WP Site Migrator
Secure WordPress migration with encrypted backups, WooCommerce-aware sync, and modular cloud storage.
by Kalakavya · github.com/pratikmoitra/wp-site-migrator · website
★ 0stars
0forks
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/pratikmoitra/wp-site-migrator/archive/refs/heads/main.zipA secure, modern WordPress migration plugin with encrypted backups, WooCommerce-aware sync, staging environment management, and modular cloud storage.
Built from scratch as a security-hardened replacement for All-in-One WP Migration.
Features
🔒 Security First
- AES-256-GCM encrypted backups with PBKDF2 key derivation
- HMAC-SHA256 integrity verification on every backup
- CSPRNG for all identifiers — no
uniqid(), norand() - WordPress nonces on every endpoint (REST + AJAX)
- Rate limiting per user via transients
- Zip-slip protection during extraction
- Symlink exclusion to prevent filesystem escape
📦 Smart Backup Engine
- Selective export — choose database, media, plugins, themes independently
- Streamed SQL export/import — handles multi-GB databases without memory issues
- Chunked file encryption — encrypt archives of any size
- Automatic integrity manifest — every backup is cryptographically signed
- Progress tracking via REST API
🔄 WooCommerce Intelligence
- Bi-directional product sync with SKU-based matching
- Conflict detection with configurable strategies (source wins, target wins, skip)
- Price auditor — compare pricing between staging and production
- Order preservation — selective export supporting both HPOS and legacy orders
- Diff reporting — see exactly what will change before syncing
🌐 Environment-Aware Staging
- Automatic environment detection (production, staging, local)
- Payment gateway mode switching — auto-toggle test/sandbox on staging import
- Plugin dependency scanning — detects 15+ API-dependent plugins (Stripe, Razorpay, PayPal, Cashfree, WP Mail SMTP, etc.)
- Import prompts — warns about missing plugins and required API keys
- Email suppression — auto-disables customer emails on staging
- Search engine blocking — auto-sets robots.txt on staging
- Config generation — produces environment-specific
wp-config.phpsnippets
☁️ Modular Cloud Storage
- Local filesystem with
.htaccessprotection and0600permissions - AWS S3 (and S3-compatible: DigitalOcean Spaces, MinIO, Backblaze B2)
- No external SDK required — uses WordPress HTTP API with AWS SigV4 signing
- Pluggable
StorageInterface— add custom adapters
🖥️ WP-CLI Support
# Export
wp site-migrator export
wp site-migrator export --no-media --encrypt
# Import
wp site-migrator import /path/to/backup.smbackup
wp site-migrator import /path/to/backup.smbackup --password=secret
Requirements
- PHP 8.1+
- WordPress 6.0+
- OpenSSL extension (for encryption)
- ZipArchive extension
Installation
As a WordPress Plugin (standard)
- Download the
wp-site-migratordirectory - Upload to
wp-content/plugins/ - Activate in WP Admin → Plugins
Via Composer
composer require kalakavya/wp-site-migrator
Architecture
wp-site-migrator/
├── wp-site-migrator.php # Bootstrap (PHP version check + PSR-4 autoloader)
├── composer.json # PSR-4 autoloading
├── uninstall.php # Safe cleanup
├── src/
│ ├── Plugin.php # Singleton orchestrator
│ ├── Security/
│ │ ├── Encryption.php # AES-256-GCM (string + file)
│ │ ├── Integrity.php # HMAC-SHA256 (string + file + manifest)
│ │ ├── AccessControl.php # Capability + nonce + rate limiting
│ │ └── SecretManager.php # CSPRNG key management
│ ├── Backup/
│ │ ├── BackupManager.php # Export/import orchestrator
│ │ ├── Archiver.php # ZIP with security checks
│ │ ├── DatabaseExporter.php # Batched SQL export
│ │ └── DatabaseImporter.php # Streamed SQL import
│ ├── Storage/
│ │ ├── StorageInterface.php # Pluggable contract
│ │ ├── LocalStorage.php # Filesystem adapter
│ │ └── S3Storage.php # AWS S3 / compatible
│ ├── Migration/
│ │ ├── URLRewriter.php # Serialization-safe URL replacement
│ │ ├── ConfigSwapper.php # wp-config + table prefix + API keys
│ │ ├── EnvironmentProfile.php # Staging/production profiles
│ │ └── PluginDependencyDetector.php # API plugin scanner
│ ├── WooCommerce/
│ │ ├── ProductSync.php # Bi-directional product sync
│ │ ├── OrderPreserver.php # Order export with HPOS support
│ │ └── PriceAuditor.php # Price comparison engine
│ └── Admin/
│ ├── AdminPage.php # WP Admin UI
│ └── RestController.php # REST API (7 endpoints)
├── assets/
│ ├── css/admin.css
│ └── js/admin.js # wp.apiFetch + environment dashboard
└── tests/
├── bootstrap.php
└── Unit/
├── EncryptionTest.php # 10 test cases
├── IntegrityTest.php # 8 test cases
├── SecretManagerTest.php # 3 test cases
└── URLRewriterTest.php # 4 test cases
REST API Endpoints
| Method | Endpoint | Description |
|---|---|---|
POST |
/site-migrator/v1/export |
Create a backup |
GET |
/site-migrator/v1/backups |
List all backups |
DELETE |
/site-migrator/v1/backups/{filename} |
Delete a backup |
GET |
/site-migrator/v1/status |
Plugin & environment status |
GET |
/site-migrator/v1/environment |
Full environment profile |
GET |
/site-migrator/v1/plugins/scan |
API plugin dependency scan |
POST |
/site-migrator/v1/environment/switch |
Toggle staging/production mode |
All endpoints require export capability and WordPress REST nonce authentication.
Import/Export Lifecycle
Export
- Scan environment → capture payment gateways, API plugins, environment type
- Export database (batched, memory-safe)
- Collect files (selective: media, plugins, themes)
- Create ZIP archive (with zip-slip protection, symlink exclusion)
- Sign with HMAC-SHA256 integrity manifest
- Optionally encrypt with AES-256-GCM
- Store to configured backend (local / S3)
Import
- Verify integrity manifest (HMAC)
- Decrypt if encrypted (PBKDF2 + AES-256-GCM)
- Extract archive (with zip-slip validation)
- Read source environment profile
- Check plugin dependencies — warn about missing API plugins
- Rewrite URLs (handles serialized PHP, JSON-escaped, protocol-relative)
- Rewrite table prefixes if different
- Import database
- Restore files
- Auto-configure environment — switch payment gateways, emails, debug flags
- Flush caches
Security Comparison
| Vulnerability | AIO WP Migration | WP Site Migrator |
|---|---|---|
| Secret comparison | !== (timing attack) |
hash_equals() |
| Random identifiers | uniqid() + rand(100,999) |
random_bytes() |
| CSRF protection | None | WordPress nonces |
| Backup encryption | None | AES-256-GCM |
| Integrity verification | None | HMAC-SHA256 manifest |
| Rate limiting | None | Per-user transients |
| Zip-slip protection | None | Path traversal validation |
| Symlink safety | None | Excluded from archives |
| Error suppression | @ operator everywhere |
Proper try/catch |
License
GPL-3.0-or-later