WP Safer connects your site to the wpsafer.com management dashboard, so you can manage multiple sites from one place: backups, plugins, themes and core updates. This plugin is the lightweight agent that runs on your site — almost all configuration lives on the dashboard, so there is very little to set up here beyond pasting your site key.
What it does
- Resumable backups. Full, database-only and incremental backups run in small, resumable steps so they survive shared-hosting execution-time limits. Archives are built locally and then collected by your dashboard, which keeps them off your server as a cloud backup.
- Safe restores. Restores are staged next to your live files and swapped in with a single atomic move; nothing is deleted until the swap succeeds, and a failed restore rolls back automatically.
- Migration & transfer. Move a site to another host or another domain from the dashboard: the archive is transferred to the target server and restored there, so a migration is the same tested path as a restore.
- Remote plugin & theme management. Install, update, activate, deactivate and uninstall plugins and themes — individually or in groups — without logging in to each site.
- One-click login. Open the wp-admin of any connected site directly from the dashboard, no password required.
- Core updates. Update WordPress core from the dashboard.
- Database & content cleanup. The built-in sweep tool removes post revisions, auto-drafts, trashed posts and comments, spam, orphaned and duplicated meta data, unused terms, transient options and stale oEmbed caches.
- Uptime monitoring. Periodic checks confirm your site is answering from the outside.
- Admin-area IP firewall. An optional allow or block list decides which addresses may open wp-login.php, /wp-admin and XML-RPC on your site. Single addresses, CIDR ranges, wildcards and ranges are understood; the public side of your site is never filtered. Managed per site from the dashboard.
- Security scans. A file integrity scan compares WordPress core, plugin and theme files against the official WordPress.org checksums and reports what no longer matches, so an unexpected change is visible from the dashboard.
- System checks. The dashboard reports on PHP version, free disk space, max execution time, ZipArchive availability and file-write access so you can see backup readiness at a glance.
- Signed connection. Every request between your site and the dashboard is authenticated with your site key; the plugin also runs a self-test to confirm the connection is healthy.
Check out wpsafer.com to create a free account.
Support
Email us at support@wpsafer.com.
External services
This plugin is the site-side agent of the WP Safer service at wpsafer.com. It cannot do its job without talking to that service, and it also fetches packages from WordPress.org. Every outbound connection it makes is listed here.
wpsafer.com / api.wpsafer.com / cdn.wpsafer.com (WP Safer)
What it is: the dashboard you connect this site to. It stores your site list, schedules and keeps your backup archives, and is where you trigger updates and restores from.
When it is contacted and what is sent:
- Backup archives. When a backup finishes, the dashboard downloads the archive from your site. It contains your database dump and your site’s files. It does not contain
wp-config.php, so your authentication keys, salts and database password never leave the server.
- Restores and migrations. When you start a restore, the site downloads the archive from
api.wpsafer.com or cdn.wpsafer.com. Only those two addresses are accepted.
- Plugin, theme and core packages. When you install or update something from the dashboard, the site downloads the package from the address the dashboard supplies — either WordPress.org or
cdn.wpsafer.com.
- Agent updates. Nothing is fetched from this service for the plugin itself any more; new versions come from WordPress.org (see below).
- Site status. The dashboard asks the site for its plugin/theme/core versions, PHP version, free disk space, database size and similar readiness information. This is sent only in response to a request signed with your site key.
- Connection self-test. The settings page can run a check that requests
https://wpsafer.com/ to see whether your host allows outbound connections. Only the request itself and this site’s address (as the user agent) are sent.
Requests are authenticated with the site key you paste into the settings page. No data is sent before a site key is entered.
Terms of service: https://wpsafer.com/terms. Privacy policy: https://wpsafer.com/privacy.
WordPress.org
What it is: the official plugin, theme and core package repository.
When it is contacted and what is sent: when you install or update a plugin, theme or WordPress core from the dashboard without supplying your own package address, the site asks WordPress.org for the package information and downloads the package. Only the slug and version being requested are sent. WordPress core itself contacts the same service for its own update checks. This plugin’s own updates come from here too: whether you update it yourself from the Plugins screen or the dashboard sends the update, the package is downloaded from WordPress.org.
Terms of service: https://wordpress.org/about/privacy/. Privacy policy: https://wordpress.org/about/privacy/.
License
This file is part of WP Safer.
WP Safer is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version.
WP Safer is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with WP Safer. If not, see http://www.gnu.org/licenses/.