
Zippy Security & Risk Analysis
wordpress.org/plugins/zippyIncredibly easy solution to archive pages and posts as zip file and unpack them back even on the other website!
Is Zippy Safe to Use in 2026?
Mostly Safe
Score 71/100Zippy is generally safe to use. 5 past CVEs were resolved.
The "zippy" v1.7.0 plugin exhibits a mixed security posture. While it demonstrates some good practices, such as a relatively low number of SQL queries and a high percentage of prepared statements, along with proper output escaping and capability checks, several concerning signals are present. The static analysis reveals the presence of a dangerous `unserialize` function, which is a significant risk, especially when not handled with extreme caution. The taint analysis shows no unsanitized paths, which is a positive indicator, but the existence of the `unserialize` function remains a potential entry point for vulnerabilities if user-supplied data is processed without strict validation.
The plugin's vulnerability history is a major concern. With a total of 5 known CVEs, including 3 high and 2 medium severity vulnerabilities, and crucially, one currently unpatched vulnerability, the risk is significantly elevated. The common vulnerability types identified – Unrestricted Upload of File with Dangerous Type, Missing Authorization, Deserialization of Untrusted Data, and Exposure of Sensitive Information – align with the `unserialize` function identified in the static analysis and suggest recurring security flaws within the plugin's development. The recent vulnerability in August 2024 further emphasizes the ongoing nature of these issues.
In conclusion, while "zippy" v1.7.0 has some positive security attributes, the presence of a dangerous function like `unserialize` and a history of multiple, including unpatched, critical and high-severity vulnerabilities overwhelmingly point to a high-risk plugin. Users should exercise extreme caution and consider migrating to a more secure alternative or thoroughly auditing and patching any identified vulnerabilities before deployment.
Key Concerns
- Unpatched CVE
- High severity vulnerabilities (3)
- Medium severity vulnerabilities (2)
- Dangerous function (unserialize)
Zippy Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Zippy <= 1.7.0 - Authenticated (Editor+) Arbitrary File Upload
Zippy <= 1.6.9 - Authenticated (Editor+) Arbitrary File Upload
Zippy <= 1.6.2 - Missing Authorization via adminInit
Zippy <= 1.6.5 - Authenticated(Author+) PHP Object Injection via unzipPosts
Zippy <= 1.6.1 - Authenticated (Contributor+) Sensitive Information Disclosure
Zippy Release Timeline
Zippy Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Zippy Attack Surface
WordPress Hooks 8
Maintenance & Trust
Zippy Maintenance & Trust
Maintenance Signals
Community Trust
Zippy Alternatives
Save Now
save-now
Easily download other installed plugins and themes as ZIP files from your WordPress admin interface.
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
WP STAGING – WordPress Backup, Restore & Migration
wp-staging
Backup, restore, staging, and migration for WordPress. Create full-site backups and test updates safely. 100% Unit Tested.
BackupBliss – Backup & Migration with Free Cloud Storage
backup-backup
Backup, migrate, and create staging sites with free cloud storage and support.
Zippy Developer Profile
2 plugins · 10K total installs
How We Detect Zippy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zippy/css/admin.css/wp-content/plugins/zippy/css/style.css/wp-content/plugins/zippy/js/admin.js/wp-content/plugins/zippy/js/zippy.js/wp-content/plugins/zippy/js/admin.js/wp-content/plugins/zippy/js/zippy.jszippy/css/admin.css?ver=zippy/css/style.css?ver=zippy/js/admin.js?ver=zippy/js/zippy.js?ver=HTML / DOM Fingerprints
zippy-boxzippy-file-upload<!-- Zippy zip --><!-- Zippy unzip --><!-- Zippy settings -->data-zippy-noncedata-zippy-actiondata-zippy-targetzippy_params[zippy_unzip]