=== Okleone Backups – Backup, Restore, Migrate, Encrypted Cloud Backups ===
Contributors: damjanfixit
Tags: backup, restore, migration, cloud backup, database backup
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 3.16.31
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Backup, restore and migrate WordPress. Encrypted backups, Dropbox and OneDrive with no app keys, and restores that verify before they touch.

== Description ==

Okleone Backups backs up your database and files into verified archives, restores them through a wizard that checks everything with a dry run first, and moves whole sites between domains without breaking serialized data. The features other plugins charge for are the point of the free version: encryption with a key only you hold, cloud storage connected in one click, and migration that actually works.

**Backups**

* Manual and scheduled backups, hourly to monthly, of your database, plugins, themes, uploads and other wp-content folders
* Built for large sites: archives are split into parts and written across many short requests, so a 4 GB site backs up on ordinary shared hosting where a single long request would be killed
* Every archive is checksum-verified after it is written, and again before it is restored
* Retention rules so old backups clean themselves up
* Email reports, either every backup or only the ones with a warning or an error

**Encryption, free, with your key**

Switch it on and every new backup is encrypted on your server with AES-256-GCM before it is stored anywhere, local disk included. You hold the recovery key; no storage provider, no host, and not Okleone Backups itself can read your archives. A standalone decrypt tool ships in the plugin folder, so even a site that no longer exists cannot lock you out of your own backups.

**Cloud storage without developer accounts**

Connect Dropbox or OneDrive by approving access on the provider's own consent screen. No app registration, no API keys to paste: our relay holds the app credentials so you never have to create developer apps, and your files travel directly from your server to the provider.

**Restores you can trust**

The restore wizard verifies the archives, then runs a dry preflight that reports exactly what would change before anything does. A restore that is interrupted resumes instead of starting over. Pick single components, the database alone, or everything.

**Migrate and clone**

Move a site to a new domain: URLs, paths and table prefixes are rewritten safely, including inside serialized data, which is where most search-and-replace tools corrupt a site. Take a full backup on one site, bring the package to another by cloud storage or upload, and press Migrate. Both directions are free.

**Housekeeping**

Database cleanup (revisions, transients, orphaned rows), file cleanup that shows where your disk actually went, a cron viewer, site info for support requests, and settings export/import.

**Premium**

The premium build adds, on top of everything above: incremental file backups (after the first full, each run carries only what changed, and a restore replays the chain for you), a staging site on your own server, Rescue Protection (an emergency console that keeps working when WordPress will not load, with crash pages that email you recovery credentials), a restore point taken automatically before plugin, theme and core updates, Amazon S3, Google Drive, Azure Blob, SFTP, FTP and S3-compatible services as storage targets, and 1 GB of managed WP-AllBackup Storage in Germany with every licence.

Premium is a separate build, WP-AllBackup, from your account at [wp-allbackup.fixit.biz](https://wp-allbackup.fixit.biz/); install it and your settings, schedules and restore points carry straight over.

== External services ==

The free plugin works without any account: backups, restores, scheduling, encryption, migration and the cleanup tools all run entirely on your server and contact nobody.

Two optional features talk to external services, and only when you use them:

**The WP-AllBackup auth relay and portal**, when you connect Dropbox or OneDrive. Pressing Connect registers your site with our portal (portal.fixit.biz), which issues the site a token; the relay (relay.fixit.biz) uses that token to hand your site the provider's access token after you approve access on the provider's own consent screen. We hold the provider app credentials so you do not have to create developer apps; we never see your files. What is sent: your site URL, the plugin version, and the token exchange itself. The same portal validates a licence key if you enter one. Our [privacy policy](https://wp-allbackup.fixit.biz/privacy.html) and [terms](https://wp-allbackup.fixit.biz/terms.html) describe both services.

**Dropbox and Microsoft OneDrive**, after you connect them. Backup archives are uploaded from your server directly to the provider's API, and deletions run there when retention removes an old backup. Their terms apply to what you store: [Dropbox privacy](https://www.dropbox.com/privacy), [Microsoft privacy](https://privacy.microsoft.com/).

== Installation ==

1. Install through the WordPress plugins screen, or upload the plugin folder to `/wp-content/plugins/okleone-backups/`.
2. Activate it through the Plugins screen.
3. Open the backup menu and press Backup Now. The local backup directory works out of the box, automatic backups are off until you switch them on in the policy, and the Targets tab adds cloud destinations when you want them.

== Frequently Asked Questions ==

= Where are backups stored? =

On a fresh install, in a `wpab-backups` folder beside your web root when the server lets the plugin write there, which no web request can reach; otherwise in `wp-content/wp-allbackup-backups`, protected from direct download. Settings > Backup directory shows the folder in use and lists the alternatives. Optionally on every connected remote storage target as well.

= How do I make sure my backups cannot be downloaded over the web? =

Okleone Backups ships an `.htaccess` and a `web.config` that block direct access on Apache and IIS, and it takes the world-readable bits off the folder and its files so a web server running as a different user cannot serve them. It also checks, from the plugin, whether the folder actually refuses a real HTTP request, and shows a warning if it does not.

nginx, Caddy and LiteSpeed do not read `.htaccess`, so on those you must add the rule yourself. For nginx, inside the site's `server { }` block:

`location ~* /wp-content/wp-allbackup-backups/ { deny all; return 403; }`

The most robust option on any server is to move the backup folder outside your web root entirely: set an absolute path in Settings under "Backup directory" and the archives you already have are moved with it. If your hosting gives you nothing above the web root, keep the default and add the server rule above.

= Are my backups encrypted? =

If you want them to be. Under Settings > Encryption, switch it on and every new backup is encrypted on your server before it goes anywhere, local disk included. You are shown a recovery key once; write it down somewhere that is not this site, because it is the only way to read these backups elsewhere and nobody, Okleone Backups included, can recover it for you. Restores decrypt as they read, and `bin/wpab-decrypt.php` in the plugin folder decrypts an archive on any machine with PHP.

= Do I need API keys for Dropbox or OneDrive? =

No. Cloud connections run through the WP-AllBackup auth relay: you approve access in the provider's own consent screen and tokens are delivered to your site server-to-server. See the External services section for exactly what travels where.

= Will it back up a large site on shared hosting? =

Yes, that is what the split-archive design is for. Archives are written in parts of a configurable size, one short request at a time, with the backup saved after every part; a request that is killed costs one part and the next request carries on. The same slicing applies to verification and uploads.

= What is a full backup here, and what is incremental? =

Every file backup the free plugin takes is a full one, so any backup can stand on its own and be migrated on its own. Incremental file backups, where each run after the first carries only what changed, are part of premium; a chain made there restores on any plan.

= Can I restore a site that no longer loads? =

That is Rescue Protection, part of the premium build: an emergency console installed under a randomized name that loads nothing from WordPress, plus crash pages that email you recovery credentials when the site goes down. The free plugin restores through wp-admin, and encrypted archives can always be decrypted off-site with the bundled tool.

= What happens to my backups if I uninstall the plugin? =

Backup archives are left untouched. Settings, history metadata and schedules are removed.

= What does premium add, and what happens to my data if I upgrade? =

Incremental backups, staging, Rescue Protection, pre-update restore points, the S3, Google Drive, Azure, SFTP, FTP and S3-compatible targets, and 1 GB of managed storage. Premium is the WP-AllBackup build, from your account; install it and settings, schedules and restore points carry straight over.

== Screenshots ==

1. Backup and Restore: one screen for taking a backup and for the restore points you already have.
2. The restore wizard's dry run reports what would change before anything does.
3. Targets: local disk plus Dropbox and OneDrive, connected without developer apps.
4. Policies: schedules from hourly to monthly with retention and backup windows.
5. Encryption: switched on once, with the recovery key only you hold.
6. Migrate / Clone: three steps, with the dry run before the site changes.

== Changelog ==

= 3.16.31 =
* Maintenance release.

= 3.16.30 =
* Bug fixes for encrypted backups and diagnostic reports.

= 3.16.29 =
* Bug fixes and improvements to backup policies.

= 3.16.28 =
* Improvements to the Licence tab.

= 3.16.27 =
* Smoother upgrade to the premium build.

= 3.16.26 =
* Bug fixes in Settings.

= 3.16.25 =
* Clearer wording in Settings.

= 3.16.24 =
* Bug fixes in the restore point list.

= 3.16.23 =
* Backup reliability fixes.

= 3.16.22 =
* Bug fixes and improvements to the Licence card.

= 3.16.21 =
* Bug fixes.

= 3.16.20 =
* Restore reliability fixes.

= 3.16.19 =
* Clearer delete confirmations for restore points.

= 3.16.18 =
* Minor improvements.

= 3.16.17 =
* Bug fixes for imported backups and small screens.

= 3.16.16 =
* New: filters and page links on the Migrate tab.

= 3.16.15 =
* Bug fixes.

= 3.16.14 =
* New: migrations turn off caching plugins, and a site that is down after a restore gets recovery steps.

= 3.16.13 =
* Bug fixes for restore points.

= 3.16.12 =
* Bug fixes for storage targets and policies.

= 3.16.11 =
* New: a fresh install keeps backups outside the web root where possible and starts with automatic backups off.

= 3.16.10 =
* New: the Backup directory setting suggests safe places on this server to keep backups.

= 3.16.9 =
* Bug fixes.

= 3.16.8 =
* Security hardening and faster restores.
