外掛說明
The UpdraftPlus Backup & Migration Plugin 深受 WordPress 社群信賴,能備份、還原及移轉 WordPress 網站。UpdraftPlus 目前已在全球超過 300 萬個網站上啟用。
使用 UpdraftPlus 備份
UpdraftPlus 是全球排名最高且最受歡迎的排程備份與移轉外掛。備份至您偏好的儲存空間,並只需三次點擊即可還原。
備份至 Dropbox、Google Drive、Amazon S3(或相容服務)、Rackspace Cloud、FTP、DreamObjects、Openstack Swift 或電子郵件。
付費版也可備份至 Microsoft OneDrive、Microsoft Azure、Google Cloud、Backblaze B2、SFTP、SCP、pCloud、WebDAV 或 UpdraftVault;UpdraftVault 是 UpdraftPlus 的整合儲存空間選項。
手動備份,或排程每 2、4、8 或 12 小時、每天、每週、每月或每兩週執行。
使用 UpdraftPlus 還原
您的 WordPress 網站存在弱點,可能會遭到駭客入侵。更新可能發生問題,或伺服器可能當機。您可能需要還原所做的變更,或修正人為錯誤造成的問題。
無論原因為何,您只需在 UpdraftPlus 中按幾下即可還原 WordPress 網站。選擇要還原的元件(例如外掛、佈景主題、資料庫等),再次按一下進行還原,然後再按一下返回主畫面。
使用 UpdraftPlus 移轉
使用 UpdraftPlus 免費版,您可以輕鬆將 WordPress 網站移轉至其他網頁主機、伺服器或網域。
若要移轉,只要從來源網站下載資料庫、外掛、佈景主題等內容,再上傳至目的地網站即可。
移轉時,內建的搜尋取代引擎會找出舊字串,並將其取代為反映新位置的字串。UpdraftPlus 能為您節省時間,並降低手動移轉可能造成連結失效或檔案遺失的風險。
為什麼選擇 UpdraftPlus?
要撰寫一套能在數百萬個不同 WordPress 部署環境中持續「正常運作」的可靠備份與移轉外掛並不容易。我們的外掛在全球獲得信賴並實際部署於比任何其他 WordPress 備份與移轉外掛更多的網站。
UpdraftPlus:
- 備份、移轉及還原
- 提供大量遠端儲存空間選項
- 可排程備份,讓您可以「設定後不必再費心」
- 功能完整且易於使用
- 已證實可在超過 300 萬個網站上運作。
UpdraftPlus Premium
UpdraftPlus 免費版能夠妥善備份及移轉您的網站。不過,如果您需要更多功能和選項,可以購買 Premium 版。
使用 UpdraftPlus Premium 備份及移轉,還可:
-
在更新前自動備份。若 WordPress 或外掛更新導致網站故障,還原至最新版本。
-
以增量方式備份。變更會新增至主備份,與重複進行完整備份相比,可節省伺服器資源。
-
取得更多遠端儲存空間選項,包括 Microsoft OneDrive、SFTP、Microsoft Azure、WebDAV、Google Cloud、SCP、Backblaze 及 pCloud。
-
透過 UpdraftVault 取得 1GB 的整合儲存空間,享有 99.999% 的可靠性、備援能力與擴充性。
-
更能控制在指定時間間隔內儲存的備份數量。
從其他備份外掛(包括 BackWPup、BackupWordPress、Simple Backups 等)還原。 -
在指定時間執行備份,例如流量較低的時段。
-
備份至多個位置,以獲得額外保護。
-
取得詳細報告。包含加密校驗碼,讓您可以驗證備份檔案的完整性,還有更多資訊。
-
取得 Premium 移轉功能。移轉至目的地網站的流程更直接,且可從來源網站完成。
-
具備 Multisite/多網路相容性。
-
備份非 WordPress 檔案及資料庫,例如電子商務商店所用的資料表,或 WordPress 核心的自訂內容。
-
取得資料庫加密功能。
-
從 WP-CLI 管理備份與移轉。
-
取得 Premium 支援。
如需進一步了解,請參閱我們的比較頁面。UpdraftPlus Premium 可在這裡購買。
要管理多個網站嗎?
UpdraftCentral 是功能強大的 WordPress 遠端控制儀表板,可讓您從單一中心位置管理備份,以及更新、使用者、頁面、文章、外掛和佈景主題。請選擇:
- UpdraftCentral (免費、自行託管)
- UpdraftCentral Premium (付費、自行託管)
- UpdraftCentral Cloud (付費、完整代管)
結合 WP-Optimize 與 UpdraftCentral 的功能,集中最佳化您的網站;或結合 UpdraftPlus 與 UpdraftCentral 的功能,集中管理您的備份。
需要建立網站的暫時複本嗎?
UpdraftClone 可快速輕鬆地建立暫時的沙盒,供您測試想進行的變更。只要選取所需的 WordPress 和 PHP 版本,其餘工作交給我們。進一步了解 UpdraftClone
Team Updraft 與合作夥伴提供的完整外掛套件
-
UpdraftPlus。
備份、移轉及還原。在外掛目錄中獲評 5*,並獲全球超過 300 萬名 WordPress 網站擁有者信賴 -
WP-Optimize。
清理資料庫、壓縮圖片並設定快取。最佳化您的 WordPress 網站。使用者評分 5*。活躍安裝數超過 100 萬。 -
All-In-One Security (AIOS)。保護您的 WordPress 網站。功能完整、功能豐富且易於使用。使用者評分 5*,活躍安裝數超過 100 萬。
-
WP Overnight。
WooCommerce 商店的高品質擴充功能。獲評 5* 的發票、訂單與產品管理、客戶管理解決方案,以及更多功能。 -
Easy Updates Manager。掌控更新。提供許多免費功能,以及功能更多的 Premium 版本—已有超過 300,000 名使用者。
-
Internal Link Juicer。提升您的 SEO。自動在您的 WordPress 網站中建立內部連結。節省時間,並在搜尋引擎中獲得更高排名。
如需其他實用的免費外掛,請參閱我們首席開發人員的個人檔案。
您是多語使用者嗎?可以協助翻譯嗎?
您想協助使用您語言的人備份、移轉及還原他們的 WordPress 網站嗎?
UpdraftPlus 備份、移轉及還原外掛已準備就緒。翻譯流程簡單,且可透過網頁進行;如需操作說明,請前往:https://updraftplus.com/translate/。
或者,如果您已是 WordPress 翻譯專家,只要從 wp-content/plugins/updraftplus/languages/ 目錄中取出 .pot 檔案即可;如果您要手動掃描可翻譯字串,則需要尋找以下函式:_x(), __(), _e(), _ex(), log_e().
非常感謝現有的翻譯人員。
授權
Copyright 2011-24 David Anderson
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program; if not, write to the Free Software
Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
非英文語言的翻譯由志工提供,且 wordpress.org 不會讓外掛開發者控制翻譯內容;因此依賴這些翻譯的風險由您自行承擔;UpdraftPlus 無法保證從原始英文翻譯而來的內容準確。
我們謹此向 https://updraftplus.com/acknowledgements/ 所列的人員致意並致謝,感謝他們的程式碼及/或程式庫依開放原始碼授權條款供我們使用及/或修改。
常見問題集
如何安裝 UpdraftPlus 備份 & 移轉外掛?
以下是我們從YouTube 頻道或從網站提供的安裝指南。
如果遇到問題/需要支援,該怎麼辦?
如果您在備份、移轉或還原時遇到困難,這裡可以取得協助。
在 WordPress 支援論壇中搜尋現有主題,或發表新主題。我們的支援與開發團隊每天都會查看並回覆問題。
UpdraftPlus Premium 客戶可以透過UpdraftPlus 支援中心,直接向我們的支援與開發團隊提交工單。
聯絡我們之前,請先確認您已閱讀常見問題,並已將外掛更新至最新版本。
如果您能在報告中附上備份記錄及盡可能多的其他資訊,將會很有幫助,例如 PHP 版本、網站、錯誤說明、您如何進入導致問題的頁面、已安裝的其他相關外掛,以及其他可能有用的資訊。
尋找備份記錄的方法:UpdraftPlus 外掛的設定頁面上有下載記錄的連結,也可能會透過電子郵件寄給您。如果仍找不到,請使用 FTP 進入 wp-content/updraft 目錄,在其中尋找備份記錄。
如果您知道如何操作,請傳送 PHP 錯誤記錄—只要傳送執行備份時出現的幾行內容即可,這些內容通常位於名為 error_log 的檔案中;您可以透過 FTP 在 wp-admin 目錄中尋找該檔案。如果您是能夠進行偵錯並提交修補程式的程式設計師,那就更好了。
使用免費外掛進行移轉時,需要先從來源網站下載備份,再將備份上傳至目的地網站。
尋找備份記錄的方法:UpdraftPlus 設定頁面上有下載記錄的連結,也可能會透過電子郵件寄給您。如果仍找不到,請使用 FTP 進入 wp-content/updraft 目錄,在其中尋找備份記錄。
免費版與 Premium 版外掛都內建搜尋取代引擎,可將舊字串取代為新位置的字串。
如果您只需要移轉功能,對簡單的單一網站移轉而言,免費外掛可能就足以滿足需求。如果您對備份有其他需求,例如需要在更新前備份、需要更多遠端儲存空間,或使用 WordPress Multisite,我們建議使用 UpdraftPlus Premium,以取得其帶來的額外優點。
UpdraftPlus 備份時逾時,即使我已讓它執行了一段時間,給它充分完成備份的機會。我可以怎麼辦?
這個問題可能是因為您的(廉價)網頁主機供應商讓您的帳戶資源不足所造成。這並不理想;雖然 UpdraftPlus 支援從備份開始就分段執行,避免所有工作必須一次完成,但仍有其限制。最好的做法是選擇更值得信賴的網頁主機。若無法這麼做,請嘗試前往「Expert settings」,降低 zip 檔案分割大小。已知 UpdraftPlus 能在資源未受限制的網頁伺服器上,成功備份容量達數 GB 的網站。
使用者評論
參與者及開發者
以下人員參與了開源軟體〈UpdraftPlus: WP 備份及移轉外掛〉的開發相關工作。
參與者變更記錄
The UpdraftPlus backup blog is the best place to learn in more detail about any important changes.
N.B. Paid versions of UpdraftPlus Backup / Restore have a version number which is 1 higher in the first digit, and has an extra component on the end, but the changelog below still applies. i.e. changes listed for 1.16.32.x of the free version correspond to changes made in 2.16.32.x of the paid version.
= 1.26.8 – 17/Sep/2026
- SECURITY: On a site which has been migrated (i.e. moved to a new address using UpdraftPlus’s migration feature), and is using an .htaccess file, and the .htaccess file has not been updated with the new site reference, and where the site owner does not respond to the notice to do so, and where the site has non-admin users who can login to the WP dashboard, and where the site had saved storage login credentials in the UpdraftPlus settings, such a logged-in user could access some of those credentials (e.g. could access FTP, but not Dropbox). Thanks to Jakub Herman for notifying us of this issue (via WPScan).
- FEATURE: Implemented an onboarding wizard to assist first-time users with plugin configuration (requires WordPress 6.2+ and PHP 7.4+).
- FIX: Error caused by the FTP wrapper referencing the STDIN constant when configuring the cURL CURLOPT_INFILE option. Since STDIN is only defined under the PHP CLI SAPI, this caused failures in PHP-FPM environments.
- FIX: WebDAV backup failures caused by a deprecated regular expression escape since PCRE2 version 10.45.
- TWEAK: The “Tour” functionality has been removed from the UI and deactivated. Its underlying code remains temporarily and will be fully removed in a future release.
- TWEAK: Remove bundled translations which are now complete and automatically downloaded from wordpress.org
- TWEAK: Added an admin notice to inform users about the upcoming retirement of legacy Azure Blob Storage accounts.
- TWEAK: Warn sites running PHP older than 5.6.1 that phpseclib-dependent features (Dropbox, SFTP/SCP, Database Encryption, UpdraftCentral, Migrator) will require a newer PHP version in future releases; the dashboard notice is also shown again to users who dismissed the previous version of this notice.
- TWEAK: Update all text labels to use teamupdraft.com instead of updraftplus.com.
- TWEAK: Fixed the ‘Bad filename format’ error when uploading small backup files via the UpdraftPlus dashboard on older WordPress versions.
- TWEAK: Clarifying WebDAV settings test popup when server does not support chunked uploads.
- TWEAK: Addressed several issues identified during Plugin Check (PCP) validation and improved overall plugin compatibility and code quality.
1.26.7 – 21/Aug/2026
- SECURITY: Restoration now requires provision of a nonce, and not only the epoch-second timestamp of a backup. This prevents an insider threat in which a previous administrator who has been removed from a site could seek to persuade a logged-in current administrator to follow a link to restore a backup which he had previous knowledge of. Thanks to Jashid Sany for raising this issue (via WPScan).
- TWEAK: In UpdraftPlus Premium, for scheduled monthly backups, change the behaviour to backup on the chosen day every month (better matching user expectation).
- TWEAK: UpdraftClone no longer supports clones launched with PHP 5.4 or 5.5.
1.26.6 – 23/Jul/2026
- FEATURE: Upon plugin deactivation, a popup will appear with data removal options, enabling users to opt-in to deleting saved data.
- FIX: “Unattached” media filter lists attached images when no unattached items exist
- TWEAK: Added Burst Statistics to TeamUpdraft family admin notices.
- TWEAK: Create a better UX for free users around premium remote storage locations
- TWEAK: Prefer http_get_last_response_headers() (PHP 8.4+) to avoid PHP 8.5 deprecation warnings for $http_response_header.
- TWEAK: Replace the calls to the native PHP ‘unserialize()’ function in the Google Drive and HTTP_Request2 libraries.
1.26.5 – 05/Jun/2026
- SECURITY: Previous versions contained a defect allowing sites with an active Migrator key (paid versions only) or UpdraftCentral key (free and paid versions) to have unauthorised operations carried out on them. All users should update immediately.
- TWEAK: Added explicit HTTP timeout of 60 seconds to pCloud chunk upload requests to prevent cURL error 28 on slow server connections
- TWEAK: Guard curl_close(), finfo_close() and xml_parser_free() calls with a PHP version check to prevent deprecation warnings on PHP 8.5+
- TWEAK: Update the bundled common-libs version
- TWEAK: Replace all usages of wpdb::esc_like() with UpdraftPlus_Database_Utility::esc_like() across the codebase to maintain consistency.
- TWEAK: Add “auto-backup before update” tour guide
1.26.4 – 07/May/2026
- FIX: In version 1.26.2, a regression prevented the backup schedule, including the day name or number, as well as backup entity exclusion rules, from being saved.
- TWEAK: Alert users who wrongly enter URLs instead of an actual hostname for SFTP and FTP remote storage.
- TWEAK: Updated DreamObjects endpoints by removing the deprecated objects-us-west-1, marking objects-us-east-1.dream.io as unavailable (Nov. 12th, 2025), and adding admin notices to inform users of this change.
- TWEAK: get_structured_data() now accepts params to avoid timeouts.
1.26.3 – 23/Apr/2026
- FEATURE: Implemented enhanced streaming extraction for large files during restoration to handle cases where the file size exceeds the PHP memory limit.
- FIX: Fix users role filter empty state shows generic “Failed to Fetch Data” error.
- FIX: Fixed backup failures on tables with invisible columns and large data volumes.
- FIX: Unable to uncheck all categories on post in UDC dashboard
- TWEAK: Added a new internal command to get given plugins’ installation info.
- TWEAK: Ensure autobackup notice is always a string to prevent PHP 8.1+ deprecation in wp_kses()
- TWEAK: Fix the JS errors that occur when deleting the last generated UDC keys.
- TWEAK: Implemented adjustments for UI misalignment issues caused by the WordPress 7 visual design refresh across the admin dashboard. The plugin’s interface now aligns correctly with the updated design standards.
- TWEAK: Prevent broken settings pages in other plugins in multisite when UpdraftPlus is active due to modified menu URLs.
- TWEAK: Update all links in the addons folder to use teamupdraft.com instead of updraftplus.com.
- TWEAK: Replaced esc_html_e() with esc_html__() where string concatenation was silently discarding the colon separator in SFTP connection failure message and noscript JavaScript warning notice
- TWEAK: Switched to native phpseclib API/function for Dropbox token decryption, replacing deprecated mcrypt_decrypt since PHP 7.1 and removed in PHP 7.2.
- TWEAK: Clear out PHP “Undefined offset” notice that occurred while restoring a backup of single site to multisite. It happened during the search-replace operation due to the absence of the users and usermeta tables.
- TWEAK: Enhance the unzip file function to handle more folder inclusion/exclusion
- TWEAK: Update all links in the methods folder to use teamupdraft.com instead of updraftplus.com.
- TWEAK: Add post status and date fields to get_posts API response for UDC
1.26.2 – 03/Mar/2026
- TWEAK: Added PHP 8.5 support to UpdraftClone
- TWEAK: Fix deprecation warnings in PHP 8.4 for the Dropbox integration
- TWEAK: Make abort backup warning icon responsive with percentage-based sizing
- TWEAK: Prevent the suppressed PHP warnings from being output in the backup and restore log on PHP 8.0+
- TWEAK: On a site where the site owner has restricted (super-)administrators (so that they can’t restore backups), require a constant to first be set to use the HTTP debug tool for internal IP addresses.
- TWEAK: Update all links in the settings folder to use teamupdraft.com instead of updraftplus.com.
- TWEAK: When deleting backup sets created through a direct site-to-site migration, the ‘Also delete from remote storage’ checkbox is unnecessary.
1.26.1 – 19/Jan/2026
- FIX: Google Drive chunked uploads didn’t resume from where it left off but started from the beginning resulting in file duplicates
- TWEAK: Add a WP-CLI command to register a product key (premium)
- TWEAK: Add product registration link on the premium version
- TWEAK: Fix JS error on UpdraftCentral Cloud connect modal.
- TWEAK: Fix grammatical error in the low disk space admin notice.
- TWEAK: Update links for better user experience
- TWEAK: Update the premium links on the settings page
- TWEAK: Update all links in the includes/notices/central folders to use teamupdraft.com instead of updraftplus.com.
- TWEAK: Upgrade the common-libs tag version
1.25.9 – 12/Nov/2025
- FIX: A regression that resulted in the list of tables within the “Database size” tools not being displayed, due to code refactoring implemented in version 1.25.8.
- TWEAK: Add function for returning Advanced Tools menu data in a structured format.
- TWEAK: Resolve regression in 1.25.2 which caused the admin notice “Not yet connected to licence” was linking to teamupdraft.com instead of the UpdraftPlus Premium/Extensions tab.
- TWEAK: Refactoring connection keys data function to deduplicate and read from a single source
- TWEAK: Restored the missing backup confirmation pop-up icon for older WordPress versions.
- TWEAK: Stripped unwanted HTML from the plain-text notice and added new lines after each sentences in the sale offer message.
- TWEAK: Update Black Friday seasonal sale URL/link
- TWEAK: Updated “Check our premium” and “Back up non-WP tables and external databases” URL links to avoid HTTP 404 (not found) errors.
- TWEAK: Update database charset detection to support both CHARSET= and CHARACTER SET syntax in SQL dumps
- TWEAK: Replaced deprecated (boolean) casting
1.25.8 – 07/Oct/2025
- FIX: A fatal error in UpdraftCentral when trying to manage posts when no posts exist.
- FIX: During a failure in the file copy process while restoring, a directory was created with the same name as the file, and the restoration process persisted when it ought to have been stopped
- FIX: PHP fatal error in WP CLI commands for listing or scanning existing backups on PHP 8.0+ after a rescan
- TWEAK: Add UpdraftCentral support to import_settings function with return values
- TWEAK: Add support for new Amazon AWS S3 regions
- TWEAK: Added Burst Statistics to the family plugin list
- TWEAK: Adjust the backup logic to recognize invisible columns, and when that occurs, use a query that explicitly specifies the required columns instead of relying on “SELECT *”.
- TWEAK: Ensure the restore process terminates with an error when file copying/moving fails
- TWEAK: Improve the backup email report to better reflect the backup types and status.
- TWEAK: New endpoint for getting locked settings data for UpdraftCentral
- TWEAK: Perform a search and replace on __PHP_Incomplete_Class to make it work with unserialize() when object deserialization is not allowed.
- TWEAK: Refactoring site info section to deduplicate and read from single source
- TWEAK: Resolved a PHP warning triggered when uploading the plugin via the WP Plugins page — caused by translation functions (e.g. __()) being called too early.
- TWEAK: Some text was left out of the translation POT file, which meant that certain translator plugins and libraries could not find the text, making it impossible to translate.
- TWEAK: Update the db_size function to allow returning either data or html, depending on the argument that is passed in.
1.25.7 – 07/Aug/2025
- FIX: A regression for verifying the presence of old folders in the backup directory; old folders created during the restoration of the “Others” entity were not detected correctly.
- FIX: The per-backup lock entries were not removed, resulting in an accumulation of these entries in the database over time. (Includes clean-up of old entries).
- TWEAK: Add IDrive e2 and MEGA to the S3-Compatible storage list
- TWEAK: Internal function call to prevent a PHP 8.1 deprecation notice on fresh WP installs
- TWEAK: Add wp-staging to the default uploads exclusion list
- TWEAK: Add UpdraftCentral handler for site icon upload request.
- TWEAK: Added support for the database view dashicon in WordPress versions prior to 5.5.
- TWEAK: Include site icon information in the ‘get_site_icon’ response of the UpdraftCentral core module.
- TWEAK: Resolve the empty list issue on the backup email reports created by the UpdraftPlus free version
- TWEAK: The “Get every feature of UpdraftPlus Premium” box shouldn’t be displayed after purchases got claimed/activated
- TWEAK: Remove seasonal (new year, summer, spring and plugin collection) sale notices
- TWEAK: Handle unsupported character set defined for table fields during database pre-restoration.
- TWEAK: Updated links in the Premium Extensions tab of the plugin’s admin menu page.
1.25.6 – 27/May/2025
- FIX: A regression that prevented the remote storage label from being updated
- FIX: A regression that could cause unintended behaviour when restoring special files
- FIX: A fatal error when executing a standalone php backup script with “do_action(‘updraft_backup_all’)”.
- FIX: Regression that caused certain features (e.g. PHP Info) to break due to a missing HTML attribute on the triggering element
- FIX: An issue that caused migration failure for sites using the Performance Lab plugin or other plugins implementing an object cache drop-in
- TWEAK: handle non fatal file rename failure during restore
- TWEAK: The automatic backup feature is now disabled by default on new installs
- TWEAK: return post status and formatted date from UDC post API
- TWEAK: Replace a call to unserialize() in the Dropbox storage library
- TWEAK: Validate the DreamObjects endpoint to ensure only expected DreamObjects enpoint formats can pass through.
- TWEAK: Position the “includes all tables not listed below” option at the beginning of the first known table in the DB restoration widget.
- TWEAK: Add a new default endpoint in DreamObjects along with UI to allow users to add custom endpoint in the format “s3..dream.io”.
- TWEAK: The Azure Storage Service add-on now requires PHP 5.6 or higher to support the mandatory use of TLS 1.2, which will be enforced starting August 31, 2025.
1.25.5 – 17/Apr/2025
- FIX: A bug that prevented the Rackspace “Create new API user and container” dialog from opening.
- TWEAK: An HTTP header intended to terminate the browser’s connection was incorrectly assigned a value that the header does not support.
- TWEAK: Ability to automatically choose the proper checkout page when the user is about to buy TeamUpdraft products from within the plugin
- TWEAK: Clear Divi theme CSS cache at the end of the restoration process
- TWEAK: Resolve PHP warning in pCloud addon when upgrading from free to premium version.
- TWEAK: Update error messages when the user fails to connect to their TeamUpdraft account on the ‘Premium/Extensions’ tab.
1.25.4 – 24/Mar/2025
- FIX: Regression in 1.25.3 – missing database encryption input field due to the use of the “wp_kses_post” function that doesn’t allow “” tag to be rendered
- TWEAK: Add new fields to UpdraftCentral handler
1.25.3 – 21/Mar/2025
- FIX: An issue that prevented an UpdraftClone backup from sending when attempting to boot an UpdraftClone from WP_CLI
- FIX: An issue that prevented changing the default UpdraftClone region when attempting to boot an UpdraftClone from WP_CLI
- TWEAK: The “x-amz-content-sha256” request header is now signed and included in the S3 signature version 4. Some S3-based providers mandate the signing of this header for accurate signature calculation.
- TWEAK: Introduce a new constant named “UPDRAFTPLUS_S3_EXCLUDE_SIGV4_CONTENT_SHA256_HEADER”. This constant allows for the exclusion of the “x-amz-content-sha256” headers from being signed if desired; it accepts a boolean value, defaulting to false.
- TWEAK: Add ‘noopener, noreferrer’ window features to the Javascript’s window.open() call to prevent the target page from changing content of the original page
- TWEAK: Favicon fetching feature for UpdraftCentral
- TWEAK: Minor tweak to “updates” module to include icons to plugin and screenshot url to theme update items
- TWEAK: New UpdraftCentral module for background fetching
- TWEAK: Revise the wording found in the expert settings regarding the deletion of local backup files
- TWEAK: Update seasonal notices
- TWEAK: Enhance the notifications to signify the introduction of other plugins that belong to the same plugin family
- TWEAK: To avoid CORS issues and ensure the UpdraftPlus plugin is functional and accessible via the UpdraftCentral dashboard, the hostname and/or domain origin is changed from updraftplus.com to teamupdraft.com.
- COMPATIBILITY: Resolved PHP deprecation warnings in lockadmin.php by eliminating the use of dynamic properties
1.25.2 – 26/Feb/2025
- FEATURE: Added a “Cron events” tab in the Advanced Tools section to check for the presence of the UpdraftPlus cron job.
- FIX: Resolve the issue of uploads to pCloud failing after a folder name change by resetting the “folderid” whenever the folder name is updated.
- TWEAK: Add site information for WooCommerce and HPOS support to the database backup header.
- TWEAK: Create a log entry when a bot verification page appears during the file upload in the migration procedure.
- TWEAK: Improve error message clarity for failed connection tests in migration.
- TWEAK: Include details in the backup log file about the status and availability of the proxy configured in the system.
- TWEAK: Update the Google library to support the WP_PROXY_HOST and WP_PROXY_PORT constants.
- TWEAK: Update the link for Onedrive and Azure app creation
- COMPATIBILITY: Got rid of PHP 8.4 deprecation messages caused by the E_STRICT constant usage
1.25.1 – 11/Jan/2025
- SECURITY: Fix a non-persistent reflected XSS vulnerability due to a missing nonce combined with missing sanitisation. This could allow an attacker, who persuaded you to click a personally-crafted link to your site’s dashboard whilst you were logged in, to once run JavaScript code in your dashboard. Thanks to Asaf Mozes for finding and responsibly disclosing this issue.
- FIX: Prevent the restoration from failing when there is a ‘sync-xhr=()’ permission policy on the response header.
- FIX: Improve the approach of acquiring a suggested region for Amazon AWS S3 if a failure arises during the getBucketLocation() call, particularly when the XML response fails to provide a field for the suggested region – this resolves issues with regions (e.g. us-east-2) which recently changed their response behaviour
- TWEAK: Broaden the support to incorporate the “ap-southeast-4” region of Amazon AWS S3 and additional recently updated regions
- TWEAK: A regression in the paid version update checker to version 4.13.2, resulting in non-appearance of notices concerning subscription status or WP version compatibility.
1.24.12 – 23/Dec/2024
- FIX: The pre-restoration stage failed to properly address the tables that were to be excluded, which caused a logical error that misread the checked “include all tables not listed” option as an instruction to restore every table
- FIX: Update PHPSecLib library to version 2.0.48 which has the fixes for the “gmp_pow(): base and exponent overflow” on certain PHP versions and could cause backups to fail on the SFTP remote storage
- TWEAK: Complete the review and removal of calls to the unserialize() PHP function allowing class instantiation begun in 1.24.7. (The final removal involved a theoretical security defect, if your development site allowed an attacker to post content to it which you migrated to another site, and which contained customised code that could perform destructive actions which the attacker knew about, prior to you then cloning the site. The result of this removal is that some search-replaces, highly unlikely to be encountered in practice, will be skipped).
- TWEAK: Drop search and replace feature for PHP 5.2 users (to fulfil the preceding item)
- TWEAK: Tweak UpdraftCentral media module to add “has_image_editor” property to each media item
- TWEAK: On the restoration screen in a multisite configuration, the dropdown labeled “which site to restore” was covering other HTML elements, which caused some buttons to be positioned at the bottom instead of at the top
- TWEAK: Avoid deregistering jQuery-UI CSS if already printed by other plugins to prevent compatibility issues
- TWEAK: In the context of database restoration, the execution of LOCK and/or ALTER SQL statements must be avoided for any tables that are part of the “skipped tables” list
- TWEAK: openssl_free_key() is only needed on PHP < 8
- TWEAK: Various coding style changes to comply with “Plugin Check” rules
1.24.11 – 15/Nov/2024
- TWEAK: Do not request drive.readonly scope on Google Drive connections, due to Google’s app permissions review (unannounced and requires us to create a Youtube video for their review process) – this means that (until the review completes) new connections to Google Drive can only access backups created by UpdraftPlus directly, and not backups which you manually upload to Google Drive. This restores the ability to make new connections to Google Drive.
- TWEAK: Adjustment of the UpdraftPlus_S3_Compat class to preserve compatibility with the external UpdraftPlus AWS SDK plugin (https://github.com/DavidAnderson684/updraftplus-aws-sdk).
1.24.9 – 14/Nov/2024
- FIX: A regression in 1.24.8 when handling restoration of wp-config.php
- TWEAK: The changes in handling of loading text domains in 1.24.8 did not cover most cases
- TWEAK: Introduce the “updraftplus_use_builtin_wpcore_restoration” filter which can be used to restore WP-Core entity using a different WP-Core restoration mechanism especially in a case that the admin-ajax.php file couldn’t be deleted during the restoration
1.24.8 – 13/Nov/2024
- TWEAK: Add descriptions for the ‘Clone Package’ dropdown when creating a clone.
- TWEAK: Move the “load_plugin_textdomain” call from being called through “plugins_loaded” action to being called via “init” action
- TWEAK: Update the log message to specify that backup files are marked as “processed” when no remote storage is selected, and as “uploaded” when remote storage is selected.
- TWEAK: Some code tidying in the restore class
1.24.7 – 04/Nov/2024
- TWEAK: Include the .part file extension into the cleanup list, guaranteeing that files associated with this extension are regularly deleted from the backup directory
- TWEAK: The update functionalities in the WordPress plugin information box (6.5 and later) have been adjusted to stop updates from taking place in the same window, ensuring that the “auto-backup before update” dialog appears as intended
- TWEAK: Add customized “unserialized” method into the UpdraftPlus class which can handle the use of the “options” argument or its absence when running across different PHP versions
- TWEAK: Add the UPDRAFTPLUS_SEND_UNWRITABLE_BACKUP_DIRECTORY_EMAIL constant to disable the sending of unwritable backup directory emails to users.
- TWEAK: Clearer notifications to users regarding unconfigured remote storage settings and/or the selection of remote storage that are not part of their UpdraftPlus version
- TWEAK: During the resumption of OneDrive’s chunk uploads, the authorisation header and bearer token should not be included as it may lead to an unauthenticated error due to a different upload URL.
- TWEAK: Implement code to enable automatic activation of the UpdraftPlus plugin during the migration process from a multisite setup to a standalone site
- TWEAK: In a multisite environment, ensure that users can access the UpdraftPlus plugin page even in the absence of the WP_ALLOW_MULTISITE constant
- TWEAK: UpdraftClone now supports PHP 8.4
- TWEAK: Prevent a potential PHP deprecation notice when zip creation fails
1.24.6 – 25/Sep/2024
- TWEAK: In 1.24.5, the browser title wrongly displayed as “UpdraftPlus” when accessing an unrelated plugin page using the main menu.
1.24.5 – 24/Sep/2024
- FIX: Incorrect regular expression for DigitalOcean Spaces endpoint
- FIX: CSS conflicts with the LearnDash LMS Instructor Role Add-on plugin which caused some UI elements to disappear
- TWEAK: Reorganize UpdraftPlus in left-hand menu and rename it to “UpdraftPlus”; to disable it, follow this guide: https://updraftplus.com/new-location-of-updraftplus-in-the-wordpress-dashboard/
- TWEAK: Add span wrapper to UpdraftCentral connection failed message
- TWEAK: Add the “Go here to complete your settings” link into the appropriate admin notice that when clicked will jump to the UpdraftVault configuration if no settings are specified.
- TWEAK: Adjust regex patterns that didn’t match some temporary files, causing them to not be automatically removed
- TWEAK: After a restoration, clicking “Delete old folders” will also remove the wp-config-pre-ud-restore-backup.php file
- TWEAK: On the settings page/tab; prevent the floating “Save changes” button from getting clicked multiple times and/or sending multiple AJAX requests
- TWEAK: Remove pCloud from the add-ons list on the “Premium / Extensions” tab (there is no change in its availability)
- TWEAK: Renamed wp-config-backup.php to wp-config-pre-ud-restore-backup.php to clarify its purpose as a backup file created before restoring WordPress core entities, and it will only be generated if the user does not select the “Over-write wp-config.php” option during restoration, as the previous name was too generic and could cause confusion
- TWEAK: The popup modal for automatic plugin updates fails to retain the backup checkbox selection when the “remember” option is enabled in a Multisite environment.
- TWEAK: Updated autobackup selector to resolve issues caused by the missing “update-link” class in WPForms Pro plugin
1.24.4 – 2/Jul/2024
- FIX: Case-sensitive issue of bit field type names in a table.
- FIX: Resolved issue where backup files could not be deleted from remote storage when either the root directory was active or no directory was specified in the OneDrive configuration form.
- FIX: When users attempt to update a plugin using the “View Version x.x.x Details” link instead of choosing “Update Now,” the plugin is successfully updated; however, the UI incorrectly displays an “Update Failed” message
- FIX: Conflict with the Gravity Forms plugin when there was an older version of jQuery UI presented on the “Installed Plugins” page.
- TWEAK: Ensure compliance with Google Granular Consent and check for required permissions during storage access authorisation of Google Drive and Google Cloud
- TWEAK: Prevent PHP warning and deprecation messages after completing access authorisation to Google Drive storage.
- TWEAK: Prevent PHP warning when Dropbox remote storage has been authenticated and the page is refreshed.
- TWEAK: Added filter updraftplus_working_dir_localpath to allow temporary unzip path to be modified by developers
- TWEAK: Modify the displayed title of the plugin from “WordPress Backup & Migration Plugin” to “WP Backup & Migration Plugin” as required by the plugin directory team
- TWEAK: Parse certain php events and log proper error messages
1.24.3 – 30/Apr/2024
- FIX: Regression in 1.23.16 for improving logs which then caused incorrect_offset error reported by Dropbox wasn’t properly handled.
- TWEAK: The UpdraftVault remote storage can handle Wasabi as well as Amazon S3 storage in the background.
- TWEAK: Fix WP_Theme_JSON_Resolver::theme_has_support deprecation warning for UpdraftCentral
- TWEAK: Prevent “PHP Warning: Undefined property: UpdraftPlus_BackupModule_pcloud::$description” during rescan remote storage.
- TWEAK: Prevent PHP deprecation warnings during database backups when encountering null values in bit field types.
- TWEAK: Show a warning message when the WP_ACCESSIBLE_HOSTS constant is defined and updraftplus.com is not permitted by its value
- TWEAK: Update notices
- TWEAK: Split multiple sentences into separate translation function calls.
- TWEAK: Trim spaces from S3-Compatible (Generic) endpoint.
1.24.2 – 26/Mar/2024
- FIX: The “Continue restoration” and “Dismiss” buttons on the unfinished restoration dialog were not responsive to being pressed due to a recent regression
- FIX: Conflict with other plugins due to different version of third party library (Guzzle) and the composer autoload.php was called too early
- FIX: Undefined “NET_SCP_LOCAL_FILE” constant when SCP was in use for the SFTP/SCP remote storage
- TWEAK: Add compatibility fields when returning plugins and themes to UpdraftCentral
- TWEAK: Due to issues in some cURL versions 7.x in handling HTTP/2 connections, all HTTP connections to the OneDrive API are now forced to use HTTP/1.1 version, on cURL versions after 7.61 and before 8.0. Also, a constant named UPDRAFTPLUS_ONEDRIVE_CURL_HTTP_VERSION can be set in the wp-config.php file to change the default HTTP version to another preferred version
- TWEAK: Adjust margin to fix broken UI for the ‘View logs’ button on backups.
- TWEAK: Ensure all “SET SQL_MODE” statements in the database backup file are internally handled and are subjected only to a restoration outside UpdraftPlus plugin
- TWEAK: Prevent PHP 8.2 coding style deprecation notices in the autobackup addon
- TWEAK: In the context of OneDrive’s chunk upload, authorisation header and bearer token should not be included during upload session as it may lead to 401 HTTP status due to different upload URL
- TWEAK: Remove default value for updraftplus_https_to_http_additional_warning and updraftplus_http_to_https_additional_warning filters.
- TWEAK: Set the SQL_MODE to ‘NO_AUTO_VALUE_ON_ZERO’ in the database backup file.
- TWEAK: Seasonal notice content update for 2024
- TWEAK: During the operations that require phpseclib, include the composer autoload.php only when the phpseclib is really needed
1.24.1 – 21/Feb/2024
- FEATURE: Implement Backblaze Object Lock support (Premium version)
- FIX: The email backup and basic report setting didn’t work causing notification email confirming backup status couldn’t be delivered to admin’s email address (free version)
- FIX: Fix WP-Optimize premium discovery for UpdraftCentral
- FIX: Regression in 1.23.16 for correcting calls to translation functions which then caused some HTML attributes to be empty
- FIX: Restoring backup sets via Migrate/Clone tab had caused all associated backup entities being downloaded immediately ignoring user preferences about the entities they wanted to restore
- FIX: Third-party library conflict (phpseclib) with WP All Import Pro and AIO WP Migration plugins that caused failure in testing SFTP credentials and backing up to the SFTP remote storage
- FIX: Restore compatibility with WordPress multisite running on versions < 4.9 caused by use of function not present before then
- TWEAK: Add new translation entries for UpdraftCentral
- TWEAK: Got rid of PHP 8.2 deprecation messages caused by a null value being passed to the htmlspecialchars() function and creation of dynamic property
- TWEAK: Got rid of PHP 8.3 deprecation messages caused by calling get_class() without arguments.
- TWEAK: Refactor methods in UpdraftPlus_Database_Utility class
- TWEAK: Send an email if the backup directory is not writable.
- TWEAK: Add and set the
filename_onlyparameter to reduce search times when looking for specific backup files in Dropbox. - TWEAK: Autoload PHP secure communication library (phpseclib) in a better way that would prevent already-loaded phpseclib classes (by other plugin) from being used in certain operations
- TWEAK: Add updraftplus_backup_db_header_append filter to allow site owners to include arbitrary content in their database backup header
1.23.16 – 23/Dec/2023
- TWEAK: Added demo link for the family plugin in advertisement
- TWEAK: Removed https / http prefix from s3generic endpoints
- TWEAK: Resolve PHP 8.0 compatibility with ob_implicit_flush function
- TWEAK: Dropbox error logs improvement
- …




