It is designed around durable jobs, bounded memory, checkpoints, verification, and safe recovery instead of one long-running request.
.nbh streaming archives with record checksums and final archive verificationDELIMITER support, bounded multi-row insert splitting, and separate view/trigger/routine/event export.nbh import with archive readiness details, restore planning, quarantine verification, safety backup, and resumable rollback-protected restoreNOBASH_BACKUP_STORAGE_DIR in wp-config.php when they prefer an explicitly managed local storage path..nbh backup archives only.SECURITY.md included with the pluginassets/dist/ are the editable source files; no minification or build tool is required to modify these assets.Nobash Backup works locally without connecting to a Nobash account. The following connections happen only in the circumstances described below.
The in-plugin support form sends an email through your WordPress site’s configured mail service only after an administrator presses Send support request. It sends the entered name, reply email, subject and message, plus the site URL and WordPress, PHP, and Nobash Backup versions, to support@nobash.com. Do not include passwords, access tokens, private backup files, or backup contents.
Service: https://nobash.com/contact/
Terms: https://nobash.com/terms/
Privacy: https://nobash.com/privacy/
Webhook notifications, URL imports connect only to endpoints selected or configured by an administrator. Data sent to those endpoints is governed by the destination provider and the site’s own privacy policy.
Local storage protection checks make requests to random, non-sensitive test files on this site’s own URL before writing sensitive archive data. They do not send backup contents to Nobash or another third party.
Backup archives can contain the same personal data and private content stored by the WordPress site. Local archives remain on infrastructure controlled by the site administrator unless an administrator downloads, migrates, or sends them to a configured destination. Archives are immutable recovery snapshots and are not modified by WordPress personal-data erasure requests; administrators should apply an appropriate retention policy and remove obsolete archives when required. Plugin settings and metadata are preserved on uninstall by default and are removed only when Delete data on uninstall was explicitly enabled beforehand. Administrative backup actions may store the acting WordPress user ID and request IP address locally in the site’s audit log for security accountability; this audit data is not transmitted to Nobash.
Export skips host configuration such as .user.ini, user.ini, php.ini, nginx.conf, httpd.conf, web.config, .htpasswd, and known server error/access logs, including nested copies and log rotations. Existing cache, temporary and backup-directory exclusions still apply. Custom site files, robots.txt, favicons, verification HTML, application files and WordPress .htaccess rules remain eligible for backup.
Import/restore applies the host-file exclusion policy even to older archives. It verifies excluded payloads without extracting or deploying them, and does not delete host files through incremental restore. The uploaded archive itself is preserved unchanged. Backup-folder access protection remains enabled.