{"id":350827,"date":"2026-08-28T04:35:49","date_gmt":"2026-08-28T04:35:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/mozzy-assistance\/"},"modified":"2026-09-13T06:23:51","modified_gmt":"2026-09-13T06:23:51","slug":"mozzy-assistance","status":"publish","type":"plugin","link":"https:\/\/es-cr.wordpress.org\/plugins\/mozzy-assistance\/","author":23544826,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.2.0","stable_tag":"3.2.0","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Mozzy Assistance","header_author":"Mozzy","header_description":"Private WordPress monitoring plus verified, optionally encrypted local and Google Drive backups.","assets_banners_color":"a4a199","last_updated":"2026-09-13 06:23:51","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/mozzy.au\/wordpress","header_author_uri":"https:\/\/mozzy.au","rating":0,"author_block_rating":0,"active_installs":10,"downloads":348,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"3.1.1":{"tag":"3.1.1","author":"mozzzy","date":"2026-08-28 04:35:34","revision":3669768},"3.1.149":{"tag":"3.1.149","author":"mozzzy","date":"2026-09-13 05:20:22","revision":3693324},"3.1.2":{"tag":"3.1.2","author":"mozzzy","date":"2026-09-02 11:28:27","revision":3677866},"3.1.3":{"tag":"3.1.3","author":"mozzzy","date":"2026-09-08 10:41:13","revision":3686417},"3.1.4":{"tag":"3.1.4","author":"mozzzy","date":"2026-09-09 04:53:07","revision":3687581},"3.1.5":{"tag":"3.1.5","author":"mozzzy","date":"2026-09-09 06:58:03","revision":3687749},"3.1.6":{"tag":"3.1.6","author":"mozzzy","date":"2026-09-10 23:44:18","revision":3690613},"3.2.0":{"tag":"3.2.0","author":"mozzzy","date":"2026-09-13 06:23:51","revision":3693368}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3669768,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3669768,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3669768,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3669768,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3669768,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["3.1.1","3.1.149","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.2.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[151,17785,34356,5603,56926],"plugin_category":[54,59],"plugin_contributors":[277994],"plugin_business_model":[],"class_list":["post-350827","plugin","type-plugin","status-publish","hentry","plugin_tags-backup","plugin_tags-google-drive","plugin_tags-health-check","plugin_tags-monitoring","plugin_tags-wordpress-maintenance","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-mozzzy","plugin_committers-mozzzy"],"banners":{"banner":"https:\/\/ps.w.org\/mozzy-assistance\/assets\/banner-772x250.png?rev=3669768","banner_2x":"https:\/\/ps.w.org\/mozzy-assistance\/assets\/banner-1544x500.png?rev=3669768","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/mozzy-assistance\/assets\/icon.svg?rev=3669768","icon":"https:\/\/ps.w.org\/mozzy-assistance\/assets\/icon.svg?rev=3669768","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Mozzy Assistance connects a WordPress website to the Mozzy monitoring service.\nA Mozzy account is required for hosted monitoring and remote management. Local backups, downloads and restoration remain available without an account. To connect, open Mozzy &gt; Overview and\nselect Connect to Mozzy. Sign in, choose or create a project, and approve the\nwebsite. WordPress exchanges a short-lived authorization code directly with\nMozzy; the permanent connector token is never placed in a browser URL.<\/p>\n\n<p>The plugin contacts https:\/\/mozzy.au to authorize the connection and send the\nmonitoring information described in the Privacy section. Nothing is sent until\nan administrator approves or manually configures a connection.<\/p>\n\n<p>Mozzy Assistance can also create complete database and file archives, retain\nprotected local copies, and upload them directly to a Google Drive account using\nGoogle's least-privilege drive.file permission. Backup contents upload directly\nto Google. With easy connection, Mozzy securely manages Google authorization.\nAdvanced setup can keep your own Google application credentials in WordPress.<\/p>\n\n<p>Administrators can instead send backups directly to Backblaze B2, Amazon S3,\nCloudflare R2, Wasabi, DigitalOcean Spaces, or another service with an\nS3-compatible HTTPS endpoint. Credentials and archive contents are sent directly\nfrom WordPress to the destination selected and configured by the administrator;\nthey never pass through Mozzy.<\/p>\n\n<p>Protected updates let an administrator select pending plugin, theme, and\nWordPress core updates. Mozzy Assistance creates and verifies a new full safety\nbackup first, requires any connected remote upload to succeed, applies updates\none at a time, refreshes inventory, and runs database and filesystem checks.\nNormal WordPress automatic updates are not intercepted.<\/p>\n\n<p>Maintenance Autopilot lets an authorized Mozzy user approve specific update\nversions in Mozzy. The connected plugin receives those maintenance commands in\nheartbeat responses and performs the same backup-gated updates locally. If\npost-update verification fails, Mozzy can request an automatic rollback using\nthe verified pre-update archive. WordPress creates a failed-state safety backup\nbefore restoring that archive; this rollback does not require a separate\nconfirmation in WordPress.<\/p>\n\n<p>Remote recovery can browse Mozzy-created Google Drive, Backblaze B2, and\nS3-compatible archives and download a selected copy into protected local storage\nin resumable chunks. Transport and archive checks run before the existing\nexplicit guided-restore confirmation is enabled.<\/p>\n\n<p>Optional encrypted backups use authenticated XChaCha20-Poly1305 chunks in a\nMozzy .mzb container. Encryption and decryption are resumable, plaintext working\narchives are removed after encryption, and weak cryptographic fallbacks are not\nused. Administrators can export offline recovery-key files and rotate to a new\nkey while retaining previous keys for older archives. Existing ZIP archives\nremain fully supported.<\/p>\n\n<p>New backups contain a small manifest archive and numbered component parts. Keep\nall files in a set together: the manifest alone cannot restore the website.\nRecent backups offers separate downloads for the manifest and every part.\nConnected cloud destinations receive the parts before the final manifest.<\/p>\n\n<h3>External services<\/h3>\n\n<h4>Mozzy<\/h4>\n\n<p>The plugin contacts https:\/\/mozzy.au only after an administrator connects the\nsite or manually saves a connector token. It sends the monitoring and backup\nstatus and maintenance progress listed in the Privacy section to provide the\nMozzy monitoring and maintenance service. Heartbeat responses can contain managed\nbackup settings and requests, approved maintenance updates, or automatic rollback\ncommands as described in the FAQ. Easy Google Drive connection also sends authorization\nrequests and the selected folder ID\/name to Mozzy. Mozzy stores an encrypted Google\nrefresh token and issues short-lived access tokens to the authenticated website.\nMozzy does not receive backup archives, object-storage secrets, or recovery keys.<\/p>\n\n<p>When you submit Contact Mozzy, your topic, message and reply email are saved in\nMozzy's support inbox and linked to your connected project. An email notification\nis sent by Mozzy, not by WordPress. WordPress, PHP and Mozzy version numbers are\nincluded only if you select the optional technical-details checkbox.<\/p>\n\n<p>Mozzy privacy policy: https:\/\/mozzy.au\/privacy\nMozzy terms: https:\/\/mozzy.au\/terms<\/p>\n\n<h4>Google Drive<\/h4>\n\n<p>After an administrator selects Connect Google Drive, Mozzy handles Google consent\nand folder selection. Authorization codes and tokens pass through Mozzy; backup\nfiles upload directly from WordPress to Google. Disconnect removes this website's\nMozzy grant without deleting Drive files or disconnecting other websites. You can\nalso revoke Mozzy in your Google account permissions.<\/p>\n\n<p>Advanced setup uses your own Google application with tokens held in WordPress.\nBoth modes use\nhttps:\/\/accounts.google.com for authorization, https:\/\/oauth2.googleapis.com for\nOAuth token exchange and revocation, and https:\/\/www.googleapis.com for Drive\nfile operations. OAuth identifiers, authorization codes, access and refresh\ntokens, backup archives, filenames, sizes, checksums, and plugin-created folder\nmetadata are sent directly to Google as required to store, list, download, and\nremove retained backups in the administrator's Drive account.<\/p>\n\n<p>Google privacy policy: https:\/\/policies.google.com\/privacy\nGoogle terms: https:\/\/policies.google.com\/terms<\/p>\n\n<h4>Backblaze B2 and S3-compatible storage<\/h4>\n\n<p>The plugin contacts an object-storage service only after an administrator saves\nits HTTPS endpoint and credentials. It sends signed S3 API requests, the access\nkey identifier, backup archives, filenames, sizes, and storage metadata directly\nto that endpoint to test the connection and to store, list, download, and remove\nretained backups. The secret key remains stored encrypted in WordPress and is\nused locally to sign requests. Supported services include Backblaze B2, Amazon\nS3, Cloudflare R2, Wasabi, DigitalOcean Spaces, and other administrator-selected\nS3-compatible services. Use of a configured service is governed by that\nprovider's terms and privacy policy.<\/p>\n\n<p>For Amazon S3, the standard API endpoint is https:\/\/s3.amazonaws.com. An Amazon\nWeb Services account, an S3 bucket, an access key ID, and a secret access key are\nrequired. Administrators must explicitly enter their provider's HTTPS endpoint;\nthe plugin does not prefill or contact one merely by being activated or viewed.\nRequests begin only after an administrator saves the destination and explicitly\ntests it or runs a backup, recovery, retention, or restore operation. This is an\noptional storage API integration, not a source of remotely loaded JavaScript,\nCSS, images, fonts, or executable code.<\/p>\n\n<p>Backblaze privacy: https:\/\/www.backblaze.com\/company\/policy\/privacy\nBackblaze terms: https:\/\/www.backblaze.com\/company\/policy\/terms-of-service\nAWS privacy: https:\/\/aws.amazon.com\/privacy\/\nAWS service terms: https:\/\/aws.amazon.com\/service-terms\/\nCloudflare privacy: https:\/\/www.cloudflare.com\/privacypolicy\/\nCloudflare terms: https:\/\/www.cloudflare.com\/terms\/\nWasabi privacy: https:\/\/wasabi.com\/legal\/privacy-policy\nWasabi terms: https:\/\/wasabi.com\/legal\/terms-of-use\nDigitalOcean privacy: https:\/\/www.digitalocean.com\/legal\/privacy-policy\nDigitalOcean terms: https:\/\/www.digitalocean.com\/legal\/terms-of-service-agreement<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>When connected and enabled, the plugin sends data to https:\/\/mozzy.au. Data can\ninclude health heartbeats; WordPress, PHP, theme and plugin names and versions;\nactive plugin status; fatal error messages, file locations, line numbers and the\naffected URL; database error messages; backup state, progress, filenames, sizes\nand destination labels; maintenance command identifiers, update and rollback\nprogress, results and backup filenames; failed email events; and supported\nscheduled-task failures.<\/p>\n\n<p>The plugin does not intentionally send passwords, cookies, form contents,\ndatabase records, WordPress users, visitor IP addresses, backup archives, object-storage\ncredentials or recovery keys. Easy Google Drive connection stores encrypted Google\nauthorization credentials and destination metadata on Mozzy. Review Mozzy's privacy policy at\nhttps:\/\/mozzy.au\/privacy and terms at https:\/\/mozzy.au\/terms.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate Mozzy Assistance.<\/li>\n<li>Open Mozzy &gt; Overview.<\/li>\n<li>Select Connect to Mozzy.<\/li>\n<li>Sign in to Mozzy and choose or create a project.<\/li>\n<li>Confirm the connection test in WordPress.<\/li>\n<\/ol>\n\n<p>Administrators can alternatively paste a connector token from Mozzy. Monitoring\ncan be paused and local credentials can be removed from the settings page.<\/p>\n\n<p>Verified local backups can be restored from Mozzy &gt; Backups. Manual\nguided restore requires explicit administrator confirmation, creates a fresh safety\nbackup first, preserves wp-config.php and the active Mozzy recovery component,\nrestores in background batches, and finishes with database and filesystem checks.<\/p>\n\n<h4>Website activation<\/h4>\n\n<p>Connecting to Mozzy activates this website against its project using a private\nconnection token. Each project can activate one WordPress website. Your account's\nproject allowance controls new activations. Existing connections remain active\nwhen a plan limit is lowered. Remove a connection in Mozzy to revoke its token;\ndisconnecting in WordPress removes the local credentials. Local backup and restore\nfeatures remain available without a Mozzy activation. Activation status and plan\nallowances refresh with successful monitoring heartbeats. Existing clients remain\ncompatible; upgrading adds website-URL checks to monitoring requests.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"when%20does%20the%20plugin%20start%20contacting%20mozzy%3F\"><h3>When does the plugin start contacting Mozzy?<\/h3><\/dt>\n<dd><p>Only after a WordPress administrator approves the connection or saves a connector\ntoken. Deactivating the plugin stops its scheduled events. The connection can also\nbe paused or disconnected from Mozzy &gt; Overview.<\/p><\/dd>\n<dt id=\"what%20can%20mozzy%20remotely%20control%3F\"><h3>What can Mozzy remotely control?<\/h3><\/dt>\n<dd><p>When an administrator enables managed backups, Mozzy can supply the schedule,\nretention and backup preset and request a new backup through the authenticated\nheartbeat. WordPress performs every backup locally and uploads directly to the\nconfigured destination.<\/p>\n\n<p>Maintenance Autopilot also lets an authorized Mozzy user approve specific plugin,\ntheme, and WordPress core update versions. Mozzy sends these limited maintenance\ncommands through heartbeat responses. WordPress checks that the requested\nversions are still available and creates and verifies a full safety backup before\napplying updates; connected remote backup uploads must also succeed.<\/p>\n\n<p>If post-update verification fails, Mozzy can request an automatic rollback using\nthe verified pre-update archive. WordPress validates that archive against its\nprotected-update history and creates a failed-state safety backup before\nrestoring it. Automatic rollback does not require a separate confirmation in\nWordPress. Manual guided restores still require explicit confirmation from a\nlogged-in WordPress administrator.<\/p>\n\n<p>These commands are limited to the plugin's backup, update, and rollback workflows;\nthey do not provide a general-purpose remote shell or arbitrary file editor.\nRecovery keys and object-storage credentials remain in WordPress. Easy Google Drive\nconnection keeps the Google refresh token encrypted on Mozzy; WordPress requests\nshort-lived access for direct uploads. Advanced Google setup keeps its credentials\nin WordPress. Recovery keys and archives are not sent to Mozzy. Any archive\ndecryption required for restoration happens locally.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20lose%20an%20encrypted%20backup%20recovery%20key%3F\"><h3>What happens if I lose an encrypted backup recovery key?<\/h3><\/dt>\n<dd><p>Mozzy cannot decrypt the archive and does not receive a copy of the key. Download\nand securely retain every recovery-key file, including older keys kept after a\nrotation. Importing the matching key makes its encrypted archives restorable.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.2.0<\/h4>\n\n<ul>\n<li>Replace multipart download dialogs with animated inline download rows and retry handling.<\/li>\n<li>Stream complete and component ZIP wrappers without recompressing or duplicating backups on disk.<\/li>\n<li>Preserve original manifest, part checksums and encrypted files for recovery after extraction.<\/li>\n<li>Show one download row at a time with grouped cards, loading feedback and an animated close control.<\/li>\n<li>Include all plugins and themes in Essential files while excluding WordPress core; Custom remains configurable.<\/li>\n<\/ul>\n\n<h4>3.1.149<\/h4>\n\n<ul>\n<li>Add resumable multipart backups, component archives and manifest-based recovery with adaptive processing.<\/li>\n<li>Cache source-size estimates and improve backup progress, diagnostics and recovery controls.<\/li>\n<li>Refresh account plans automatically and verify activations for Mozzy-hosted services while preserving local recovery.<\/li>\n<li>Add private support messaging through Mozzy with clearer delivery errors.<\/li>\n<li>Detect supported active applications and provide native export entry points with bundled product icons.<\/li>\n<li>Refine Overview, accordion animations, accessibility labels and backup selection controls.<\/li>\n<\/ul>\n\n<h4>3.1.131<\/h4>\n\n<ul>\n<li>Add visible warm-coloured scrollbars and an overflow-aware bottom fade to backup-selection lists.<\/li>\n<\/ul>\n\n<h4>3.1.130<\/h4>\n\n<ul>\n<li>Apply logo-peach styling to Overview actions and preserve confirmed project metadata across incomplete responses.<\/li>\n<li>Read project identity from successful API responses and accept both nested and legacy pairing metadata.<\/li>\n<\/ul>\n\n<h4>3.1.129<\/h4>\n\n<ul>\n<li>Sanitize backup control inputs, use WordPress deletion APIs and document required native streaming\/atomic restore operations.<\/li>\n<li>Update tested WordPress version and release metadata.<\/li>\n<\/ul>\n\n<h4>3.1.128<\/h4>\n\n<ul>\n<li>Use readable website\/CMS\/component filenames with UTC date, time and unique backup ID. Older backup names remain supported.<\/li>\n<li>Tune archive sizes independently per component, avoid shrinking on small final parts, and raise the per-part file limit.<\/li>\n<li>Use more available request time for checkpointed work and record upload and phase timing separately.<\/li>\n<\/ul>\n\n<h4>3.1.126<\/h4>\n\n<ul>\n<li>Group file inventories by component using bounded, resumable passes to reduce small backup parts and upload requests.<\/li>\n<li>Restore accessible Download, Restore and Delete tooltips after recent-backup rows refresh.<\/li>\n<\/ul>\n\n<h4>3.1.125<\/h4>\n\n<ul>\n<li>Add a saved per-user Show diagnostics switch under Advanced, off by default. Backup progress and errors remain visible.<\/li>\n<\/ul>\n\n<h4>3.1.124<\/h4>\n\n<ul>\n<li>Show backup identity, result and timestamps beside a dismissible diagnostics download button. Export filenames include the backup ID and export time.<\/li>\n<\/ul>\n\n<h4>3.1.123<\/h4>\n\n<ul>\n<li>Create bounded, immutable backup parts for database, core, uploads, plugins, themes and other content, with a manifest describing the complete set.<\/li>\n<li>Verify and stage every part before restoring files; retain support for existing single-file ZIP and encrypted backups.<\/li>\n<li>Encrypt, transfer, download and retain multipart backups as one logical backup set.<\/li>\n<li>Cache source-size estimates persistently and refresh them in background after WordPress content and extension changes.<\/li>\n<li>Respect the host PHP execution limit and record runtime capabilities in diagnostics.<\/li>\n<\/ul>\n\n<h4>3.1.122<\/h4>\n\n<ul>\n<li>Bound repeated worker crashes and archive rebuilds, preserve valid ZIP checkpoints on retry, and report worker delays.<\/li>\n<li>Add downloadable backup timings and reduce compression work for already-compressed media.<\/li>\n<\/ul>\n\n<h4>3.1.8<\/h4>\n\n<ul>\n<li>Show Check connection only after Google Drive is connected, replacing the confusing Test Google Drive label.<\/li>\n<\/ul>\n\n<h4>3.1.7<\/h4>\n\n<ul>\n<li>Connect Google Drive through Mozzy without entering developer credentials in WordPress.<\/li>\n<li>Create or select a backup destination folder and preserve Advanced Google application setup.<\/li>\n<li>Keep backup uploads direct and explain how managed Google authorization is stored.<\/li>\n<\/ul>\n\n<h4>3.1.6<\/h4>\n\n<ul>\n<li>Explain connection and inventory failures with transport or HTTP error details.<\/li>\n<li>Allow 15 seconds for manual connection tests and inventory uploads.<\/li>\n<li>Distinguish enabled monitoring from confirmed uploads and website availability.<\/li>\n<\/ul>\n\n<h4>3.1.5<\/h4>\n\n<ul>\n<li>Let connected maintenance requests update directly or create a verified backup first.<\/li>\n<li>Keep backups enabled by default for existing update requests.<\/li>\n<\/ul>\n\n<h4>3.1.4<\/h4>\n\n<ul>\n<li>Start requested maintenance scans through a signed, on-demand wake-up instead of waiting for the next scheduled heartbeat.<\/li>\n<li>Reject expired and replayed wake-ups, rate-limit requests, and prevent concurrent remote inventory scans.<\/li>\n<li>Keep the existing heartbeat as a fallback when the wake-up cannot reach WordPress.<\/li>\n<\/ul>\n\n<h4>3.1.3<\/h4>\n\n<ul>\n<li>Check for maintenance commands every 30 seconds while an administrator is active in WordPress. Background checks remain every five minutes.<\/li>\n<\/ul>\n\n<h4>3.1.2<\/h4>\n\n<ul>\n<li>Let Mozzy request a fresh authenticated software inventory before maintenance verification.<\/li>\n<li>Deduplicate remote inventory commands and retry them safely when a sync fails.<\/li>\n<\/ul>\n\n<h4>3.1.1<\/h4>\n\n<ul>\n<li>Store new local backups under the WordPress uploads directory while retaining read access to legacy archives.<\/li>\n<li>Require explicit object-storage endpoint entry and clarify the optional Amazon S3 account requirements, transmitted data, and activation behavior.<\/li>\n<li>Document installation-root access required for full-site backup, restore, and WordPress core health checks.<\/li>\n<li>Clarify Maintenance Autopilot commands, automatic rollback, manual restore confirmation, and maintenance status data sent to Mozzy.<\/li>\n<\/ul>\n\n<h4>3.1.0<\/h4>\n\n<ul>\n<li>Added Maintenance Autopilot rollback using the exact verified pre-update archive.<\/li>\n<li>Added a failed-state safety backup, resumable restore progress, and post-rollback verification reporting.<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>Add authenticated Maintenance Autopilot commands with exact-version approval.<\/li>\n<li>Report backup-gated update progress and results to the Mozzy maintenance record.<\/li>\n<\/ul>\n\n<h4>2.9.3<\/h4>\n\n<ul>\n<li>Document the live schema reads required to export database structures without stale cache data.<\/li>\n<li>Document the intentional installation-root write performed by an administrator-approved guided restore.<\/li>\n<\/ul>\n\n<h4>2.9.2<\/h4>\n\n<ul>\n<li>Resolve all errors and warnings reported by the official WordPress Plugin Check rules.<\/li>\n<li>Use WordPress file-deletion APIs and document necessary resumable streaming operations.<\/li>\n<li>Strengthen input sanitization and OAuth redirect validation.<\/li>\n<\/ul>\n\n<h4>2.9.1<\/h4>\n\n<ul>\n<li>Load administration CSS and JavaScript through the WordPress enqueue API.<\/li>\n<li>Improve compatibility with custom uploads and content-directory locations.<\/li>\n<li>Confirm request authorization checks and external-service disclosures for WordPress.org review.<\/li>\n<\/ul>\n\n<h4>2.9.0<\/h4>\n\n<ul>\n<li>Add optional Mozzy-managed backup schedules, including monthly and three-month intervals.<\/li>\n<li>Accept idempotent remote backup requests through the existing authenticated heartbeat.<\/li>\n<li>Report throttled backup progress and terminal results without sending archives or credentials.<\/li>\n<li>Keep destination credentials, encryption keys, emergency controls and restores in WordPress.<\/li>\n<\/ul>\n\n<h4>2.8.1<\/h4>\n\n<ul>\n<li>Replace the generic WordPress shield menu icon with the Mozzy brand mark.<\/li>\n<\/ul>\n\n<h4>2.8.0<\/h4>\n\n<ul>\n<li>Move Mozzy Assistance from Tools into its own top-level WordPress admin menu.<\/li>\n<li>Add dedicated Overview and Backups child pages.<\/li>\n<li>Keep backup, recovery, encryption, and protected-update workflows together on the Backups page.<\/li>\n<li>Correct the Mozzy brand mark alignment in the administration header.<\/li>\n<\/ul>\n\n<h4>2.7.0<\/h4>\n\n<ul>\n<li>Add optional authenticated XChaCha20-Poly1305 backup encryption using PHP sodium.<\/li>\n<li>Encrypt and authenticate large archives in resumable, independently verified chunks.<\/li>\n<li>Add offline recovery-key generation, protected key storage, import, export, and rotation.<\/li>\n<li>Retain previous keys so encrypted archives remain restorable after rotation.<\/li>\n<li>Add resumable authenticated decryption before guided restore begins destructive stages.<\/li>\n<li>Remove plaintext working archives after encryption and decrypted staging files after restore.<\/li>\n<li>Introduce the .mzb encrypted container while retaining full legacy ZIP compatibility.<\/li>\n<li>Block encryption when secure sodium support or a recovery key is unavailable.<\/li>\n<\/ul>\n\n<h4>2.6.0<\/h4>\n\n<ul>\n<li>Add provider-neutral remote backup catalogue and recovery contracts.<\/li>\n<li>Browse Mozzy-created Google Drive backups from the WordPress administration page.<\/li>\n<li>Download large remote archives in resumable background chunks with retry and cancellation controls.<\/li>\n<li>Add SHA-256 and site-identity metadata to new Google Drive backups.<\/li>\n<li>Verify remote MD5 metadata, SHA-256, ZIP integrity, and same-site identity before enabling guided restore.<\/li>\n<li>Clean partial recovery files safely and preserve verified copies under normal local retention.<\/li>\n<\/ul>\n\n<h4>2.5.0<\/h4>\n\n<ul>\n<li>Add administrator-approved protected updates for plugins, themes, and WordPress core.<\/li>\n<li>Require a new verified safety backup and successful connected remote upload before updating.<\/li>\n<li>Apply approved updates one at a time in a recoverable background queue.<\/li>\n<li>Verify installed target versions, refresh Mozzy inventory, and run post-update health checks.<\/li>\n<li>Preserve the safety archive as an explicit rollback source when an update or health check fails.<\/li>\n<\/ul>\n\n<h4>2.4.0<\/h4>\n\n<ul>\n<li>Add guided restore for verified, same-site local backups.<\/li>\n<li>Create and verify a fresh safety backup before restoration begins.<\/li>\n<li>Restore files and database statements in resumable background batches.<\/li>\n<li>Protect wp-config.php and the active Mozzy recovery runner during file restoration.<\/li>\n<li>Add path traversal protection, guarded cancellation, maintenance responses, retries, and post-restore health checks.<\/li>\n<\/ul>\n\n<h4>2.3.0<\/h4>\n\n<ul>\n<li>Build database and file archives in resumable WP-Cron batches.<\/li>\n<li>Persist backup progress across requests and recover stalled jobs automatically.<\/li>\n<li>Add live progress, continue-now and safe cancellation controls.<\/li>\n<li>Retry failed stages three times and remove partial files after cancellation or failure.<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Add manual and scheduled full-site backups with protected local storage.<\/li>\n<li>Add direct Google Drive OAuth and resumable, chunked uploads.<\/li>\n<li>Add archive verification, SHA-256 checksums, execution locking, history, and retention.<\/li>\n<li>Add an extensible destination-provider contract for future storage services.<\/li>\n<\/ul>\n\n<h4>2.1.2<\/h4>\n\n<ul>\n<li>Keep notices from other WordPress plugins outside the Mozzy Assistance hero.<\/li>\n<\/ul>\n\n<h4>2.1.1<\/h4>\n\n<ul>\n<li>Refresh WordPress update information before inventory scans and support third-party update payload formats.<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Include available WordPress, theme and plugin versions in inventory scans.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Add secure one-click account pairing with PKCE.<\/li>\n<li>Store connection credentials in WordPress instead of plugin files.<\/li>\n<li>Start monitoring only after explicit administrator approval.<\/li>\n<\/ul>","raw_excerpt":"Connect WordPress to Mozzy for monitoring and protected local, Google Drive, Backblaze B2, and S3-compatible backups.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/350827","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=350827"}],"author":[{"embeddable":true,"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/mozzzy"}],"wp:attachment":[{"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=350827"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=350827"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=350827"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=350827"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=350827"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es-cr.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=350827"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}