Descripción
La comunidad de WordPress confía en el plugin de copias de seguridad y migración UpdraftPlus para realizar copias de seguridad, restaurar y migrar sus sitios web de WordPress. UpdraftPlus está instalado activamente en más de 3 millones de sitios web en todo el mundo.
Haz copias de seguridad con UpdraftPlus
UpdraftPlus es el plugin de copias de seguridad programadas y migración mejor valorado y más popular del mundo. Haz copias de seguridad en tu ubicación de almacenamiento preferida y restaura en solo tres clics.
Haz copias de seguridad en Dropbox, Google Drive, Amazon S3 (o compatible), Rackspace Cloud, FTP, DreamObjects, Openstack Swift o por correo electrónico.
La versión de pago también te permite hacer copias de seguridad en Microsoft OneDrive, Microsoft Azure, Google Cloud, Backblaze B2, SFTP, SCP, pCloud, WebDAV o UpdraftVault, nuestra opción de almacenamiento integrado para UpdraftPlus.
Haz la copia de seguridad manualmente o prográmala para que se ejecute cada 2, 4, 8 o 12 horas, diariamente, semanalmente, mensualmente o quincenalmente.
Restaura con UpdraftPlus
Tu sitio web de WordPress es vulnerable. Tu sitio podría ser hackeado. Algo podría salir mal con una actualización o tu servidor podría caerse. Es posible que necesites revertir un cambio realizado o un error provocado por un fallo humano.
Cualquiera que sea la razón, puedes restaurar tu sitio web de WordPress en solo unos pocos clics con UpdraftPlus. Elige qué componentes restaurar (por ejemplo, plugins, temas, base de datos, etc.), haz clic de nuevo para restaurar y luego haz clic otra vez para volver a la pantalla principal.
Migra con UpdraftPlus
Es fácil migrar tu sitio web de WordPress a otro alojamiento web, servidor o dominio con esta versión gratuita de UpdraftPlus.
Para migrar, simplemente descarga tu base de datos, plugins, temas, etc. del sitio de origen y luego súbelos a tu sitio de destino.
Al migrar, un motor de búsqueda y reemplazo integrado identifica las cadenas antiguas y las sustituye para reflejar la nueva ubicación. UpdraftPlus te ahorra tiempo y reduce el riesgo de enlaces rotos o archivos faltantes asociados a las migraciones manuales.
¿Por qué UpdraftPlus?
Escribir un plugin de copias de seguridad y migración fiable que simplemente funcione de forma consistente en millones de instalaciones de WordPress distintas es difícil. Se confía en UpdraftPlus exactamente para hacer eso. Se confía en nosotros y estamos desplegados activamente en más sitios web en todo el mundo que cualquier otro plugin de copia de seguridad y migración para WordPress.
UpdraftPlus:
- Realiza copias de seguridad, migra y restaura
- Ofrece una gran cantidad de ubicaciones de almacenamiento remoto
- Te permite programar copias de seguridad, para que puedas «configurarlo y olvidarte»
- Es completo y fácil de usar
- Está probado que funciona en más de 3 millones de sitios.
UpdraftPlus Premium
La versión gratuita de UpdraftPlus realizará copias de seguridad y migrará tu sitio web perfectamente. Sin embargo, si necesitas más funciones y opciones, puedes adquirir nuestra versión Premium.
Haz copias de seguridad y migra con UpdraftPlus Premium, y:
-
Obtén copias de seguridad automáticas antes de las actualizaciones. Restaura la versión más reciente si una actualización de WordPress o de un plugin rompe tu sitio.
-
Realiza copias de seguridad incrementales. Los cambios se añaden a la copia principal, ahorrando recursos del servidor en comparación con hacer copias de seguridad completas repetidamente.
-
Obtén más opciones de almacenamiento remoto, como Microsoft OneDrive, SFTP, Microsoft Azure, WebDAV, Google Cloud, SCP, Backblaze y pCloud.
-
Obtén 1 GB de almacenamiento integrado con UpdraftVault para un 99,999 % de fiabilidad, redundancia y escalabilidad.
-
Obtén más control sobre cuántas copias de seguridad se almacenan en un intervalo determinado.
Restaura desde otros plugins de copias de seguridad, incluidos BackWPup, BackupWordPress, Simple Backups y más. -
Ejecuta copias de seguridad a horas establecidas, por ejemplo, durante periodos de bajo tráfico.
-
Realiza copias de seguridad en más de una ubicación para mayor protección.
-
Obtén informes detallados. Incluye sumas de comprobación criptográficas para que puedas verificar la integridad de los archivos de copia de seguridad y mucho más.
-
Obtén la migración Premium. La migración al sitio de destino es más directa y se puede realizar desde el propio sitio de origen.
-
Obtén compatibilidad con sitios múltiples y redes múltiples.
-
Realiza copias de seguridad de archivos y bases de datos que no sean de WP, por ejemplo, tablas pertenecientes a tu tienda de comercio electrónico o personalizaciones en el núcleo de WordPress.
-
Obtén cifrado de la base de datos.
-
Gestiona tus copias de seguridad y migraciones desde WP-CLI.
-
Obtén soporte Premium.
Obtén más información en nuestra página de comparación. UpdraftPlus Premium está disponible para su compra aquí.
¿Gestionas múltiples sitios web?
UpdraftCentral es un potente panel de control remoto para WordPress que te permite gestionar tus copias de seguridad, así como actualizaciones, usuarios, páginas, entradas, plugins y temas desde una ubicación central. Elige entre:
- UpdraftCentral (gratuito, autoalojado)
- UpdraftCentral Premium (de pago, autoalojado)
- UpdraftCentral Cloud (de pago, totalmente alojado)
Optimiza tus sitios de forma centralizada combinando la potencia de WP-Optimize y UpdraftCentral o gestiona tus copias de seguridad de forma centralizada combinando la potencia de UpdraftPlus con UpdraftCentral.
¿Necesitas crear un clon temporal de tu sitio?
UpdraftClone permite crear de forma rápida y sencilla un entorno de pruebas (sandbox) temporal para los cambios que desees probar. Solo tienes que seleccionar las versiones de WordPress y PHP que quieras y nosotros nos encargaremos del resto. Más sobre UpdraftClone
La suite completa de plugins de Team Updraft y amigos
-
UpdraftPlus.
Copias de seguridad, migración y restauración. Valoración de 5 estrellas en el directorio de plugins y en el que confían más de 3 millones de propietarios de sitios web de WordPress -
WP-Optimize.
Limpia la base de datos, comprime imágenes y gestiona la caché. Optimiza tu sitio web de WordPress. Valoración de usuarios de 5 estrellas. Más de 1 millón de instalaciones activas. -
All-In-One Security (AIOS).
Protege tu sitio web de WordPress. Completo, lleno de funciones y fácil de usar. Valoración de usuarios de 5 estrellas y más de 1 millón de instalaciones activas. -
WP Overnight.
Extensiones de calidad para tu tienda WooCommerce. Soluciones de facturación valoradas con 5 estrellas, gestión de pedidos y productos, gestión de clientes y más. -
Easy Updates Manager.
Toma el control de las actualizaciones. Muchas funciones de forma gratuita y una versión Premium con aún más: más de 300.000 usuarios. -
Internal Link Juicer. Impulsa tu SEO. Automatiza los enlaces internos dentro de tu sitio web de WordPress. Ahorra tiempo y posiciona mejor en los motores de búsqueda.
Para ver otros plugins gratuitos y útiles, consulta el perfil de nuestro desarrollador principal, aquí.
¿Eres políglota? ¿Puedes traducir?
¿Quieres ayudar a las personas que hablan tu idioma a realizar copias de seguridad, migrar y restaurar sus sitios web de WordPress?
El plugin de copias de seguridad, migración y restauración UpdraftPlus está listo y esperando. El proceso de traducción es sencillo y se realiza a través de la web; consulta las instrucciones aquí: https://updraftplus.com/translate/.
O bien, si ya eres un traductor experto de WordPress, solo tienes que coger el archivo .pot del directorio wp-content/plugins/updraftplus/languages/ ; si escaneas manualmente las cadenas traducibles, debes obtener estas funciones: _x(), __(), _e(), _ex(), log_e().
Muchas gracias a nuestros traductores actuales.
Licencia
Copyright 2011-24 David Anderson
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program; if not, write to the Free Software
Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
Las traducciones a otros idiomas aparte del inglés son aportadas por voluntarios y wordpress.org no otorga a los desarrolladores del plugin el control sobre sus traducciones; por lo tanto, confiar en ellas es bajo tu propio riesgo. UpdraftPlus no puede garantizar que las traducciones desde el inglés original sean precisas.
Reconocemos y agradecemos a los mencionados en https://updraftplus.com/acknowledgements/ por el código y/o las bibliotecas utilizadas y/o modificadas bajo los términos de sus licencias de código abierto.
Capturas

Escritorio principal – las capturas son de UpdraftPlus Premium por lo que pueden hacer referencia a algunas de las características que no son parte de la versión gratuita

Configurando tus copias de seguridad

Hacer una copia de seguridad

Elige qué componentes restaurar
FAQ
¿Cómo instalo el plugin de copias de seguridad y migración UpdraftPlus?
Here are the installation guidelines from our YouTube channel or from our website.
¿Qué pasa si tengo un problema / necesito soporte?
Si tienes problemas para realizar copias de seguridad, migrar o restaurar, hay ayuda disponible.
Busca temas existentes en el foro de soporte de WordPress o publica uno nuevo. Nuestros equipos de soporte y desarrollo revisan y responden a las consultas todos los días.
Los clientes de UpdraftPlus Premium pueden abrir un ticket directamente con nuestros equipos de soporte y desarrollo a través del centro de soporte de UpdraftPlus.
Antes de ponerte en contacto, asegúrate de haber leído nuestras preguntas frecuentes y de haber actualizado a la última versión de nuestro plugin.
Ayuda enormemente si puedes incluir el registro de la copia de seguridad y tanta información adicional como sea posible en tu informe; por ejemplo, la versión de PHP, tu sitio web, la descripción del error, cómo llegaste a la página que lo causó, cualquier otro plugin relevante que tengas instalado, además de cualquier otra información que pueda ser de utilidad.
Para encontrar el registro de la copia de seguridad: hay enlaces para descargar los registros en la página de ajustes de UpdraftPlus dentro del plugin, o bien se te puede enviar por correo electrónico. En su defecto, accede por FTP al directorio wp-content/updraft y búscalo allí.
Si sabes cómo hacerlo, por favor envía tus registros de errores de PHP: solo las pocas líneas que aparecen cuando ejecutas una copia de seguridad, a menudo el archivo llamado error_log, posiblemente en tu directorio wp-admin, el cual puedes comprobar mediante FTP. Si eres un programador que puede depurar y enviar un parche, eso sería aún mejor.
Migrar con el plugin gratuito implica descargar las copias de seguridad del sitio de origen y luego subirlas al sitio de destino.
Para encontrar el registro de la copia de seguridad: hay enlaces para descargar los registros en la página de ajustes de UpdraftPlus, o bien se te puede enviar por correo electrónico. En su defecto, accede por FTP al directorio wp-content/updraft y búscalo allí.
Tanto el plugin gratuito como el Premium incluyen un motor de búsqueda y reemplazo integrado para sustituir las cadenas antiguas por la nueva ubicación.
Si la migración es todo lo que necesitas, para migraciones sencillas de un solo sitio el plugin gratuito probablemente sea suficiente para cubrir tus necesidades. Si tienes necesidades adicionales con respecto a las copias de seguridad (por ejemplo, la capacidad de realizar copias de seguridad antes de las actualizaciones), si requieres más ubicaciones de almacenamiento remoto o si tienes un sitio multisitio de WordPress, te recomendamos UpdraftPlus Premium por los beneficios adicionales que ofrece.
UpdraftPlus se queda sin tiempo cuando intenta hacer una copia de seguridad, después de haberlo dejado un tiempo razonable para darle una oportunidad. ¿Qué puedo hacer?
Este problema probablemente se deba a que tu proveedor de alojamiento web (económico) está limitando los recursos de tu cuenta. Esto está lejos de ser lo ideal; aunque UpdraftPlus admite la reanudación de las ejecuciones de copias de seguridad desde el principio para evitar tener que hacerlo todo a la vez, tiene sus límites. Lo mejor es elegir un proveedor de alojamiento web de mayor reputación. En su defecto, prueba a ir a los «Ajustes avanzados» y reducir el tamaño en el que se dividen los archivos zip. Se sabe que UpdraftPlus realiza con éxito copias de seguridad de sitios web que alcanzan varios gigabytes en servidores web que no tienen restricciones de recursos.
Reseñas
Colaboradores y desarrolladores
«UpdraftPlus: Plugin de copia de seguridad y migración de WP» es un software de código abierto. Las siguientes personas han colaborado con este plugin.
Colaboradores«UpdraftPlus: Plugin de copia de seguridad y migración de WP» está traducido en 37 idiomas. Gracias a los traductores por sus contribuciones.
Traduce «UpdraftPlus: Plugin de copia de seguridad y migración de WP» a tu idioma.
¿Interesado en el desarrollo?
Revisa el código , echa un vistazo al repositorio SVN o suscríbete al registro de desarrollo por RSS.
Registro de cambios
The UpdraftPlus backup blog is the best place to learn in more detail about any important changes.
N.B. Paid versions of UpdraftPlus Backup / Restore have a version number which is 1 higher in the first digit, and has an extra component on the end, but the changelog below still applies. i.e. changes listed for 1.16.32.x of the free version correspond to changes made in 2.16.32.x of the paid version.
1.26.6 – 23/Jul/2026
- FEATURE: Upon plugin deactivation, a popup will appear with data removal options, enabling users to opt-in to deleting saved data.
- FIX: «Unattached» media filter lists attached images when no unattached items exist
- TWEAK: Added Burst Statistics to TeamUpdraft family admin notices.
- TWEAK: Create a better UX for free users around premium remote storage locations
- TWEAK: Prefer http_get_last_response_headers() (PHP 8.4+) to avoid PHP 8.5 deprecation warnings for $http_response_header.
- TWEAK: Replace the calls to the native PHP ‘unserialize()’ function in the Google Drive and HTTP_Request2 libraries.
1.26.5 – 05/Jun/2026
- SECURITY: Previous versions contained a defect allowing sites with an active Migrator key (paid versions only) or UpdraftCentral key (free and paid versions) to have unauthorised operations carried out on them. All users should update immediately.
- TWEAK: Added explicit HTTP timeout of 60 seconds to pCloud chunk upload requests to prevent cURL error 28 on slow server connections
- TWEAK: Guard curl_close(), finfo_close() and xml_parser_free() calls with a PHP version check to prevent deprecation warnings on PHP 8.5+
- TWEAK: Update the bundled common-libs version
- TWEAK: Replace all usages of wpdb::esc_like() with UpdraftPlus_Database_Utility::esc_like() across the codebase to maintain consistency.
- TWEAK: Add «auto-backup before update» tour guide
1.26.4 – 07/May/2026
- FIX: In version 1.26.2, a regression prevented the backup schedule, including the day name or number, as well as backup entity exclusion rules, from being saved.
- TWEAK: Alert users who wrongly enter URLs instead of an actual hostname for SFTP and FTP remote storage.
- TWEAK: Updated DreamObjects endpoints by removing the deprecated objects-us-west-1, marking objects-us-east-1.dream.io as unavailable (Nov. 12th, 2025), and adding admin notices to inform users of this change.
- TWEAK: get_structured_data() now accepts params to avoid timeouts.
1.26.3 – 23/Apr/2026
- FEATURE: Implemented enhanced streaming extraction for large files during restoration to handle cases where the file size exceeds the PHP memory limit.
- FIX: Fix users role filter empty state shows generic “Failed to Fetch Data” error.
- FIX: Fixed backup failures on tables with invisible columns and large data volumes.
- FIX: Unable to uncheck all categories on post in UDC dashboard
- TWEAK: Added a new internal command to get given plugins’ installation info.
- TWEAK: Ensure autobackup notice is always a string to prevent PHP 8.1+ deprecation in wp_kses()
- TWEAK: Fix the JS errors that occur when deleting the last generated UDC keys.
- TWEAK: Implemented adjustments for UI misalignment issues caused by the WordPress 7 visual design refresh across the admin dashboard. The plugin’s interface now aligns correctly with the updated design standards.
- TWEAK: Prevent broken settings pages in other plugins in multisite when UpdraftPlus is active due to modified menu URLs.
- TWEAK: Update all links in the addons folder to use teamupdraft.com instead of updraftplus.com.
- TWEAK: Replaced esc_html_e() with esc_html__() where string concatenation was silently discarding the colon separator in SFTP connection failure message and noscript JavaScript warning notice
- TWEAK: Switched to native phpseclib API/function for Dropbox token decryption, replacing deprecated mcrypt_decrypt since PHP 7.1 and removed in PHP 7.2.
- TWEAK: Clear out PHP «Undefined offset» notice that occurred while restoring a backup of single site to multisite. It happened during the search-replace operation due to the absence of the users and usermeta tables.
- TWEAK: Enhance the unzip file function to handle more folder inclusion/exclusion
- TWEAK: Update all links in the methods folder to use teamupdraft.com instead of updraftplus.com.
- TWEAK: Add post status and date fields to get_posts API response for UDC
1.26.2 – 03/Mar/2026
- TWEAK: Added PHP 8.5 support to UpdraftClone
- TWEAK: Fix deprecation warnings in PHP 8.4 for the Dropbox integration
- TWEAK: Make abort backup warning icon responsive with percentage-based sizing
- TWEAK: Prevent the suppressed PHP warnings from being output in the backup and restore log on PHP 8.0+
- TWEAK: On a site where the site owner has restricted (super-)administrators (so that they can’t restore backups), require a constant to first be set to use the HTTP debug tool for internal IP addresses.
- TWEAK: Update all links in the settings folder to use teamupdraft.com instead of updraftplus.com.
- TWEAK: When deleting backup sets created through a direct site-to-site migration, the ‘Also delete from remote storage’ checkbox is unnecessary.
1.26.1 – 19/Jan/2026
- FIX: Google Drive chunked uploads didn’t resume from where it left off but started from the beginning resulting in file duplicates
- TWEAK: Add a WP-CLI command to register a product key (premium)
- TWEAK: Add product registration link on the premium version
- TWEAK: Fix JS error on UpdraftCentral Cloud connect modal.
- TWEAK: Fix grammatical error in the low disk space admin notice.
- TWEAK: Update links for better user experience
- TWEAK: Update the premium links on the settings page
- TWEAK: Update all links in the includes/notices/central folders to use teamupdraft.com instead of updraftplus.com.
- TWEAK: Upgrade the common-libs tag version
1.25.9 – 12/Nov/2025
- FIX: A regression that resulted in the list of tables within the «Database size» tools not being displayed, due to code refactoring implemented in version 1.25.8.
- TWEAK: Add function for returning Advanced Tools menu data in a structured format.
- TWEAK: Resolve regression in 1.25.2 which caused the admin notice «Not yet connected to licence» was linking to teamupdraft.com instead of the UpdraftPlus Premium/Extensions tab.
- TWEAK: Refactoring connection keys data function to deduplicate and read from a single source
- TWEAK: Restored the missing backup confirmation pop-up icon for older WordPress versions.
- TWEAK: Stripped unwanted HTML from the plain-text notice and added new lines after each sentences in the sale offer message.
- TWEAK: Update Black Friday seasonal sale URL/link
- TWEAK: Updated «Check our premium» and «Back up non-WP tables and external databases» URL links to avoid HTTP 404 (not found) errors.
- TWEAK: Update database charset detection to support both CHARSET= and CHARACTER SET syntax in SQL dumps
- TWEAK: Replaced deprecated (boolean) casting
1.25.8 – 07/Oct/2025
- FIX: A fatal error in UpdraftCentral when trying to manage posts when no posts exist.
- FIX: During a failure in the file copy process while restoring, a directory was created with the same name as the file, and the restoration process persisted when it ought to have been stopped
- FIX: PHP fatal error in WP CLI commands for listing or scanning existing backups on PHP 8.0+ after a rescan
- TWEAK: Add UpdraftCentral support to import_settings function with return values
- TWEAK: Add support for new Amazon AWS S3 regions
- TWEAK: Added Burst Statistics to the family plugin list
- TWEAK: Adjust the backup logic to recognize invisible columns, and when that occurs, use a query that explicitly specifies the required columns instead of relying on «SELECT *».
- TWEAK: Ensure the restore process terminates with an error when file copying/moving fails
- TWEAK: Improve the backup email report to better reflect the backup types and status.
- TWEAK: New endpoint for getting locked settings data for UpdraftCentral
- TWEAK: Perform a search and replace on __PHP_Incomplete_Class to make it work with unserialize() when object deserialization is not allowed.
- TWEAK: Refactoring site info section to deduplicate and read from single source
- TWEAK: Resolved a PHP warning triggered when uploading the plugin via the WP Plugins page — caused by translation functions (e.g. __()) being called too early.
- TWEAK: Some text was left out of the translation POT file, which meant that certain translator plugins and libraries could not find the text, making it impossible to translate.
- TWEAK: Update the db_size function to allow returning either data or html, depending on the argument that is passed in.
1.25.7 – 07/Aug/2025
- FIX: A regression for verifying the presence of old folders in the backup directory; old folders created during the restoration of the «Others» entity were not detected correctly.
- FIX: The per-backup lock entries were not removed, resulting in an accumulation of these entries in the database over time. (Includes clean-up of old entries).
- TWEAK: Add IDrive e2 and MEGA to the S3-Compatible storage list
- TWEAK: Internal function call to prevent a PHP 8.1 deprecation notice on fresh WP installs
- TWEAK: Add wp-staging to the default uploads exclusion list
- TWEAK: Add UpdraftCentral handler for site icon upload request.
- TWEAK: Added support for the database view dashicon in WordPress versions prior to 5.5.
- TWEAK: Include site icon information in the ‘get_site_icon’ response of the UpdraftCentral core module.
- TWEAK: Resolve the empty list issue on the backup email reports created by the UpdraftPlus free version
- TWEAK: The «Get every feature of UpdraftPlus Premium» box shouldn’t be displayed after purchases got claimed/activated
- TWEAK: Remove seasonal (new year, summer, spring and plugin collection) sale notices
- TWEAK: Handle unsupported character set defined for table fields during database pre-restoration.
- TWEAK: Updated links in the Premium Extensions tab of the plugin’s admin menu page.
1.25.6 – 27/May/2025
- FIX: A regression that prevented the remote storage label from being updated
- FIX: A regression that could cause unintended behaviour when restoring special files
- FIX: A fatal error when executing a standalone php backup script with «do_action(‘updraft_backup_all’)».
- FIX: Regression that caused certain features (e.g. PHP Info) to break due to a missing HTML attribute on the triggering element
- FIX: An issue that caused migration failure for sites using the Performance Lab plugin or other plugins implementing an object cache drop-in
- TWEAK: handle non fatal file rename failure during restore
- TWEAK: The automatic backup feature is now disabled by default on new installs
- TWEAK: return post status and formatted date from UDC post API
- TWEAK: Replace a call to unserialize() in the Dropbox storage library
- TWEAK: Validate the DreamObjects endpoint to ensure only expected DreamObjects enpoint formats can pass through.
- TWEAK: Position the «includes all tables not listed below» option at the beginning of the first known table in the DB restoration widget.
- TWEAK: Add a new default endpoint in DreamObjects along with UI to allow users to add custom endpoint in the format «s3..dream.io».
- TWEAK: The Azure Storage Service add-on now requires PHP 5.6 or higher to support the mandatory use of TLS 1.2, which will be enforced starting August 31, 2025.
1.25.5 – 17/Apr/2025
- FIX: A bug that prevented the Rackspace «Create new API user and container» dialog from opening.
- TWEAK: An HTTP header intended to terminate the browser’s connection was incorrectly assigned a value that the header does not support.
- TWEAK: Ability to automatically choose the proper checkout page when the user is about to buy TeamUpdraft products from within the plugin
- TWEAK: Clear Divi theme CSS cache at the end of the restoration process
- TWEAK: Resolve PHP warning in pCloud addon when upgrading from free to premium version.
- TWEAK: Update error messages when the user fails to connect to their TeamUpdraft account on the ‘Premium/Extensions’ tab.
1.25.4 – 24/Mar/2025
- FIX: Regression in 1.25.3 – missing database encryption input field due to the use of the «wp_kses_post» function that doesn’t allow «» tag to be rendered
- TWEAK: Add new fields to UpdraftCentral handler
1.25.3 – 21/Mar/2025
- FIX: An issue that prevented an UpdraftClone backup from sending when attempting to boot an UpdraftClone from WP_CLI
- FIX: An issue that prevented changing the default UpdraftClone region when attempting to boot an UpdraftClone from WP_CLI
- TWEAK: The «x-amz-content-sha256» request header is now signed and included in the S3 signature version 4. Some S3-based providers mandate the signing of this header for accurate signature calculation.
- TWEAK: Introduce a new constant named «UPDRAFTPLUS_S3_EXCLUDE_SIGV4_CONTENT_SHA256_HEADER». This constant allows for the exclusion of the «x-amz-content-sha256» headers from being signed if desired; it accepts a boolean value, defaulting to false.
- TWEAK: Add ‘noopener, noreferrer’ window features to the Javascript’s window.open() call to prevent the target page from changing content of the original page
- TWEAK: Favicon fetching feature for UpdraftCentral
- TWEAK: Minor tweak to «updates» module to include icons to plugin and screenshot url to theme update items
- TWEAK: New UpdraftCentral module for background fetching
- TWEAK: Revise the wording found in the expert settings regarding the deletion of local backup files
- TWEAK: Update seasonal notices
- TWEAK: Enhance the notifications to signify the introduction of other plugins that belong to the same plugin family
- TWEAK: To avoid CORS issues and ensure the UpdraftPlus plugin is functional and accessible via the UpdraftCentral dashboard, the hostname and/or domain origin is changed from updraftplus.com to teamupdraft.com.
- COMPATIBILITY: Resolved PHP deprecation warnings in lockadmin.php by eliminating the use of dynamic properties
1.25.2 – 26/Feb/2025
- FEATURE: Added a «Cron events» tab in the Advanced Tools section to check for the presence of the UpdraftPlus cron job.
- FIX: Resolve the issue of uploads to pCloud failing after a folder name change by resetting the «folderid» whenever the folder name is updated.
- TWEAK: Add site information for WooCommerce and HPOS support to the database backup header.
- TWEAK: Create a log entry when a bot verification page appears during the file upload in the migration procedure.
- TWEAK: Improve error message clarity for failed connection tests in migration.
- TWEAK: Include details in the backup log file about the status and availability of the proxy configured in the system.
- TWEAK: Update the Google library to support the WP_PROXY_HOST and WP_PROXY_PORT constants.
- TWEAK: Update the link for Onedrive and Azure app creation
- COMPATIBILITY: Got rid of PHP 8.4 deprecation messages caused by the E_STRICT constant usage
1.25.1 – 11/Jan/2025
- SECURITY: Fix a non-persistent reflected XSS vulnerability due to a missing nonce combined with missing sanitisation. This could allow an attacker, who persuaded you to click a personally-crafted link to your site’s dashboard whilst you were logged in, to once run JavaScript code in your dashboard. Thanks to Asaf Mozes for finding and responsibly disclosing this issue.
- FIX: Prevent the restoration from failing when there is a ‘sync-xhr=()’ permission policy on the response header.
- FIX: Improve the approach of acquiring a suggested region for Amazon AWS S3 if a failure arises during the getBucketLocation() call, particularly when the XML response fails to provide a field for the suggested region – this resolves issues with regions (e.g. us-east-2) which recently changed their response behaviour
- TWEAK: Broaden the support to incorporate the «ap-southeast-4» region of Amazon AWS S3 and additional recently updated regions
- TWEAK: A regression in the paid version update checker to version 4.13.2, resulting in non-appearance of notices concerning subscription status or WP version compatibility.
1.24.12 – 23/Dec/2024
- FIX: The pre-restoration stage failed to properly address the tables that were to be excluded, which caused a logical error that misread the checked «include all tables not listed» option as an instruction to restore every table
- FIX: Update PHPSecLib library to version 2.0.48 which has the fixes for the «gmp_pow(): base and exponent overflow» on certain PHP versions and could cause backups to fail on the SFTP remote storage
- TWEAK: Complete the review and removal of calls to the unserialize() PHP function allowing class instantiation begun in 1.24.7. (The final removal involved a theoretical security defect, if your development site allowed an attacker to post content to it which you migrated to another site, and which contained customised code that could perform destructive actions which the attacker knew about, prior to you then cloning the site. The result of this removal is that some search-replaces, highly unlikely to be encountered in practice, will be skipped).
- TWEAK: Drop search and replace feature for PHP 5.2 users (to fulfil the preceding item)
- TWEAK: Tweak UpdraftCentral media module to add «has_image_editor» property to each media item
- TWEAK: On the restoration screen in a multisite configuration, the dropdown labeled «which site to restore» was covering other HTML elements, which caused some buttons to be positioned at the bottom instead of at the top
- TWEAK: Avoid deregistering jQuery-UI CSS if already printed by other plugins to prevent compatibility issues
- TWEAK: In the context of database restoration, the execution of LOCK and/or ALTER SQL statements must be avoided for any tables that are part of the «skipped tables» list
- TWEAK: openssl_free_key() is only needed on PHP < 8
- TWEAK: Various coding style changes to comply with «Plugin Check» rules
1.24.11 – 15/Nov/2024
- TWEAK: Do not request drive.readonly scope on Google Drive connections, due to Google’s app permissions review (unannounced and requires us to create a Youtube video for their review process) – this means that (until the review completes) new connections to Google Drive can only access backups created by UpdraftPlus directly, and not backups which you manually upload to Google Drive. This restores the ability to make new connections to Google Drive.
- TWEAK: Adjustment of the UpdraftPlus_S3_Compat class to preserve compatibility with the external UpdraftPlus AWS SDK plugin (https://github.com/DavidAnderson684/updraftplus-aws-sdk).
1.24.9 – 14/Nov/2024
- FIX: A regression in 1.24.8 when handling restoration of wp-config.php
- TWEAK: The changes in handling of loading text domains in 1.24.8 did not cover most cases
- TWEAK: Introduce the «updraftplus_use_builtin_wpcore_restoration» filter which can be used to restore WP-Core entity using a different WP-Core restoration mechanism especially in a case that the admin-ajax.php file couldn’t be deleted during the restoration
1.24.8 – 13/Nov/2024
- TWEAK: Add descriptions for the ‘Clone Package’ dropdown when creating a clone.
- TWEAK: Move the «load_plugin_textdomain» call from being called through «plugins_loaded» action to being called via «init» action
- TWEAK: Update the log message to specify that backup files are marked as «processed» when no remote storage is selected, and as «uploaded» when remote storage is selected.
- TWEAK: Some code tidying in the restore class
1.24.7 – 04/Nov/2024
- TWEAK: Include the .part file extension into the cleanup list, guaranteeing that files associated with this extension are regularly deleted from the backup directory
- TWEAK: The update functionalities in the WordPress plugin information box (6.5 and later) have been adjusted to stop updates from taking place in the same window, ensuring that the «auto-backup before update» dialog appears as intended
- TWEAK: Add customized «unserialized» method into the UpdraftPlus class which can handle the use of the «options» argument or its absence when running across different PHP versions
- TWEAK: Add the UPDRAFTPLUS_SEND_UNWRITABLE_BACKUP_DIRECTORY_EMAIL constant to disable the sending of unwritable backup directory emails to users.
- TWEAK: Clearer notifications to users regarding unconfigured remote storage settings and/or the selection of remote storage that are not part of their UpdraftPlus version
- TWEAK: During the resumption of OneDrive’s chunk uploads, the authorisation header and bearer token should not be included as it may lead to an unauthenticated error due to a different upload URL.
- TWEAK: Implement code to enable automatic activation of the UpdraftPlus plugin during the migration process from a multisite setup to a standalone site
- TWEAK: In a multisite environment, ensure that users can access the UpdraftPlus plugin page even in the absence of the WP_ALLOW_MULTISITE constant
- TWEAK: UpdraftClone now supports PHP 8.4
- TWEAK: Prevent a potential PHP deprecation notice when zip creation fails
1.24.6 – 25/Sep/2024
- TWEAK: In 1.24.5, the browser title wrongly displayed as «UpdraftPlus» when accessing an unrelated plugin page using the main menu.
1.24.5 – 24/Sep/2024
- FIX: Incorrect regular expression for DigitalOcean Spaces endpoint
- FIX: CSS conflicts with the LearnDash LMS Instructor Role Add-on plugin which caused some UI elements to disappear
- TWEAK: Reorganize UpdraftPlus in left-hand menu and rename it to «UpdraftPlus»; to disable it, follow this guide: https://updraftplus.com/new-location-of-updraftplus-in-the-wordpress-dashboard/
- TWEAK: Add span wrapper to UpdraftCentral connection failed message
- TWEAK: Add the «Go here to complete your settings» link into the appropriate admin notice that when clicked will jump to the UpdraftVault configuration if no settings are specified.
- TWEAK: Adjust regex patterns that didn’t match some temporary files, causing them to not be automatically removed
- TWEAK: After a restoration, clicking «Delete old folders» will also remove the wp-config-pre-ud-restore-backup.php file
- TWEAK: On the settings page/tab; prevent the floating «Save changes» button from getting clicked multiple times and/or sending multiple AJAX requests
- TWEAK: Remove pCloud from the add-ons list on the «Premium / Extensions» tab (there is no change in its availability)
- TWEAK: Renamed wp-config-backup.php to wp-config-pre-ud-restore-backup.php to clarify its purpose as a backup file created before restoring WordPress core entities, and it will only be generated if the user does not select the «Over-write wp-config.php» option during restoration, as the previous name was too generic and could cause confusion
- TWEAK: The popup modal for automatic plugin updates fails to retain the backup checkbox selection when the «remember» option is enabled in a Multisite environment.
- TWEAK: Updated autobackup selector to resolve issues caused by the missing «update-link» class in WPForms Pro plugin
1.24.4 – 2/Jul/2024
- FIX: Case-sensitive issue of bit field type names in a table.
- FIX: Resolved issue where backup files could not be deleted from remote storage when either the root directory was active or no directory was specified in the OneDrive configuration form.
- FIX: When users attempt to update a plugin using the «View Version x.x.x Details» link instead of choosing «Update Now,» the plugin is successfully updated; however, the UI incorrectly displays an «Update Failed» message
- FIX: Conflict with the Gravity Forms plugin when there was an older version of jQuery UI presented on the «Installed Plugins» page.
- TWEAK: Ensure compliance with Google Granular Consent and check for required permissions during storage access authorisation of Google Drive and Google Cloud
- TWEAK: Prevent PHP warning and deprecation messages after completing access authorisation to Google Drive storage.
- TWEAK: Prevent PHP warning when Dropbox remote storage has been authenticated and the page is refreshed.
- TWEAK: Added filter updraftplus_working_dir_localpath to allow temporary unzip path to be modified by developers
- TWEAK: Modify the displayed title of the plugin from «WordPress Backup & Migration Plugin» to «WP Backup & Migration Plugin» as required by the plugin directory team
- TWEAK: Parse certain php events and log proper error messages
1.24.3 – 30/Apr/2024
- FIX: Regression in 1.23.16 for improving logs which then caused incorrect_offset error reported by Dropbox wasn’t properly handled.
- TWEAK: The UpdraftVault remote storage can handle Wasabi as well as Amazon S3 storage in the background.
- TWEAK: Fix WP_Theme_JSON_Resolver::theme_has_support deprecation warning for UpdraftCentral
- TWEAK: Prevent «PHP Warning: Undefined property: UpdraftPlus_BackupModule_pcloud::$description» during rescan remote storage.
- TWEAK: Prevent PHP deprecation warnings during database backups when encountering null values in bit field types.
- TWEAK: Show a warning message when the WP_ACCESSIBLE_HOSTS constant is defined and updraftplus.com is not permitted by its value
- TWEAK: Update notices
- TWEAK: Split multiple sentences into separate translation function calls.
- TWEAK: Trim spaces from S3-Compatible (Generic) endpoint.
1.24.2 – 26/Mar/2024
- FIX: The «Continue restoration» and «Dismiss» buttons on the unfinished restoration dialog were not responsive to being pressed due to a recent regression
- FIX: Conflict with other plugins due to different version of third party library (Guzzle) and the composer autoload.php was called too early
- FIX: Undefined «NET_SCP_LOCAL_FILE» constant when SCP was in use for the SFTP/SCP remote storage
- TWEAK: Add compatibility fields when returning plugins and themes to UpdraftCentral
- TWEAK: Due to issues in some cURL versions 7.x in handling HTTP/2 connections, all HTTP connections to the OneDrive API are now forced to use HTTP/1.1 version, on cURL versions after 7.61 and before 8.0. Also, a constant named UPDRAFTPLUS_ONEDRIVE_CURL_HTTP_VERSION can be set in the wp-config.php file to change the default HTTP version to another preferred version
- TWEAK: Adjust margin to fix broken UI for the ‘View logs’ button on backups.
- TWEAK: Ensure all «SET SQL_MODE» statements in the database backup file are internally handled and are subjected only to a restoration outside UpdraftPlus plugin
- TWEAK: Prevent PHP 8.2 coding style deprecation notices in the autobackup addon
- TWEAK: In the context of OneDrive’s chunk upload, authorisation header and bearer token should not be included during upload session as it may lead to 401 HTTP status due to different upload URL
- TWEAK: Remove default value for updraftplus_https_to_http_additional_warning and updraftplus_http_to_https_additional_warning filters.
- TWEAK: Set the SQL_MODE to ‘NO_AUTO_VALUE_ON_ZERO’ in the database backup file.
- TWEAK: Seasonal notice content update for 2024
- TWEAK: During the operations that require phpseclib, include the composer autoload.php only when the phpseclib is really needed
1.24.1 – 21/Feb/2024
- FEATURE: Implement Backblaze Object Lock support (Premium version)
- FIX: The email backup and basic report setting didn’t work causing notification email confirming backup status couldn’t be delivered to admin’s email address (free version)
- FIX: Fix WP-Optimize premium discovery for UpdraftCentral
- FIX: Regression in 1.23.16 for correcting calls to translation functions which then caused some HTML attributes to be empty
- FIX: Restoring backup sets via Migrate/Clone tab had caused all associated backup entities being downloaded immediately ignoring user preferences about the entities they wanted to restore
- FIX: Third-party library conflict (phpseclib) with WP All Import Pro and AIO WP Migration plugins that caused failure in testing SFTP credentials and backing up to the SFTP remote storage
- FIX: Restore compatibility with WordPress multisite running on versions < 4.9 caused by use of function not present before then
- TWEAK: Add new translation entries for UpdraftCentral
- TWEAK: Got rid of PHP 8.2 deprecation messages caused by a null value being passed to the htmlspecialchars() function and creation of dynamic property
- TWEAK: Got rid of PHP 8.3 deprecation messages caused by calling get_class() without arguments.
- TWEAK: Refactor methods in UpdraftPlus_Database_Utility class
- TWEAK: Send an email if the backup directory is not writable.
- TWEAK: Add and set the
filename_onlyparameter to reduce search times when looking for specific backup files in Dropbox. - TWEAK: Autoload PHP secure communication library (phpseclib) in a better way that would prevent already-loaded phpseclib classes (by other plugin) from being used in certain operations
- TWEAK: Add updraftplus_backup_db_header_append filter to allow site owners to include arbitrary content in their database backup header
1.23.16 – 23/Dec/2023
- TWEAK: Added demo link for the family plugin in advertisement
- TWEAK: Removed https / http prefix from s3generic endpoints
- TWEAK: Resolve PHP 8.0 compatibility with ob_implicit_flush function
- TWEAK: Dropbox error logs improvement
- TWEAK: As required by the wordpress.org plugin team, all UpdraftPlus news is forbidden to be displayed in the «WordPress News» section of the dashboard for users of the free plugin even if consent is first given.
- TWEAK: Fix some incorrect calls to translation functions
1.23.14 – 30/Nov/2023
- FIX: Resolved Google Cloud remote storage authentication flow
- TWEAK: Changed updraftvault links functionality to open in different tab
- TWEAK: Clarify significance of warnings in report emails
- TWEAK: Make the news-consent’s layer fit with the confirmation text thus removing empty space that can reveal some of the UpdraftPlus news
- TWEAK: Declare a shim «php_uname» function when it’s found to be undefined to prevent a fatal error in the phpseclib library (which calls it)
1.23.13 – 22/Nov/2023
- FIX: An issue that prevented incremental backups from running via WP-CLI or Cron when the option to backup mu-plugins was enabled but no mu-plugins existed
- FIX: OneDrive remote storage authentication was giving the error «Invalid input.»
- FIX: The option to back up additional, user-chosen files (i.e. the morefiles entity) was no longer present in the UI
- TWEAK: Remove unused «migrator-lite.php» string during search and replace operations
- TWEAK: Replace remaining hardcoded text domain with UPDRAFTCENTRAL_TEXT_DOMAIN placeholder within the central folder
- TWEAK: LiteSpeed admin dashboard warning is now displayed upon completion of migration on the destination site, even after dismissing the message on the source site.
- TWEAK: Do not show UpdraftPlus news in the WordPress events and news widget section without first gaining user consent
- TWEAK: Change order of checks when seeing if cPanel is present/accessible for asking about disk quota in order to prevent unwanted an PHP notice when safe_mode is active
- TWEAK: Prevent potential fatal error if something has modified an updates check’s ‘translation’ property to be invalid before passing on to UpdraftPlus
- TWEAK: Update bundled cacert.pem file
1.23.12 – 08/Nov/2023
- FIX: Issue that prevented some database restores from completing due to a change in wpdb in WordPress 6.4
- TWEAK: Replace Javascript onchange event with oninput event to detect changes made for HTML tags on the settings page, also to add to the event handler so that unsaved changes can be detected
1.23.11 – 03/Nov/2023
- SECURITY: Fix a vulnerability which could, if you had Google Drive storage enabled, and if an attacker targetted a logged-in administrator on your site and persuaded them to access a specific URL that the attacker creates, add the attacker’s own Google Drive account to the saved storage methods. Thanks to Nicolas Decayeux of Patrowl for finding and disclosing this issue.
- FEATURE: Add JSTree for Google Drive to select existing folder
- FEATURE: The …
