Releases: akhmadsakhoji/founders-migration-website
Releases · akhmadsakhoji/founders-migration-website
Release list
Founders Migration Website 1.0.4
Fixed
-
A restore or pull to a new address stopped in the Replace step with "Duplicate entry '…' for key '…'" when a table with a unique URL column held the same address over
http://andhttps://(LiteSpeed Cache'slitespeed_url, for example): both became the new URL. The step now:- empties LiteSpeed Cache's URL tables (
litespeed_url,litespeed_url_file) instead of searching them, since LiteSpeed rebuilds them (fmwp_restore_cache_tablesfilter to change the list); - leaves a value that would duplicate another row's unique key as it was, still replaces the row's other columns, logs how many rows of which table kept the old address and ends the restore with a note.
A restore that stopped this way continues after the update (Backups page or
wp fmw resume). - empties LiteSpeed Cache's URL tables (
Founders Migration Website 1.0.3
Fixed
- Activating the plugin while another copy of it is loaded (another folder under plugins, or a must-use copy) stopped with "Constant FMWP_PLUGIN_FILE already defined" and a fatal error. The second copy now stays idle and wp-admin shows which copy runs and that the other should be deleted.
Founders Migration Website 1.0.2
Security
- The backups and storage folders could be downloaded from the web on OpenLiteSpeed (CyberPanel), which reads only rewrite rules from
.htaccessand ignoresRequire all denied. Their.htaccessnow also hasRewriteRule .* - [F,L], applied by OpenLiteSpeed whenautoLoadHtaccessis on (restart lsws once after the update). An unchanged.htaccessfrom an older version is replaced; one edited by hand is left alone. The warning in wp-admin says what to do when the folder is still reachable.
Founders Migration Website 1.0.1
Added
- After a restore, a new "Server" step makes the site work on its server (
fmwp_server_fixesfilter to switch parts off):- Adds WordPress's permalink rules (
# BEGIN WordPress, or the network rules on a multisite network) to the root.htaccesswhen they are missing (an empty block counts as missing). A backup never carries that file, so restores onto a fresh CyberPanel / OpenLiteSpeed or Apache site answered 404 on every page but the home page. - Gives what a restore run as root (WP-CLI) wrote in
wp-content(and custom uploads, plugins or themes folders), the root.htaccessand FMW's folders to the owner ofwp-config.phpor the site folder, so WordPress can write uploads and updates. Only entries owned by root and changed since the restore started; links are never followed, and folders outside the site that do not belong to it are not walked. - Empties Elementor's generated CSS and element caches, rebuilt on the next visit with the new URLs.
- Purges the LiteSpeed page cache on the next uncached request.
- Requests an unknown address from this server (127.0.0.1, whatever the DNS says) and, when the web server answers with its own 404 page, ends the restore with what to do (on OpenLiteSpeed: make sure the site's
vhost.confhasautoLoadHtaccess 1, thensystemctl restart lsws).
- Adds WordPress's permalink rules (
- Notes from a restore are shown after it: as warnings in WP-CLI and in the restore dialog.
Fixed
- Plugin Check (WordPress.org rules) passes again; it had failed in CI since 1.0.0. Exception messages are marked as plain text file by file (they reach WP-CLI, logs and JSON, and the admin screens insert them as text), and PHP_CodeSniffer now enforces the rule instead of switching it off for the whole plugin. S3 and Google Drive addresses (the endpoint of the user's own bucket, examples in messages, the S3 XML namespace, the client ID format) are marked as not loading anything,
load_plugin_textdomain()is gone (WordPress loads translations itself since 4.6), and the Google Drive account shown after connecting is sanitized first.
Founders Migration Website 1.0.0
First public release. The development history before it is in the pull requests and the git log.
Backup
wp fmw backupand the Export screen make resumable.fmwbackups: a TAR container of.tar.gz/.tarfile parts (1 GiB by default, 128 MiB to 4 GiB), gzip-compressed plain SQL per table and a JSON manifest with a SHA-256 per part. Restorable by hand withtar,gunzipandmysql(format specification, CC BY 4.0).- Built for very large sites: constant-memory file scan, keyset-paginated database dump with a consistent snapshot, files larger than 8 GiB, resumable in the middle of a table or a file, parts deleted as they are packed (little more than one copy of the site on disk).
- Exclusions of
wp ai1wm backup(spam comments, revisions, media, themes, plugins, inactive ones, must-use plugins, cache, database) plus transients, tables (--exclude-tables), path patterns (--exclude-paths) and the part size. - Password protection: AES-256-CBC (OpenSSL
encformat) with PBKDF2-SHA256 (600,000 iterations) and HMAC-SHA256; the manifest, table names and the file name are hidden too.
Restore
wp fmw restoreand the Import / Backups screens restore.fmwand All-in-One WP Migration.wpressbackups (plain, encrypted, gzip or bzip2 compressed, versions 7.85 to 7.111) onto the same or another address, path or table prefix.- Safety: every part is checked before use; the database goes into
fmwtmp_*tables and live with one atomicRENAME TABLE(the previous tables are kept asfmwold_*until the end, or with--keep-old-tables); SQL from backups is checked against an allowlist; the plugin, its folders and other installs in a shared database are never touched. - Serialized-safe search-replace of URLs, paths and e-mail domains without
unserialize(), matching whole addresses only. - Resumable uploads of any size in the browser (continue by choosing the same file again) and resumable downloads with byte ranges.
Multisite
- Whole networks back up and restore onto a network of the same kind at any address,
.fmwor.wpress(Multisite Extension); subsites move with the network's address, and those with their own domain can be mapped with--map. - One site of a network backup restores onto a single site (
--site), a single-site backup becomes a new or existing site of a network, and sites picked from a.wpressnetwork backup restore into a network, with users merged and authors kept. - Reset of one site or of the whole network.
Reset
wp fmw resetand the Reset screen bring the database, media, plugins or themes back to a fresh install, after a safety backup and a typed confirmation, keeping the address, title, language and the chosen administrators.
Schedules and cloud storage
- Scheduled backups (hourly, daily, weekly, monthly in the site time zone) with retention, e-mail and optional password, driven by WP-Cron (on a network, the main site's) or a system cron (
wp fmw schedule run); interrupted runs continue in the background. - Cloud storage on Amazon S3 and S3-compatible services (Cloudflare R2, Wasabi, Backblaze B2, DigitalOcean Spaces, MinIO, others) and Google Drive with your own OAuth client: resumable uploads and downloads, retention per schedule, credentials stored encrypted.
Pull
wp fmw pulland the Pull screen copy another site, or a network onto a network, server to server in one resumable job, authorised by a short-lived pull key (wp fmw pull-key) that can be limited to addresses (protocol).
Operations
- Every backup, restore, reset, upload and pull is a job that checkpoints its position: continue after Ctrl+C, a lost SSH session, a timeout or a server restart (
wp fmw jobs,resume,cancel,log,cleanup). Real progress with speed and time left in the browser and the terminal. - Data folders protected from the web, with an HTTP check and a warning where the server ignores
.htaccess; both can be moved outside the web root. - Deleting the plugin removes its settings, credentials, jobs and logs, never backups.
- Requirements: 64-bit PHP 7.4 or newer, WordPress 6.0 or newer.