Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
WordPress Backup & Migration Plugin Duplicator provides a simple way to move WordPress sites, create reliable backups, or clone a site for staging. With Duplicator, you can easily migrate, transfer, or clone your WordPress site between domains or hosts with no downtime. Create full backups of your website, or package your entire site to download and install elsewhere with only a few steps. At Duplicator, reliabilty, security, and ease of use are our top priorities. Our variety of cloud backup integrations and easy migration wizard make Duplicator the most beginner-friendly backup and migration plugin on the market. You don’t have to hire a developer. Create a backup and migrate sites in just a few minutes. Duplicator Pro This plugin is the Lite version of Duplicator Pro, which comes with scheduled backups, cloud storage integrations, multisite support, and more. Get Duplicator Pro for the complete migration and backup solution. Easy Site Migration, Backup, and Cloning Duplicator streamlines site migrations by packaging your website files and database into a single file, known as a “backup”. Download and re-install your “backup” on any new WordPress location or server without dealing with complicated setups. Launch at your new destination without installing WordPress. Duplicator is the only migration and backup plugin that works on an empty site. See why experts love Duplicator: “Duplicator provides an easy to use tool to make backups of your site, or to transfer it to another location.” Richard McAdams – Expert Web Developer Secure WordPress Backups Duplicator offers cloud WordPress backups with military-grade encryption. Automatically backup your entire WordPress site to secure cloud storage. Recovery Points (1-click Restore) Duplicator makes 1-click restores for WordPress backups easy and stress-free. Quickly restore your entire website in minutes just like a time machine. Fast WordPress Migrations Duplicator makes WordPress website migrations fast and stress-free. Quickly move to a new host, domain, or server. No downtime, no data loss, and no coding required. WordPress Multisite Backups Duplicator offers automatic WordPress Multisite backups with easy 1-click restore. Safely backup your entire Multisite network to secure cloud storage. WooCommerce Backups Duplicator offers reliable WooCommerce backups with military-grade encryption. Easily and automatically back up your entire online store to secure cloud storage. Pre-configured WordPress Installs Never start from scratch with Duplicator’s smart pre-configured WordPress installs. Save time and hassle duplicating ready-made sites with 1-click. WordPress Recovery Points with Quick Rollbacks Duplicator offers hourly recovery points and 1-click rollbacks for WordPress sites. Quickly and automatically recover from failed WordPress updates or disasters. Partial WordPress Backup Plugin Duplicator makes partial backups for WordPress quick and easy. Save storage and restore sites faster with database-only, media-only, or completely custom backups. Server to Server WordPress Migration Import Tool Duplicator makes server-to-server WordPress migrations fast and hassle-free. Quickly import your website to a new server in minutes. No downtime, no data loss. Smart WordPress Migration Wizard Duplicator’s smart WordPress migration wizard makes transferring your website to a new host or server effortless. No downtime, no data loss, and no code required. Drag & Drop Import WordPress Website Tool Migrating WordPress sites has never been easier with Duplicator’s drag & drop import tools. Quickly transfer your site to a new host or server in minutes, no code required. Clone WordPress Website Plugin Duplicator clones your entire WordPress website with 1-click, no code needed. Perfect for staging sites, sandbox, or site migration. WordPress Staging Site Duplicator Pro lets you create a WordPress staging site directly from your WordPress dashboard. Safely test plugin updates, theme changes, and new features on a staging environment before pushing changes to your live site. No manual setup, no separate hosting, and no risk to your production site. Duplicator Pro Features Duplicator Pro takes Duplicator to the next level with features you’ll love, such as: WordPress staging sites – create a staging copy of your site to safely test changes before going live Drag and Drop installs – just drag the backup file to the destination site! Scheduled backups Cloud Storage to Dropbox Backups, Google Drive Backups, Microsoft OneDrive Backups, Amazon S3 Backups and FTP/SFTP Backups Custom Backups and Cloning: want just plugins, or just themes, just the database? No problem! A special 2-step streamlined installer mode for mega-fast installs Recovery Points added for very fast emergency site restores Support for managed and shared hosts such as WordPress.com, WPEngine, GoDaddy Managed, and more Multi-threaded to support larger websites & databases Migrate an entire multisite WordPress network or a sub site as a standalone site Database and user creation in the installer with cPanel API Connect to cPanel directly from the installer Custom plugin hooks for developers Advanced permissions Email notifications Professional support … and much more! Supported Backup Cloud Storage Integrations We support any Amazon S3 compatible storage providers plus these first-party integrations. Localhost Backups FTP/ SFTP Backups Dropbox Backups Google Drive Backups Microsoft OneDrive Backups Amazon S3 Backups Cloudflare R2 Backups Wasabi Backups Dream Objects Backups Vultr Backups Digital Ocean Spaces Backups Google Cloud Storage Backups Backblaze B2 Storage Backups Linode Object Storage Backups You can easily see why Duplicator is the best WordPress backup and migration plugin on the market! Want to unlock these features? Upgrade to our Pro version Branding Guidelines Duplicator® is a registered trademark of Snap Creek LLC. When writing about the backup & migration plugin by Duplicator, please make sure to uppercase the initial first letter. Duplicator (correct) duplicator (incorrect)
Top keywords
- wordpress35×3.91%
- backups34×3.80%
- duplicator32×3.58%
- site19×2.12%
- backup16×1.79%
- migration12×1.34%
- storage11×1.23%
- cloud9×1.01%
- website9×1.01%
- sites8×0.89%
- cloud storage7×0.78%
- entire7×0.78%
Tempmails
Self-hosted. Privacy-first. Fully yours. Tempmails turns your WordPress site into a self-hosted temporary email service. Visitors generate a random disposable email address, receive messages in a real-time inbox, and discard them when done — all without leaving your site. Unlike third-party services, Tempmails runs entirely on your own server and IMAP mailbox. You own the data, the domain, and the brand. 🔒 No third-party email APIs 📬 Real IMAP inbox — not a simulation 🎨 Material Design 3 UI — beautiful out of the box ⚡ AJAX-powered — no page reloads 🚀 Quick Links Everything you need to get started, get help, and stay connected: 🌐 Official Website — tempmails.cv — docs, roadmap, and addon announcements 🎬 Installation Tutorial — Watch the step-by-step video guide below 📺 YouTube Channel — NeoSmartApps on YouTube — tutorials, walkthroughs, and new release demos ☕ Support the Project — Buy us a coffee via PayPal — Tempmails is free forever; your support keeps development alive 🖥️ Need Hosting? — Tempmails works best on a VPS or shared host with catch-all IMAP support. We recommend Hostinger (affiliate link — we earn a small commission at no extra cost to you) 🎬 Watch: Full Installation Tutorial Core Features 📨 Email Engine IMAP Email Fetching — connects to any catch-all IMAP mailbox Auto Email Generation — random disposable addresses on your own domains Real-time Inbox — AJAX-powered message viewer with configurable auto-refresh Attachment Support — download files with 40+ allowed extensions 🎨 Design & UI Material Design 3 UI — modern, responsive inbox with Inter & Poppins fonts White-labeled — fully rebrandable, no third-party branding in the UI Design Panel — live color picker and label customization in admin 🛡️ Privacy & Data Soft Delete — messages are never hard-deleted; safe for compliance Cookie-based sessions — no user accounts or registration required Zero external data transmission — all data stays on your server ⚙️ WordPress Native Uses WP database, cron, options, nonces, and security APIs throughout Settings API compliant admin panel Full i18n/l10n support with .pot file included Shortcode Place the inbox anywhere on your site with one shortcode: [tempmails_inbox] This renders the full inbox UI — email generation, copy button, auto-refresh, message list, and message viewer modal. Addon Ecosystem Tempmails Core is frozen infrastructure. All new functionality is delivered via addons using a documented, stable hook system — your site never breaks on Core updates. Available addon hooks cover: email generation, message routing, inbox access control, multi-domain support, billing integration, and more. See the Hooks section below for the full reference. Privacy Tempmails stores temporary email addresses in browser cookies to maintain inbox sessions between page loads. No personal data is collected, stored against user accounts, or transmitted to any external service. See External Services below for details on the optional GitHub ecosystem feed. Hooks Tempmails exposes a complete hook system for addon developers. All hooks below are stable and frozen — they will not be renamed, removed, or have their signatures changed in any minor version. Action Hooks tempmails_loaded — Core fully initialized; safe for addon bootstrap tempmails_core_ready — fires after DB integrity check; passes Core version string tempmails_activated — fires on plugin activation; safe for addon setup tempmails_deactivated — fires on plugin deactivation tempmails_email_generated — new address generated; params: $email, $ip tempmails_inbox_accessed — user opened inbox; params: $email, $ip tempmails_message_received — new message stored; params: $message_id, $to_address tempmails_message_marked_seen — message read; params: $message_id tempmails_message_deleted — soft delete triggered; params: $message_id, $email tempmails_cleanup_completed — cron cleanup finished; params: $deleted_count tempmails_fetch_completed — fetch cycle finished; params: $results array Filter Hooks tempmails_registered_addons — register your addon for the Addons admin page tempmails_generated_email — modify a generated address before returning it tempmails_available_domains — modify the domain list available for generation tempmails_can_fetch_messages — allow/block a fetch cycle; params: $bool, $engine tempmails_can_process_message — allow/block a single message; params: $bool, $message tempmails_can_store_message — allow/block DB insert; params: $bool, $data tempmails_can_read_inbox — allow/block inbox access; params: $bool, $email tempmails_message_content — filter body before display; params: $content, $message_id tempmails_default_settings — modify default option values on activation tempmails_inbox_attributes — modify shortcode default attributes tempmails_admin_dashboard_stats — extend dashboard stat cards tempmails_settings_tabs — add custom tabs to the Settings page External Services Ecosystem Feed (Optional — Default On) Tempmails fetches a public JSON file from GitHub to display addon and ecosystem information inside the WordPress admin panel. What this connection does: Fires only when viewing Tempmails admin pages Retrieves only public, non-personal JSON content Transmits no user data, site URL, or any identifiable information Results are cached locally for 1 hour to minimize requests Remote endpoint: https://raw.githubusercontent.com/ubermensch-site/tempmails-ecosystem/main/ecosystem.json Service provider: GitHub Privacy policy: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement To disable this connection entirely, uncheck Ecosystem Feed under Tempmails → Settings → General. Hardcoded fallback content is shown instead — no requests are made. Google Fonts The frontend inbox loads the Inter and Poppins typefaces and the Material Symbols icon font from Google Fonts CDN. What this connection does: Fires only on pages where [tempmails_inbox] is rendered Transmits the visitor’s IP address to Google as part of a standard font request Service provider: Google Fonts Privacy policy: https://developers.google.com/fonts/faq/privacy To avoid this (e.g. for GDPR compliance), dequeue tempmails-google-fonts and load self-hosted font copies instead. Developers This section documents internal implementation details, security practices, and notes for addon developers. Security Hardening Log All security changes are tracked here for auditing purposes. 2026-04-04 — Security Review Pass (v1.0.7 patch) class-core.php — ajax_delete_message(): $_POST['message_id'] was wp_unslash()-ed but not sanitized, with a phpcs:ignore suppression comment masking the warning. Now wrapped with sanitize_text_field( wp_unslash( … ) ). Suppression comment removed. 2026-04-02 — Security Review Pass (v1.0.7 patch) class-design.php — Removed raw echo from render_page(). Static CSS moved to assets/css/admin.css. class-design.php — inject_css_variables() refactored: replaced echo “…” with wp_add_inline_style('tempmails-admin', ...). All $v() return values now pass through esc_attr(). class-design.php — inject_frontend_css_variables() refactored: all CSS values escaped with esc_attr(), wp_strip_all_tags() applied. class-design.php — wp_footer fallback replaced raw echo ' ' with a dummy registered style handle. class-tempmails-shortcodes.php — Inline replaced with wp_add_inline_script(‘tempmails-frontend’, …). class-ecosystem.php — Inline replaced with wp_add_inline_script(‘tempmails-admin’, …). class-core.php — ajax_mark_seen(): sanitized with sanitize_text_field( wp_unslash( … ) ). class-admin.php — save_settings(): Raw $_POST replaced with $clean_post = array_map(‘sanitize_text_field’, wp_unslash($_POST)). class-email-generator.php — get_emails(): Cookie data sanitized with array_values(array_filter(array_map('sanitize_email', $raw))). Addon Development Notes Hook Stability Guarantee All hooks listed in the == Hooks == section are frozen. Signatures will not change in any 1.x release. Breaking changes will only occur in a major version bump with a migration guide. $clean_post in save_settings hooks As of the 2026-04-02 security patch, both tempmails_before_save_settings and tempmails_before_save_imap_settings receive a sanitized copy of $_POST. If your addon previously relied on raw values via these hooks, retrieve those fields directly from $_POST with appropriate sanitization. CSS Variable Injection inject_css_variables() now attaches inline CSS to the `tempmails-admin` style handle. If your addon dequeues tempmails-admin, Design color variables will not be applied on admin pages. inject_frontend_css_variables() uses a priority waterfall: 1. Attaches to tempmails-frontend if registered/enqueued 2. Falls back to tempmails-frontend-css 3. Registers a dummy handle tempmails-design-vars in wp_footer at priority 1 File Structure tempmails/ ├── assets/ │ ├── css/ │ │ ├── admin.css │ │ ├── frontend.css │ │ └── ecosystem.css │ └── js/ │ ├── admin.js │ ├── admin-design.js │ └── frontend.js ├── core/ │ ├── class-core.php │ ├── class-admin.php │ ├── class-design.php │ ├── class-ecosystem.php │ ├── class-email-generator.php │ └── class-addon-handler.php ├── includes/ │ ├── class-tempmails-shortcodes.php │ ├── class-tempmails-database.php │ ├── class-tempmails-settings.php │ ├── class-tempmails-imap.php │ └── class-tempmails-fetcher.php └── tempmails.php