shouldiuse.io

Categories

VERDICT

Should I use WordPress Backup + Staging - WP Time Capsule?

A time machine for your WordPress sites. Backup just the changes, time to smarten up. - wptimecapsule.com

Depends. Buy it if you run WordPress sites, want incremental backups into your own cloud storage, and patch plugins promptly. Skip it if you won't keep it updated — its CVE history makes an unpatched install a genuine attack vector.

Confidence

Medium. Based on 14 public sources; no pricing data found in reviewed pages; several reviews date to 2017–2018.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support evidence in sources
  • Security posture

Pricing

Not disclosed

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • WordPress owners wanting incremental backups
  • Sites already on S3, Dropbox, or Google Drive
  • Agencies managing multiple WordPress sites
  • Staging plus pre-update safety snapshots

Not for

  • Anyone who won't update plugins within days of a security release
  • Non-WordPress sites — this is WordPress only
  • Buyers wanting vendor-hosted, managed backups (it stores in your cloud)
  • High-risk sites needing a spotless plugin security record

Gotchas - check before you buy

high

Backup plugins are prime attack targets; this one has had unauthenticated file-upload and missing-authorization CVEs. Patch immediately.

medium

Backups land in your own cloud storage — you cover storage costs and manage access credentials.

medium

No vendor security page, so patch transparency is hard to assess.

medium

No pricing found in reviewed sources; verify current plans and renewal terms before buying.

Pros and cons

Pros

  • Backs up only changed files and DB tables, not the entire site
  • Stores backups in your own cloud: S3, Wasabi, Backblaze, Dropbox, or Google Drive
  • Includes staging and WordPress multisite backup support
  • Automatic backup before plugin and theme updates
  • Reviewers praise easy UI and pocket-friendly pricing

Cons

  • Unauthenticated arbitrary file upload vulnerability in v1.22.21 (CVE-2024-8856)
  • Missing authorization flaw in versions below 1.22.26
  • Subscriber-level users could download decrypted SQL database backups
  • Security bypass vulnerability flagged by multiple scanners
  • No security page published on vendor site

Sources & method

Analyzed 9/20/2026 - 13 sources - Multiple published vulnerabilities, including unauthenticated arbitrary file upload and missing authorization; fixed in versions at or above 1.22.26.

official x3review x4security x6
  • Unauthenticated Arbitrary File Upload (CVE-2024-8856), Version 1.22.21 allowed unauthenticated attackers to upload arbitrary files.
  • Missing Authorization (CVE-2026-42760), Versions below 1.22.26 affected per WPScan.
  • Database backup exposure, Authenticated attackers with subscriber-level access could download the most recently admin-decrypted SQL database.
  • Security bypass vulnerability, Reported by Acunetix and Invicti scanners against the plugin.

Key stats

  • Value for money: 4/5

    Rating

  • Not disclosed

    Starting price

  • 13

    Sources

  • Analyzed

  • Value for money: 4/5. Called 'pocket-friendly' by independent reviewer
  • Ease of use: 4/5. Reviewers cite an easy-to-use UI
  • Feature depth: 4/5. Incremental backups, staging, multisite, pre-update backups
  • Support quality. No support evidence in sources
  • Security posture: 1/5. Unauthenticated file-upload and auth-bypass CVEs
  • 2 CVEs cited CVE-2024-8856; CVE-2026-42760
  • Yes Free version Plugin listed on WordPress.org
  • 5 Cloud targets S3, Wasabi, Backblaze, Dropbox, Google Drive
  • Dec 2024 Most recent coverage Delicious Brains plugin roundup

Pricing

Free tier: Yes

Security

Multiple published vulnerabilities, including unauthenticated arbitrary file upload and missing authorization; fixed in versions at or above 1.22.26.

  • Unauthenticated Arbitrary File Upload (CVE-2024-8856)Version 1.22.21 allowed unauthenticated attackers to upload arbitrary files.⁸
  • Missing Authorization (CVE-2026-42760)Versions below 1.22.26 affected per WPScan.⁹
  • Database backup exposureAuthenticated attackers with subscriber-level access could download the most recently admin-decrypted SQL database.11
  • Security bypass vulnerabilityReported by Acunetix and Invicti scanners against the plugin.12

What users say

Reviewers call it an easy-to-use, affordable incremental backup plugin, though most third-party coverage dates from 2017–2018.

“It backs up and restores only the changed files & DB and not the entire site every time.”
WordPress.org plugin page
“WP Time Capsule is an excellent backup plugin with innovative features and an easy to use UI with a pocket-friendly pricing structure.”
WP Beaver Addons review
“The thing I like about WP Time Capsule Pro is that backups are not zipped up, but rather transferred individually to your cloud.”
Leokoo review
Full analysis

Based on 14 public sources; no pricing data found in reviewed pages; several reviews date to 2017–2018.

Solid incremental WordPress backups to your own cloud — but recent CVEs mean patch fast or pick another tool.

Methodology

Based on 14 public sources; no pricing data found in reviewed pages; several reviews date to 2017–2018.

Sources

  1. official
  2. review
  3. review
  4. review
  5. review
  6. official
  7. security
  8. security
  9. security
  10. security
  11. security
  12. security
  13. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.