Site Replica copies a whole WordPress site (database and wp-content) to another WordPress install. It was built for large sites on restrictive shared hosting, where the usual “make one big ZIP” approach fails because of time limits, memory limits or missing disk space.
Pull backups (direct download). On the live site, turn on “This site as a source” and generate a connection key. Paste the key into Site Replica on another site (for example a local development copy). That site pulls the live site in small encrypted pieces. Nothing large is ever written on the live server.
- Resumable: every piece is saved before moving on, and interrupted jobs continue where they stopped.
- Adapts to slow or strict hosts: smaller pieces after timeouts, automatic retries with back-off.
- Incremental: unchanged files are shared with the previous backup, so later backups only download what changed.
- Verified: every database chunk and file is checked with SHA-256.
Clone and restore, safely.
- The database is imported into temporary tables while the site keeps running. The site is switched in one short step at the end.
- Search-replace that is safe for serialized data, without ever unserializing it (no object injection). It handles JSON-escaped and URL-encoded addresses, and never touches look-alike domains.
- Roll back: after a restore you choose Keep or Roll back. Roll back puts the previous site back exactly.
- Keeps you logged in, keeps this site’s own Site Replica settings, and on local copies discourages search engines and blocks outgoing email (or lets it through to a local mail catcher such as Mailpit, when one is set up).
- Copes with MySQL/MariaDB differences (collations, engines, defaults).
- Back up the site you are on, and restore it from the Backups page if something goes wrong.
Scheduled backups to Google Drive or S3-compatible storage (Amazon S3, Backblaze B2, Cloudflare R2, Wasabi and others). Daily or weekly, database and files or database only, with the number of backups to keep and an e-mail when a backup fails.
- Made for hosts with little free disk: the backup is packed into parts of about 50 MB, and each part is uploaded, checked and deleted before the next is made.
- Runs on the server in the background, continuing where it stopped after timeouts or Google Drive hiccups.
- The parts are ordinary ZIP files. Any site with Site Replica connected to the same Google account can download a backup and restore it.
- Uses Google’s drive.file access: Site Replica can only see the files it created in your Drive.
- S3 uploads are signed (Signature Version 4) and every piece carries its MD5, so the storage rejects damaged data.
Security
- Pulling is off until you turn it on. Keys can expire, be limited to IP addresses and be revoked.
- A key can only read the site: nothing can be uploaded to it.
- Every request is signed (HMAC-SHA256) with replay protection. Responses are encrypted (AES-256-GCM).
- HTTPS is required (except for local development sites).
- Site Replica’s own secrets and settings are never included in backups.
- Before a restore, the table, view and trigger definitions in the backup are checked: only plain definitions of the backup’s own tables are run, so a tampered backup can’t reach other tables, files or servers.
- Backups are stored in a randomly named folder inside wp-content, never in the uploads folder, with deny rules for Apache and IIS. On a server that ignores those rules, the plugin notices and refuses to back up until the folder is protected.
External services
Site Replica only contacts other services that you set up yourself.
Other WordPress sites you connect. When you pull a backup, this site exchanges signed, encrypted requests with the other WordPress site whose connection key you entered. The data is the site’s database and wp-content files. Nothing goes to AccessNow or any other third party.
Google Drive (Google LLC). Used only when you choose Google Drive under Cloud Backups and connect your Google account.
* What is sent, and when: when you connect, the OAuth authorization is exchanged at accounts.google.com and oauth2.googleapis.com. When a backup runs, or when you list, download or delete backups, requests go to www.googleapis.com (Drive API). They carry the backup: this site’s database and files, packed in ZIP parts, plus their names and checksums.
* Access: Site Replica asks only for access to the files it creates (the drive.file scope).
* Terms and privacy: Google Terms of Service, Google Privacy Policy, Google API Services User Data Policy.
S3-compatible storage. Used only when you choose it under Cloud Backups. The same backup data goes, when a backup runs or when you list, download or delete backups, to the storage endpoint you enter. The terms and privacy policy of the provider you choose apply, for example:
* Amazon S3: service terms, privacy
* Backblaze B2: terms, privacy
* Cloudflare R2: terms, privacy
* Wasabi: terms, privacy