Backups
Backups
What It Does
The Backups module (SecuPress Pro) creates archives of your files and database. Since 2.6.4, SecuPress stores these archives outside the web root whenever possible, in a secupress-backups folder one level above the site's public directory. Nobody can then download them by URL.
If PHP open_basedir forbids it, or if the parent folder is not writable, backups stay in wp-content/backups/. A warning is then displayed: delete those files as soon as possible.
You can also protect ZIP files with an AES-256 password. That password is stored as a secret constant in wp-config.php. It cannot be recovered: keep it in a safe place. ZIP files already created keep the password from their own generation.
Why It Matters
Security vulnerabilities can expose your website, user data, and business to serious risks.
By putting this security measure in place, you protect your website against threats and potential attacks. A backup reachable from the browser often contains the full database, including passwords and keys.
How to Use
Open the Backups module in SecuPress settings, in the Backup Storage section.
The path in use is shown automatically. No setting is required for off-web storage: SecuPress chooses it as soon as the server allows it.
To encrypt ZIP files, enter a password in Backup ZIP password. This requires PHP 7.2+ and libzip 1.2+ (AES-256), and a writable wp-config.php file. Leave the field empty to keep ZIP files without a password.
To change or remove the password, enter the current password first. Leave the new password empty to turn protection off. After several wrong attempts, the field locks. A Forgot your password? link then appears to send a reset link to the administration email address.