=== Stalza Backup ===
Contributors: fuadkm
Tags: backup, restore, recovery, verification, schedule
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.10
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Lightweight, resource-aware, verifiable WordPress backup and recovery.

== Description ==

Stalza Backup protects your WordPress site with chunked, resumable backups, integrity verification, and safe restore — without unnecessarily overloading your server.

**Free includes**

* Manual backups: full, database, files, or media
* Daily / weekly schedules with retention and exclusions
* Local protected storage + download
* Verification and backup manifests
* Restore with pre-restore safety snapshot
* WP-CLI for backup, restore, schedule, and jobs (including `wp stalza-backup job worker` to run backups back-to-back)

**Core principles**

* A backup is not successful until verified
* Restore is as important as backup
* Local backup works without an external account
* Free version is genuinely useful

== Installation ==

1. Upload the `stalza-backup` folder to `/wp-content/plugins/`
2. Activate the plugin through the Plugins menu
3. Open **Stalza Backup** in the admin menu

== Frequently Asked Questions ==

= Does Free require a cloud account? =

No. Local storage and download work without any external account.

= Is verification Free? =

Yes. Verification and backup manifests are core Free features.

= How do scheduled backups run? =

Through WordPress cron (`stalza_backup_cron_run`). On hosts where WP-Cron is unreliable, trigger it with a real system cron calling `wp cron event run`.

== Screenshots ==

1. Overview — protection status, stats, Backup Now, and recent backups
2. Backup history — download, verify, restore, and delete
3. Restore — restore from a verified backup with safety snapshot
4. Schedules — daily/weekly schedule, retention, and exclusions
5. Storage — local storage path and disk usage

== Changelog ==

= 1.0.10 =
Bug Fixes:

* Allow deleting any backup after confirm (no longer block the last verified backup).
* Large imports use a light structure check so multi-GB uploads finish; treat completed imports as restorable.
* Restart orphaned chunked uploads after wiped import sessions; treat Cloudflare 5xx/520 HTML as transient during job polling.

= 1.0.8 =
Bug Fixes:

* Large backup downloads no longer die mid-transfer: download tokens scale with file size (up to 24h) so browser resumes stay valid.
* Stream multi-GB backups to disk via Chrome/Edge save dialog (Range chunks + retries) instead of assembling the zip in RAM.
* Harden PHP download streaming (8 MiB chunks, disable nginx buffering, release session lock) and block in-memory fallback above 100 MiB.

= 1.0.9 =
Bug Fixes:

* Chunked backup import uploads (2 MiB slices) so large zips no longer hit nginx/PHP single-request body limits (413).

= 1.0.7 =
Features:

* Signed admin download links (short-lived HMAC tokens) for faster native browser downloads without public static zip URLs.
* Resumable native SHA-256 checksum phase for large archives (HashContext across ticks, pure-PHP fallback).

Performance:

* Archive phase respects a per-tick byte budget so zip close stays within proxy/time limits.
* Admin UI prefers native download when a signed link is available, with chunked Range fallback.

Bug Fixes:

* After restore, reset foreign `stalza_backup_storage_path` / upload paths that point outside the destination install.
* Clear PHPStan findings in job runner / hasher paths; Plugin Check ERROR-clean on free build.

= 1.0.6 =
Bug Fixes:

* Stop writing `$wpdb->prepare()` `%` placeholder hashes into SQL dumps (Elementor `settings="%7B%7D"` / site-logo fatals).
* Exclusive job lock so admin ticks and WP-Cron cannot double-append `filelist.txt`.
* Heal prepare-placeholder corruption on restore and rewrite absolute URLs in uploads CSS (Elementor google-fonts CORS).
* Remap option/usermeta keys and unknown collations when restoring custom table prefixes.
* Stream large zip downloads with Range support; clear Plugin Check ERROR/WARNING findings.

Features:

* Stronger site-to-site restore: prefix rewrite, serialize-safe URL remap, JSON-escaped URL pairs, and uploads text-file remaps.

= 1.0.5 =
Bug Fixes:

* Set WordPress.org Contributors to valid username `fuadkm`.

= 1.0.4 =
Features:

* Site-to-site restore: automatic table-prefix rewrite and serialize-safe URL remapping when source and destination differ.
* Restore-completed modal with Go to login (sessions are usually reset after DB restore).

Bug Fixes:

* Dump pagination uses `ORDER BY` primary/unique key so large tables do not emit duplicate PKs.
* Persist SQL restore offset mid-tick and rewrite `INSERT` to `REPLACE` so resume cannot fail on Duplicate entry.
* Restore ticks survive session wipe via tick token (omit stale REST nonce; clear cookie check when token present).
* Harden staging cleanup and prune missing `active_plugins` after restore so incomplete plugin copies cannot fatal the site.

Full history: https://stalza.com/docs/stalza-backup/changelog
