YAWP
Yet Another WordPress Backup Plugin
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/nonatech-uk/wp-backup/archive/refs/heads/main.zipDeclares an update source (https://github.com/nonatech-uk/yawp), so updates arrive through the plugin's own updater.
Readme
YAWP — Yet Another WordPress (Backup) Plugin
Incremental S3 backups with Object Lock for WordPress sites running in containers. Optimised for slow-moving sites — after an initial full backup, incremental backups only run if someone logged in that day.
Features
- Full & incremental backups — tar.gz archive of files + full database dump
- S3 Object Lock — COMPLIANCE mode for immutable, ransomware-proof storage
- Login-triggered incrementals — no login, no backup, no wasted storage
- Scheduled full backups — configurable interval (or manual-only)
- No SDK dependencies — minimal S3 client with SigV4 signing using PHP curl
- Encrypted credentials — AWS secret key stored with XSalsa20-Poly1305 (libsodium)
- GitHub auto-updater — updates via GitHub releases, no WordPress.org listing needed
Requirements
- PHP 7.4+
curlandsodiumextensionsexec()enabled (fortar)- S3 bucket with Object Lock enabled
Installation
cd /path/to/wp-content/plugins/
git clone git@github.com:nonatech-uk/yawp.git
Activate in WordPress admin, then configure under Settings → YAWP Backup.
S3 Bucket Setup
aws s3api create-bucket --bucket yawp-pitstop --region eu-central-1 \
--create-bucket-configuration LocationConstraint=eu-central-1 \
--object-lock-enabled-for-bucket
aws s3api put-bucket-versioning --bucket yawp-pitstop \
--versioning-configuration Status=Enabled
aws s3api put-object-lock-configuration --bucket yawp-pitstop \
--object-lock-configuration '{"ObjectLockEnabled":"Enabled","Rule":{"DefaultRetention":{"Mode":"COMPLIANCE","Days":90}}}'
IAM policy needs: s3:PutObject, s3:GetObject, s3:ListBucket, s3:AbortMultipartUpload, s3:ListMultipartUploadParts. No s3:DeleteObject — COMPLIANCE mode objects can't be deleted anyway.
How It Works
- Activation — schedules a daily WP-Cron event at 03:00 UTC
- Login hook — any
wp_loginsets a date flag inwp_options - Daily check — if no full backup exists, runs full; if login flag is set, runs incremental; otherwise skips
- Backup — exports DB via
$wpdb, creates tar.gz, uploads to S3 with Object Lock headers - Incremental — uses
tar --newerto include only files changed since last backup (always includes full DB)
License
GPL v2 or later. See LICENSE.
Read the full README on GitHub →
Releases
| Tag | Published |
|---|---|
| v1.15.0 | May 9, 2026 |
| v1.14.0 | Apr 14, 2026 |
| v1.13.0 | Feb 25, 2026 |
| v1.12.0 | Feb 17, 2026 |
| v1.11.0 | Feb 17, 2026 |
| v1.6.1 | Feb 16, 2026 |
| v1.6.0 | Feb 16, 2026 |
| v1.5.1 | Feb 13, 2026 |
| v1.5.0 | Feb 12, 2026 |
| v1.4.1 | Feb 12, 2026 |
| v1.4.0 | Feb 11, 2026 |
| v1.3.1 | Feb 11, 2026 |
| v1.2.0 | Feb 11, 2026 |
These releases are tags only. The author does not attach a packaged zip, so there are no download counts to report.