The Clone plugin for WordPress is not secure and could potentially allow attackers to change data without permission. This is because the wpa_wpc_ajax_install_new() function does not have a check to make sure the user has the proper capabilities. This means that someone who is logged in and has at least subscriber-level access could install a backup plugin without authorization.