=== Tiny Backup ===
Contributors: ejointjp
Tags: backup, database, files, zip, admin
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.5.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Simple and minimal backup plugin for WordPress. Create database and files backups manually or automatically on a schedule.

== Description ==

Tiny Backup is a WordPress plugin that allows you to create backup files simply and without any complicated configuration.
You can create and download the bare minimum backup with just one click, stress-free.

**Manual Backup**

- Database backup (SQL inside ZIP) with a single click
- Files backup from your uploads folder — select specific subfolders as needed
- Clear progress indicator during backup

**Auto Backup (WP-Cron)**

- Set separate schedules for database and files backups (daily / weekly / monthly)
- Configure time, day of week, or day of month for each schedule
- Manage retention: set max generations for database and files independently
- Email notifications on failure (sent to the admin email address)

**General**

- No external services required; everything runs on your server unless you enable the optional Dropbox integration
- Backup files are stored in `wp-content/uploads/tiny-backup-datas`, protected by an `.htaccess` file and randomized file names

This plugin is ideal for small to medium sites that need simple, low-overhead backups.

== Installation ==

1. Upload the plugin to the `/wp-content/plugins/` directory or install via the WordPress Plugins screen.
2. Activate the plugin through the 'Plugins' screen in WordPress.
3. Go to Tools → Tiny Backup.
4. Click "Database Backup" or "Files Backup" to run a manual backup, or configure Auto Backup settings.

== Frequently Asked Questions ==

= Where are backups saved? =

Backups are saved to `wp-content/uploads/tiny-backup-datas`. The plugin protects this folder with an `.htaccess` file (Apache / LiteSpeed) and an empty `index.php`, and every backup file name includes a random string so that it cannot be guessed.

If your server does not read `.htaccess` files (for example nginx), Tiny Backup shows a warning on its settings page. In that case, block the folder in your server configuration. For nginx:

`location ^~ /wp-content/uploads/tiny-backup-datas/ { deny all; }`

Temporary .sql and .part files left behind by an interrupted backup are deleted after one day. When you update from version 1.4.2 or earlier, existing backup files are renamed once to include a random string; their contents and dates do not change.

= Can I change the destination directory? =

Yes. Add the following to `wp-config.php` with an absolute path, preferably outside the public web folder:

`define( 'TNBU_BACKUP_DIR', '/path/outside/public/folder/tiny-backup' );`

Notes:

- The path must be absolute and writable by the web server.
- Tiny Backup does not add `.htaccess` or `index.php` to a custom folder, so choose a folder that is not reachable from the web.
- Existing backups are not moved. Move them by hand if you want to keep them in the new folder.

= Are scheduled backups supported? =

Yes. As of version 1.3.0, you can configure automatic backups for database and files independently using WP-Cron. Options include daily, weekly, and monthly schedules.

= Does scheduled backup run at the exact time I set? =

WP-Cron is triggered by site visits, so the actual execution time may differ slightly from the configured time on low-traffic sites. The backup will run on the next page load after the scheduled time.

= What folders can I select for file backup? =

You can select the entire uploads folder or individual subfolders directly under it. Subfolders of subfolders are not selectable.

Symbolic links inside the selected folders are followed, and the linked files are saved at the link's location in the ZIP file. Each folder is included only once, even if several links point to it or a link points back to a parent folder.

= Which database tables are backed up? =

Tiny Backup backs up the tables whose names start with your WordPress table prefix (`$table_prefix` in `wp-config.php`, `wp_` by default). Tables of other sites or applications in the same database are not included, so restoring a backup does not overwrite them.

If another site in the same database uses a table prefix that starts with yours (for example, `wp_` and `wp_shop_`), its tables are included as well.

= Does Tiny Backup work on WordPress Multisite? =

Yes, but only super admins can use it. Site administrators do not see the Tiny Backup menu.

A database backup contains every site in the network, so database backups (manual and automatic) run only on the main site. A files backup includes the uploads folder of the site where you run it.

== Screenshots ==

1. Settings screen — Select backup items from the uploads folder
2. Auto Backup settings — Configure separate schedules, retention, and email notifications for database and files
3. Backup screen — Run manual backups and manage backup files

== Changelog ==

= 1.5.1 =

- Security: On multisite, site administrators could download a database backup of the whole network, including the email addresses and password hashes of all users. Only super admins can now use Tiny Backup, and database backups run only on the main site
- Change: On multisite, Dropbox is disconnected once after updating. Reconnect it from Tools → Tiny Backup
- Change: Database backups now include only tables with your WordPress table prefix (`wp_` by default)
- Change: On multisite, a subsite now backs up only its own uploads folder
- Bug fix: Sites that keep uploads outside `wp-content/uploads` now back up their actual uploads folder
- Bug fix: Folders reached through symbolic links are now backed up. A symbolically linked uploads folder no longer breaks file names in the ZIP file or leaves the folder list empty
- Bug fix: Unreadable folders, files deleted during the backup, and special files such as named pipes are now skipped and recorded in the PHP error log instead of stopping the files backup
- Bug fix: When a manual backup fails, the error now stays on screen instead of disappearing on reload
- Error messages now say what went wrong and what to do next

= 1.5.0 =

- Security: Backup files could be downloaded directly from the web by anyone who guessed their file names. Every backup file name now includes a random string, and the backup folder is protected with an `.htaccess` file and an empty `index.php`. Existing backups are renamed automatically when you update
- New: Tiny Backup checks whether the backup folder can be read from the web (for example on nginx, which ignores `.htaccess`) and shows a warning with a configuration example on its settings page
- New: Define `TNBU_BACKUP_DIR` in `wp-config.php` to store backups outside the public web folder
- Temporary files left behind by an interrupted backup are deleted after one day, and a failed database dump no longer leaves a plain `.sql` file in the backup folder
- Bug fix: Automatic files backups beyond "Max files to keep" were never deleted from the server. They are now removed as intended

= 1.4.2 =

- Confirmed compatibility with WordPress 7.1
- Removed screenshot images that were accidentally bundled in the plugin package. The download is about 400KB smaller

= 1.4.1 =

- Confirmed compatibility with WordPress 7.0
- Internal code quality work to meet the WordPress Coding Standards. No changes to how the plugin behaves

= 1.4.0 =

- Show server backup destination path under the Backup files section
- Show Dropbox backup subfolder reference under the Backup files on Dropbox section

= 1.3.0 =

- Added auto backup feature using WP-Cron (daily / weekly / monthly)
- Database and files can be scheduled independently
- Configurable retention (max generations) per backup type
- Email notifications on success and/or failure
- Split manual backup into separate "Database Backup" and "Files Backup" buttons
- Limited file backup scope to uploads folder (direct subfolders selectable)
- Introduced wp-scripts build pipeline for admin assets

= 1.2.0 =

- Internal improvements and refactoring.

= 1.1.1 =

- Bug fix.

= 1.1.0 =

- Added an action link to the plugin list for quick access to the settings page.

= 1.0.0 =

- Initial Release.

== Upgrade Notice ==

= 1.5.1 =

Security update for multisite: only super admins can now use Tiny Backup, because site administrators could download a database backup of the whole network. On multisite, connect Dropbox again after updating. Also fixes several files backup problems and makes error messages clearer.

= 1.5.0 =

Security update: protects backup files from being downloaded directly from the web. Please update right away. On nginx, follow the warning shown on the Tiny Backup screen.

= 1.4.0 =

Minor UI improvements: backup destination paths are now shown in the backup file lists.

= 1.3.0 =

Auto backup, separate DB/files schedules, email notifications, and a redesigned backup UI are now available.
