WPIntell

Source evidence

YARA scan/ false positive?

Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More · support · 2026-05-20T16:33:00+00:00

mixedsentiment
highseverity
0.95relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 13 rows with source links

46.2% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

7 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
programmin resolved
YARA scan shows this plugin’s files as a webshell… in /wp-snapshots/XYZ…BAK_(long-idenifier)_installer.php I’m thinking this is a false-positive, and is secure as long as someone doesn’t guess that long-identifier and decide to call a backup restore somehow? Hi @programmin , Thanks for flagging this. This is a false positive. Duplicator’s installer.php is a legitimate restore script that gets flagged by security scanners because it has powerful capabilities by design (file access, database interaction, etc.), the same traits scanners look for in webshells. A couple of things worth noting: The /wp-snapshots/ directory you’re seeing is from an older version of Duplicator — it no longer exists in current releases. This suggests your plugin is out of date. Duplicator includes a cleanup step at the end of the restore process that removes the installer and archive files. If you see an installer.php sitting around, make sure you complete that cleanup step after any restore. We’d recommend updating Duplicator to the latest version to get the most recent security improvements and stay on the supported path. Hope that helps! Hi @programmin , We haven’t heard back from you in a few days, so I’m going to go ahead and close this thread for now. But if you’d like us to assist further, please feel welcome to continue the conversation. Thanks!

Comments

2 shown
mohammedeisa 2026-05-20T18:16:00+00:00

Hi @programmin , Thanks for flagging this. This is a false positive. Duplicator’s installer.php is a legitimate restore script that gets flagged by security scanners because it has powerful capabilities by design (file access, database interaction, etc.), the same traits scanners look for in webshells. A couple of things worth noting: The /wp-snapshots/ directory you’re seeing is from an older version of Duplicator — it no longer exists in current releases. This suggests your plugin is out of date. Duplicator includes a cleanup step at the end of the restore process that removes the installer and archive files. If you see an installer.php sitting around, make sure you complete that cleanup step after any restore. We’d recommend updating Duplicator to the latest version to get the most recent security improvements and stay on the supported path. Hope that helps!

mohammedeisa 2026-05-26T18:43:00+00:00

Hi @programmin , We haven’t heard back from you in a few days, so I’m going to go ahead and close this thread for now. But if you’d like us to assist further, please feel welcome to continue the conversation. Thanks!