backup, Restore and Migrate your sites with XCloner is generally safe to use. 16 past CVEs were resolved.
The plugin "xcloner-backup-and-restore" v4.8.4 presents a mixed security posture. While static analysis indicates a limited attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication, and all SQL queries utilize prepared statements, there are significant concerns. The low percentage of properly escaped output (29%) is a red flag, suggesting a high potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. Furthermore, the presence of a single flow with unsanitized paths in the taint analysis, even if not classified as critical or high, warrants careful review, as it could lead to path traversal or other file manipulation issues.
The plugin's vulnerability history is a major concern, with a substantial number of known CVEs, including a significant portion classified as critical and high. The variety of vulnerability types found in the history (Exposure of Sensitive Information, Missing Authorization, Path Traversal, Code Injection, Command Injection, XSS, Improper Access Control, CSRF) suggests a systemic issue with how user input and access control are managed within the plugin. The fact that the last recorded vulnerability was in 2025 indicates that even recent versions have had security flaws.
In conclusion, despite the apparent lack of directly exposed entry points in the static analysis, the plugin's history of numerous critical and high-severity vulnerabilities, coupled with the low percentage of proper output escaping and the identified unsanitized path flow, indicates a significant risk. The plugin has a track record of severe security flaws, and the current static analysis does not fully mitigate the risks suggested by its past. Users should exercise extreme caution and prioritize updating to a version that has demonstrably addressed the historical vulnerability patterns.
Key Concerns
- Low output escaping (29%)
- Taint flow with unsanitized paths
- High number of historical CVEs (16 total)
- Significant historical critical CVEs (4)
- Significant historical high CVEs (6)
- Vulnerability history includes code injection
- Vulnerability history includes path traversal
- Vulnerability history includes missing authorization
Backup, Restore and Migrate your sites with XCloner Security Vulnerabilities
CVEs by Year
Severity Breakdown
16 total CVEs
Backup, Restore and Migrate your sites with XCloner <= 4.8.2 - Cross-Site Request Forgery in Xcloner_Remote_Storage:save()
XCloner <= 4.7.3 - Unauthenticated Full Path Disclosure
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.16 - Unauthenticated Plugin Settings Reset
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin 4.2.1 - 4.2.12 - Unprotected AJAX Actions
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 4.2.152 - Cross-Site Request Forgery
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.4 - Path Traversal to Sensitive Information Disclosure
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Remote Code Execution
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Remote Command Execution
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.2 - Cross-Site Scripting
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Improper Access Control to Information Disclosure
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Directory Traversal
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Remote Code Execution
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 - Multiple Cross-Site Request Forgery
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.0 - Cross-Site Request Forgery
Backup, Restore and Migrate your sites with XCloner Release Timeline
Backup, Restore and Migrate your sites with XCloner Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Backup, Restore and Migrate your sites with XCloner Attack Surface
Maintenance & Trust
Backup, Restore and Migrate your sites with XCloner Maintenance & Trust
Maintenance Signals
Community Trust
Backup, Restore and Migrate your sites with XCloner Alternatives
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
Backuply – Backup, Restore, Migrate and Clone
backuply
Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …
BackWPup – WordPress Backup & Restore Plugin
backwpup
Create a complete WordPress backup easily. Schedule automatic backups, store securely, and restore effortlessly with the best WordPress backup plugin!
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid
boldgrid-backup
Automated backups, remote backup to Amazon S3 and Google Drive, stop website crashes before they happen and more. Total Upkeep is the backup solution …
Backup, Restore and Migrate your sites with XCloner Developer Profile
3 plugins · 14K total installs
How We Detect Backup, Restore and Migrate your sites with XCloner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xcloner-backup-and-restore/admin/css/materialize.min.css/wp-content/plugins/xcloner-backup-and-restore/admin/css/jquery.dataTables.min.css/wp-content/plugins/xcloner-backup-and-restore/admin/css/responsive.dataTables.css/wp-content/plugins/xcloner-backup-and-restore/vendor/vakata/jstree/dist/themes/default/style.min.css/wp-content/plugins/xcloner-backup-and-restore/admin/css/xcloner-admin.css/wp-content/plugins/xcloner-backup-and-restore/admin/js/jquery.dataTables.min.js/wp-content/plugins/xcloner-backup-and-restore/admin/js/xcloner-admin.js/wp-content/plugins/xcloner-backup-and-restore/admin/js/xcloner.js+1 moreXCloner - Site Backup and Restore 4.8.4//fonts.googleapis.com/icon?family=Material+Iconsxcloner-backup-and-restore/admin/css/materialize.min.css?ver=xcloner-backup-and-restore/admin/css/jquery.dataTables.min.css?ver=xcloner-backup-and-restore/admin/css/responsive.dataTables.css?ver=xcloner-backup-and-restore/vendor/vakata/jstree/dist/themes/default/style.min.css?ver=xcloner-backup-and-restore/admin/css/xcloner-admin.css?ver=xcloner-backup-and-restore/admin/js/jquery.dataTables.min.js?ver=xcloner-backup-and-restore/admin/js/xcloner-admin.js?ver=xcloner-backup-and-restore/admin/js/xcloner.js?ver=xcloner-backup-and-restore/vendor/js/jquery.datetimepicker.full.min.js?ver=HTML / DOM Fingerprints
xcloner-backup-and-restore<!-- XCloner notices --><!-- Begin XCloner Admin Panel --><!-- End XCloner Admin Panel --><!-- End XCloner notices -->+1 moredata-xcloner-iddata-xcloner-actionXclonerxclonerXclonerSettings/wp-json/xcloner/v1