Description
Geckada brings monitoring, backups and maintenance into one WordPress plugin.
- See site health, errors and backup status in your Geckada account.
- Back up your files and database locally, to Google Drive, Backblaze B2 or an S3-compatible service. Cloud backups go directly from WordPress to your chosen provider.
- Choose optional encryption and keep your recovery key safe. Keep every part of a backup set together to restore it.
- Update plugins, themes and WordPress after Geckada makes a verified safety backup. Approved remote updates can roll back automatically if checks fail.
- Add optional light or dark admin branding, and adjust comments, emoji assets and revisions in Site Tuner.
Local backup and restore work without a Geckada account. To use hosted monitoring or remote management, open Geckada > Overview, select Connect to Geckada and approve the site. The plugin contacts Geckada only after you connect it or save a connector token. See External services and Privacy below for details.
External services
Geckada
The plugin contacts https://geckada.au only after an administrator connects the
site or manually saves a connector token. It sends the monitoring and backup
status and maintenance progress listed in the Privacy section to provide the
Geckada monitoring and maintenance service. Heartbeat responses can contain managed
backup settings and requests, approved maintenance updates, or automatic rollback
commands as described in the FAQ. Easy Google Drive connection also sends authorization
requests and the selected folder ID/name to Geckada. Geckada stores an encrypted Google
refresh token and issues short-lived access tokens to the authenticated website.
Geckada does not receive backup archives, object-storage secrets, or recovery keys.
When you submit Contact Geckada, your topic, message and reply email are saved in
Geckada’s support inbox and linked to your connected project. An email notification
is sent by Geckada, not by WordPress. WordPress, PHP and Geckada version numbers are
included only if you select the optional technical-details checkbox.
Geckada privacy policy: https://geckada.au/privacy
Geckada terms: https://geckada.au/terms
Google Drive
After an administrator selects Connect Google Drive, Geckada handles Google consent
and folder selection. Authorization codes and tokens pass through Geckada; backup
files upload directly from WordPress to Google. Disconnect removes this website’s
Geckada grant without deleting Drive files or disconnecting other websites. You can
also revoke Geckada in your Google account permissions.
Advanced setup uses your own Google application with tokens held in WordPress.
Both modes use
https://accounts.google.com for authorization, https://oauth2.googleapis.com for
OAuth token exchange and revocation, and https://www.googleapis.com for Drive
file operations. OAuth identifiers, authorization codes, access and refresh
tokens, backup archives, filenames, sizes, checksums, and plugin-created folder
metadata are sent directly to Google as required to store, list, download, and
remove retained backups in the administrator’s Drive account.
Google privacy policy: https://policies.google.com/privacy
Google terms: https://policies.google.com/terms
Backblaze B2 and S3-compatible storage
The plugin contacts an object-storage service only after an administrator saves
its HTTPS endpoint and credentials. It sends signed S3 API requests, the access
key identifier, backup archives, filenames, sizes, and storage metadata directly
to that endpoint to test the connection and to store, list, download, and remove
retained backups. The secret key remains stored encrypted in WordPress and is
used locally to sign requests. Supported services include Backblaze B2, Amazon
S3, Cloudflare R2, Wasabi, DigitalOcean Spaces, and other administrator-selected
S3-compatible services. Use of a configured service is governed by that
provider’s terms and privacy policy.
For Amazon S3, the standard API endpoint is https://s3.amazonaws.com. An Amazon
Web Services account, an S3 bucket, an access key ID, and a secret access key are
required. Administrators must explicitly enter their provider’s HTTPS endpoint;
the plugin does not prefill or contact one merely by being activated or viewed.
Requests begin only after an administrator saves the destination and explicitly
tests it or runs a backup, recovery, retention, or restore operation. This is an
optional storage API integration, not a source of remotely loaded JavaScript,
CSS, images, fonts, or executable code.
Backblaze privacy: https://www.backblaze.com/company/policy/privacy
Backblaze terms: https://www.backblaze.com/company/policy/terms-of-service
AWS privacy: https://aws.amazon.com/privacy/
AWS service terms: https://aws.amazon.com/service-terms/
Cloudflare privacy: https://www.cloudflare.com/privacypolicy/
Cloudflare terms: https://www.cloudflare.com/terms/
Wasabi privacy: https://wasabi.com/legal/privacy-policy
Wasabi terms: https://wasabi.com/legal/terms-of-use
DigitalOcean privacy: https://www.digitalocean.com/legal/privacy-policy
DigitalOcean terms: https://www.digitalocean.com/legal/terms-of-service-agreement
Privacy
When connected and enabled, the plugin sends data to https://geckada.au. Data can
include health heartbeats; WordPress, PHP, theme and plugin names and versions;
active plugin status; fatal error messages, file locations, line numbers and the
affected URL; database error messages; backup state, progress, filenames, sizes
and destination labels; maintenance command identifiers, update and rollback
progress, results and backup filenames; failed email events; and supported
scheduled-task failures.
The plugin does not intentionally send passwords, cookies, form contents,
database records, WordPress users, visitor IP addresses, backup archives, object-storage
credentials or recovery keys. Easy Google Drive connection stores encrypted Google
authorization credentials and destination metadata on Geckada. Review Geckada’s privacy policy at
https://geckada.au/privacy and terms at https://geckada.au/terms.
Installation
- Install and activate Geckada.
- Open Geckada > Overview.
- Select Connect to Geckada.
- Sign in to Geckada and choose or create a project.
- Confirm the connection test in WordPress.
Administrators can alternatively paste a connector token from Geckada. Monitoring
can be paused and local credentials can be removed from the settings page.
Verified local backups can be restored from Geckada > Backups. Manual
guided restore requires explicit administrator confirmation, creates a fresh safety
backup first, preserves wp-config.php and the active Geckada recovery component,
restores in background batches, and finishes with database and filesystem checks.
Website activation
Connecting to Geckada activates this website against its project using a private
connection token. Each project can activate one WordPress website. Your account’s
project allowance controls new activations. Existing connections remain active
when a plan limit is lowered. Remove a connection in Geckada to revoke its token;
disconnecting in WordPress removes the local credentials. Local backup and restore
features remain available without a Geckada activation. Activation status and plan
allowances refresh with successful monitoring heartbeats. Existing clients remain
compatible; upgrading adds website-URL checks to monitoring requests.
FAQ
-
When does the plugin start contacting Geckada?
-
Only after a WordPress administrator approves the connection or saves a connector
token. Deactivating the plugin stops its scheduled events. The connection can also
be paused or disconnected from Geckada > Overview. -
What can Geckada remotely control?
-
When an administrator enables managed backups, Geckada can supply the schedule,
retention and backup preset and request a new backup through the authenticated
heartbeat. WordPress performs every backup locally and uploads directly to the
configured destination.Maintenance Autopilot also lets an authorized Geckada user approve specific plugin,
theme, and WordPress core update versions. Geckada sends these limited maintenance
commands through heartbeat responses. WordPress checks that the requested
versions are still available and creates and verifies a full safety backup before
applying updates; connected remote backup uploads must also succeed.If post-update verification fails, Geckada can request an automatic rollback using
the verified pre-update archive. WordPress validates that archive against its
protected-update history and creates a failed-state safety backup before
restoring it. Automatic rollback does not require a separate confirmation in
WordPress. Manual guided restores still require explicit confirmation from a
logged-in WordPress administrator.These commands are limited to the plugin’s backup, update, and rollback workflows;
they do not provide a general-purpose remote shell or arbitrary file editor.
Recovery keys and object-storage credentials remain in WordPress. Easy Google Drive
connection keeps the Google refresh token encrypted on Geckada; WordPress requests
short-lived access for direct uploads. Advanced Google setup keeps its credentials
in WordPress. Recovery keys and archives are not sent to Geckada. Any archive
decryption required for restoration happens locally. -
What happens if I lose an encrypted backup recovery key?
-
Geckada cannot decrypt the archive and does not receive a copy of the key. Download
and securely retain every recovery-key file, including older keys kept after a
rotation. Importing the matching key makes its encrypted archives restorable.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Geckada” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Geckada” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
3.2.161
- Shorten the plugin description and update links to geckada.au.
3.2.160
- Use Geckada as the plugin name in WordPress, the readme, and backup messages.
3.2.159
- Show every recent backup record in a scrollable list so deleted rows no longer appear to be replaced by older backups. Name the deleted backup in the confirmation notice.
3.2.158
- Improve contrast and use Geckada colours throughout the live backup progress header.
3.2.157
- Clarify how the five newest backups refill after a deletion and report failed history updates.
3.2.156
- Match the product page scrollbar to Geckada as well as the nested backup selection list.
3.2.155
- Match long backup selection scrollbars to Geckada and keep selected retention numbers white.
3.2.154
- Shorten the Backups header to Geckada and refresh the Advanced icon and accordion hover colours.
3.2.153
- Restore assets on the Geckada Backups, Branding, Site Tuner and Access pages after the menu rename.
- Apply the Geckada palette to product controls; only Save Branding changes on the Branding page.
3.2.152
- Complete the Geckada wording on the Overview plan cards.
3.2.151
- Use the complete Geckada wordmark in Overview and apply its pink-to-coral palette to plugin controls.
- Keep the supplied white WebP mark in the WordPress sidebar.
3.2.150
- Rebrand the WordPress menu, screens, and supplied logos to Geckada.
3.2.149
- Show PHP requirements expanded by default in Overview.
3.2.148
- Combine Overview resources into a compact bordered grid with shared dividers and responsive columns.
3.2.147
- Keep plugin sidebar image icons in their original colours with a contrasting rounded badge, including selected and collapsed states.
3.2.146
- Open workspace branding using the connected project’s canonical owner and workspace URL; guide missing connections to Overview.
3.2.145
- Add a compact workspace branding description and direct link below the admin branding toggle.
3.2.144
- Style plugin and theme ZIP upload panels and native file chooser buttons with the selected custom admin palette, including responsive layouts.
3.2.143
- Pin Collapse Menu to the bottom of the custom admin sidebar, keeping the navigation above it scrollable in expanded and compact modes.
3.2.142
- Add Lucide and Phosphor Regular icon families to Branding, with live previews and matching sidebar, toolbar and Collapse Menu icons.
- Bundle selected SVGs and licenses locally; keep the current icon choice and Material Rounded default.
3.2.141
- Add 16px breathing room above sticky Branding actions in custom and standard admin modes, with scrolling content masked behind the gap.
3.2.140
- Keep automatic plan sync working when the compact Overview has no Refresh button or feedback element.
- Fix logo and favicon chooser labels in Branding.
- Add an aligned Collapse Menu icon, with compact expand mode and the selected icon style.
3.2.139
- Choose Google Material Rounded, TwentyTwo or WordPress original navigation icons in Branding, with a preview before saving.
- New branding configurations default to locally bundled Material Rounded icons; existing configurations keep TwentyTwo until changed.
3.2.138
- Share custom admin colours with Fonts and editor controls, progress indicators, spinners and update notices.
- Remove custom admin focus outlines and correct theme detail modal placement.
- Animate theme detail navigation in the selected direction, respecting reduced motion.
3.2.137
- Apply custom admin colours to the active theme footer and Add Theme hover and focus states.
3.2.136
- Use font weight 500 for WordPress page headings in the custom admin UI.
3.2.135
- Make sidebar menus more responsive with 300ms hover opening, 150ms animation, and 250ms closing grace in both modes.
- Keep keyboard opening immediate and respect reduced motion preferences.
3.2.134
- Remove the WordPress hover inset shadow that obscures the left edge of selected parent menu buttons.
- Keep existing sidebar spacing and a visible keyboard focus outline.
3.2.132
- Share sidebar icon colours across selected and collapsed hover states, including the Geckada logo.
- Add isolated plugin icon compatibility with a readable themed Brevo monogram.
3.2.131
- Match secondary WordPress toolbar dropdown groups to the custom admin theme.
3.2.130
- Keep the block editor header and save panels below the branded admin toolbar.
3.2.129
- Refine Branding confirmations and keep the dismiss button inside the toast with branding on or off.
3.2.128
- Align tool heading weights and Branding intro spacing with Overview and Site Tuner.
- Keep Branding confirmations above the header.
- Share the Backups shell border, radius, and light background across Overview, Site Tuner, and Access.
3.2.127
- Match Save Branding to the Geckada backend orange in idle, hover, focus, and saving states.
3.2.126
- Require confirmed uploads, fresh reverse health checks, and site detail sync before reporting a verified connection.
- Show unverified or attention states when the server cannot confirm both directions; expire old verification results.
- Return a fresh health challenge so cached pages cannot pass verification.
3.2.125
- Match primary buttons to the Geckada backend blended orange, brighter hover, and soft shadow.
- Align product links and accent text with the backend orange palette.
- Combine site details sync into Test connection and remove the separate sync action.
- Match the welcome logo to the Geckada login wordmark.
- Remove top padding from the welcome screen on desktop and mobile.
- Show Overview connection status only after connecting a website.
- Refresh Overview and Backups with the light Geckada palette, warm surfaces, and quieter controls.
- Match destination test buttons to the scheduled-backup control.
- Default downloaded connectors to the live Geckada service.
3.2.119
- Refine agency branding across WordPress admin screens, editors, notices, navigation, and the admin toolbar.
- Clarify plan access, account branding reset, upgrade offers, and subscription copy on the Overview screen.
3.2.94
- Apply and acknowledge agency branding when Geckada wakes a connected site after publishing, using the existing signed connector request.
3.2.93
- Match the selected sidebar pointer to the dark sidebar and the unselected flyout pointer to its link text.
3.2.92
- Complete dark styling for classic post and page editing, Yoast, category tabs, media controls, Fonts, file editors, themes, and plugin directory screens.
- Match dark-mode selection controls and sidebar pointers to agency branding, and replace focus outlines on links and buttons with state changes.
3.2.91
- Refine dark mode across WordPress and WooCommerce admin screens, including Geckada Backups and Access tables and WooCommerce Payments.
3.2.90
- Replace remaining pale borders and dividers across WordPress lists, editors, Menus, Dashboard widgets, and installed plugin settings in dark mode.
3.2.89
- Match the active sidebar pointer and Dashboard panel borders to dark admin branding.
3.2.88
- Expand dark admin branding across WordPress core tables, Dashboard panels, Themes, and common plugin interfaces.
3.2.87
- Match the connected Overview dashboard to dark admin branding, including readable cards, links, status pills, and details.
3.2.86
- Receive versioned agency login and admin branding from selected Geckada projects on the authenticated heartbeat.
- Keep project overrides and unrelated WordPress settings, reuse validated image uploads, and show the managing agency and last sync in Branding.
3.2.85
- Add owner-managed section access for selected administrators and enforce Geckada action permissions.
3.2.84
- Exclude Geckada from the Plugin File Editor plugin selector.
3.2.83
- Hide the profile Administration Color Scheme picker while admin branding is enabled.
3.2.82
- Add a compact session login dialog with a honeycomb glass overlay and cross-tab session checks.
3.2.80
- Round and clip agency favicon previews to match logo previews.
3.2.79
- Use a single Change favicon button after selecting an agency favicon.
3.2.78
- Align Colours from logo with the other branding settings labels.
3.2.77
- Keep Display mode switcher spacing even by removing inherited label margins.
3.2.76
- Add padded white and charcoal backgrounds to light and dark logo previews.
3.2.75
- Colour login notices by status, add icons and dismiss controls, and keep warnings/errors visible until dismissed.
3.2.74
- Use neutral charcoal and grey for dark mode surfaces, toolbar menus, login, and animation previews.
3.2.73
- Replace the Dark mode switch with an explicit Light / Dark Display mode selector.
3.2.72
- Label logo colour matching clearly as Colours from logo and Match logo colours.
3.2.71
- Simplify logo labels and move Use logo colours into Colours & appearance.
3.2.70
- Keep Save Branding beside the page title while scrolling and show Saving with a spinner during submission.
3.2.69
- Replace Studio Light with Soft Spotlight: a diffused, gently tinted 14-second loop on login and all previews.
3.2.68
- Clear thumbnail focus when closing the login background preview.
3.2.67
- Make Aurora drift and Studio Light sweeps more visible on login, live previews, and thumbnail videos.
3.2.66
- Add large live login background previews with play/pause and a selection action.
3.2.65
- Group Branding settings into sections, simplify labels, and give Geckada admin styles priority over queued theme and plugin styles.
3.2.64
- Simplify agency address settings and show map confirmation on a green Address verified! button.
3.2.63
- Split the agency address into street, street type, suburb, post code and state, preserving existing addresses. Add a map popup for owner confirmation and reset confirmation when details change. Use standard Apple Maps links and omit unit numbers from directions searches.
3.2.62
- Make the desktop login contact address a directions link: open the native Maps app on macOS, or Google Maps in a browser tab on Windows and Linux. Keep the existing map buttons on tablet and mobile.
3.2.61
- Browse animated login background previews in a horizontal carousel with arrows, touch scrolling, and a tick on the selected card.
3.2.60
- Derive login background patterns and gradient washes from both branding colours, with softer light-mode tints and brighter dark-mode tints. Update thumbnail tinting as colour inputs change.
3.2.59
- Increase login background motion speed by approximately 20% while keeping continuous linear loops.
3.2.58
- Render login backgrounds as continuous CSS motion to avoid video restart hitches. Keep WebM hover previews in Branding.
3.2.57
- Use matching light and dark WebM loops for login backgrounds and thumbnail previews. Previews play on hover or keyboard focus; the selected login background starts automatically and loops.
3.2.56
- Add five selectable animated login backgrounds with hover and keyboard previews in Branding. Drifting Dots now move horizontally, and reduced-motion preferences pause all patterns.
3.2.55
- Add a small vertical separator after Client access in the login card header.
3.2.54
- Show the login accordion hover background only while a panel is closed.
3.2.53
- Add a subtle grey hover to login accordion headings and smoothly close one panel before opening the other.
3.2.52
- Replace the login card’s return-home chevron with a left arrow and align it 20px from the top and left card edges.
3.2.51
- Add icons to the agency accordions and contact links, move password recovery below the password field, and replace the home button with a back-angle link in the login card.
3.2.50
- Smooth the opening and closing of the agency information accordions on the login page.
3.2.49
- Refine the hexagon outlines in the login and logout transitions with a slightly lighter stroke.
3.2.48
- Animate sign-out from the browser edges toward the centre with frosted-glass hexagons before opening the login page.
3.2.47
- Reveal the dashboard only after the glass honeycomb fills the browser, then unblur and fade the hexagons away as the dashboard fades in.
3.2.46
- Place the agency logo on the left and Client access on the right inside the login form card, with a subtle divider below its header.
3.2.45
- Start the login-to-admin transition with one centered glass hexagon, grow the blurred honeycomb across the dashboard, then clear it from the center outward.
3.2.44
- Replace the creative partner label with Client access beside the logo and left-align the login header.
3.2.43
- Replace the solid login-to-admin reveal with a full-screen, frosted-glass honeycomb that clears from the centre outward, inspired by the FireTail map transition.
3.2.42
- Align the agency logo and “Your creative partner” on one row above Client access on the centered login page.
3.2.41
- Center the branded login and logo, place the creative partner label above Client access, and move agency services and contact details into compact accordions below the login card.
3.2.40
- Show “Logging now..” after submitting the branded login form, then reveal the first backend page with a brief centre-out honeycomb animation.
- Skip the reveal for reduced-motion visitors and on later admin navigation.
3.2.39
- Use border-based keyboard focus styling on the branded login page and Branding image picker buttons instead of an outer outline.
3.2.38
- Add an agency favicon picker in Branding settings for login and wp-admin tabs, without changing the public site icon.
3.2.37
- Show Google Maps and Apple Maps direction buttons on tablet and mobile login layouts only.
3.2.36
- Give the client sign-in card more space and a full-width primary button while softening the agency panel.
3.2.35
- Simplify the client login heading, dismiss logged-out notices after four seconds, and style the password and home links as compact buttons.
3.2.34
- Add a gently drifting dot-grid background to the branded login page, inspired by the managing agency’s homepage, with reduced-motion support.
3.2.33
- Present the managing agency beside client login with services, contact details, website, and address-based Google and Apple Maps directions.
- Refine the login layout and remove thick left-edge notice styling.
3.2.32
- Add a responsive two-column login page with owner-managed services and contact details in Branding settings.
3.2.31
- Show login logos no larger than their uploaded resolution and add a reduced-motion-aware ambient background.
3.2.30
- Colour plugin-owned admin-bar icons from the selected theme on admin and frontend pages.
3.2.29
- Keep the sidebar collapse handle above the scroll fades while preserving the scrolling cues.
3.2.28
- Match all wp-admin toolbar dropdowns to the frontend toolbar in light and dark modes.
3.2.27
- Match the WordPress dashboard welcome panel and login screen to the selected Geckada admin theme and logo.
3.2.26
- Use one shared profile menu style for the WordPress admin and frontend toolbar.
3.2.25
- Give the frontend profile menu a compact account card and add space between the greeting and avatar.
3.2.24
- Place frontend toolbar dropdowns directly below their parent links.
3.2.23
- Centre frontend toolbar links, improve menu contrast in light and dark modes, and keep the uploaded logo clear on hover.
- Keep account controls on the same row when no dark mode logo is selected.
3.2.21
- Match the logged-in frontend toolbar to the selected admin branding, including its logo and light or dark colours.
- Replace black admin bar hover backgrounds with the matching toolbar hover colour.
3.2.20
- Improve narrow-screen controls and present recent backups as cards on phones, with visible actions and a stacked download panel.
- Add a logout icon to the compact admin profile menu.
- Give the sidebar collapse handle a softer, correctly directed horizontal gradient animation, with reduced-motion support.
- Keep the admin bar profile trigger plain and make its account menu compact in light and dark mode.
- Show branding appearance and logo controls only while the admin theme is active, retaining their saved settings when it is off.
- Use “colour” in Branding controls and guidance.
- Place the selected admin bar logo first, ahead of other toolbar items, and hide competing theme logo decoration while Geckada branding is enabled.
- Show one Change logo button after a logo is selected; use the WordPress media picker to choose or upload its replacement.
- Hide the toolbar site name when the selected logo is visible, so the logo takes its place.
- Keep the account profile control on the same toolbar row as the uploaded logo.
- Show logo settings only while admin branding is enabled, retaining saved logos when branding is turned off.
- Rename the inactive appearance setting to “When branding is off.”
3.2.19
- Resolve Plugin Check findings in Branding and Site Tuner request handling.
3.2.18
- Shorten the Close comments description in Site Tuner.
3.2.17
- Show Enable or Disable beside each Site Tuner switch to match its current state.
3.2.16
- Show Remove logo and Use logo colors only when a logo is selected in Branding.
3.2.15
- Hide the Comments status from the admin toolbar when Close comments on posts and pages is enabled.
3.2.14
- Save Branding and refresh the admin page automatically when Geckada admin branding is switched on or off.
3.2.13
- Show Site Tuner check progress in the button and reserve the helper line for errors.
3.2.12
- Present on-demand Site Tuner checks as a ranked findings list with a summary, clear status labels, links, and expandable details.
3.2.11
- Simplify Branding guidance for logo uploads and automatic color suggestions.
3.2.10
- Let administrators choose WordPress or the existing theme appearance when Geckada branding is off.
- Suppress only the known Southern Gulf theme admin design assets while Geckada branding is on.
- Add an administrator-only, request-level branding bypass and scope Geckada styles to its admin body class.
3.2.9
- Add an optional XML-RPC pingback blocker while retaining authenticated XML-RPC methods.
- Add on-demand, read-only checks for autoloaded options, page and object cache, scheduled tasks, and large image uploads.
3.2.8
- Hide Comments from the admin sidebar while the Tuner comment switch is enabled.
3.2.7
- Prefer saturated logo colors over neutral pixels when suggesting a palette.
3.2.6
- Suggest readable primary and secondary colors from a selected light mode admin bar logo.
- Place Overview cards at the top and use the same switch control across Branding and Tuner.
3.2.5
- Let the standard WordPress admin background show around the Geckada Overview cards.
3.2.4
- Remove the grid pattern behind the Geckada Overview and welcome screens.
3.2.3
- Add a reversible Tuner page for post and page comments, emoji assets, legacy head tags, and future revisions.
3.2.2
- Add separate toolbar logos for light and dark mode and an Appearance switch.
- Dismiss the Branding saved-settings notice after four seconds.
3.2.1
- Add optional admin-only branding with a toolbar logo, custom colors, and light or dark mode.
- Restore the standard admin styling when Geckada branding is disabled.
3.2.0
- Replace multipart download dialogs with animated inline download rows and retry handling.
- Stream complete and component ZIP wrappers without recompressing or duplicating backups on disk.
- Preserve original manifest, part checksums and encrypted files for recovery after extraction.
- Show one download row at a time with grouped cards, loading feedback and an animated close control.
- Include all plugins and themes in Essential files while excluding WordPress core; Custom remains configurable.
3.1.149
- Add resumable multipart backups, component archives and manifest-based recovery with adaptive processing.
- Cache source-size estimates and improve backup progress, diagnostics and recovery controls.
- Refresh account plans automatically and verify activations for Geckada-hosted services while preserving local recovery.
- Add private support messaging through Geckada with clearer delivery errors.
- Detect supported active applications and provide native export entry points with bundled product icons.
- Refine Overview, accordion animations, accessibility labels and backup selection controls.
3.1.131
- Add visible warm-coloured scrollbars and an overflow-aware bottom fade to backup-selection lists.
3.1.130
- Apply logo-peach styling to Overview actions and preserve confirmed project metadata across incomplete responses.
- Read project identity from successful API responses and accept both nested and legacy pairing metadata.
3.1.129
- Sanitize backup control inputs, use WordPress deletion APIs and document required native streaming/atomic restore operations.
- Update tested WordPress version and release metadata.
3.1.128
- Use readable website/CMS/component filenames with UTC date, time and unique backup ID. Older backup names remain supported.
- Tune archive sizes independently per component, avoid shrinking on small final parts, and raise the per-part file limit.
- Use more available request time for checkpointed work and record upload and phase timing separately.
3.1.126
- Group file inventories by component using bounded, resumable passes to reduce small backup parts and upload requests.
- Restore accessible Download, Restore and Delete tooltips after recent-backup rows refresh.
3.1.125
- Add a saved per-user Show diagnostics switch under Advanced, off by default. Backup progress and errors remain visible.
3.1.124
- Show backup identity, result and timestamps beside a dismissible diagnostics download button. Export filenames include the backup ID and export time.
3.1.123
- Create bounded, immutable backup parts for database, core, uploads, plugins, themes and other content, with a manifest describing the complete set.
- Verify and stage every part before restoring files; retain support for existing single-file ZIP and encrypted backups.
- Encrypt, transfer, download and retain multipart backups as one logical backup set.
- Cache source-size estimates persistently and refresh them in background after WordPress content and extension changes.
- Respect the host PHP execution limit and record runtime capabilities in diagnostics.
3.1.122
- Bound repeated worker crashes and archive rebuilds, preserve valid ZIP checkpoints on retry, and report worker delays.
- Add downloadable backup timings and reduce compression work for already-compressed media.
3.1.8
- Show Check connection only after Google Drive is connected, replacing the confusing Test Google Drive label.
3.1.7
- Connect Google Drive through Geckada without entering developer credentials in WordPress.
- Create or select a backup destination folder and preserve Advanced Google application setup.
- Keep backup uploads direct and explain how managed Google authorization is stored.
3.1.6
- Explain connection and inventory failures with transport or HTTP error details.
- Allow 15 seconds for manual connection tests and inventory uploads.
- Distinguish enabled monitoring from confirmed uploads and website availability.
3.1.5
- Let connected maintenance requests update directly or create a verified backup first.
- Keep backups enabled by default for existing update requests.
3.1.4
- Start requested maintenance scans through a signed, on-demand wake-up instead of waiting for the next scheduled heartbeat.
- Reject expired and replayed wake-ups, rate-limit requests, and prevent concurrent remote inventory scans.
- Keep the existing heartbeat as a fallback when the wake-up cannot reach WordPress.
3.1.3
- Check for maintenance commands every 30 seconds while an administrator is active in WordPress. Background checks remain every five minutes.
3.1.2
- Let Geckada request a fresh authenticated software inventory before maintenance verification.
- Deduplicate remote inventory commands and retry them safely when a sync fails.
3.1.1
- Store new local backups under the WordPress uploads directory while retaining read access to legacy archives.
- Require explicit object-storage endpoint entry and clarify the optional Amazon S3 account requirements, transmitted data, and activation behavior.
- Document installation-root access required for full-site backup, restore, and WordPress core health checks.
- Clarify Maintenance Autopilot commands, automatic rollback, manual restore confirmation, and maintenance status data sent to Geckada.
3.1.0
- Added Maintenance Autopilot rollback using the exact verified pre-update archive.
- Added a failed-state safety backup, resumable restore progress, and post-rollback verification reporting.
3.0.0
- Add authenticated Maintenance Autopilot commands with exact-version approval.
- Report backup-gated update progress and results to the Geckada maintenance record.
2.9.3
- Document the live schema reads required to export database structures without stale cache data.
- Document the intentional installation-root write performed by an administrator-approved guided restore.
2.9.2
- Resolve all errors and warnings reported by the official WordPress Plugin Check rules.
- Use WordPress file-deletion APIs and document necessary resumable streaming operations.
- Strengthen input sanitization and OAuth redirect validation.
2.9.1
- Load administration CSS and JavaScript through the WordPress enqueue API.
- Improve compatibility with custom uploads and content-directory locations.
- Confirm request authorization checks and external-service disclosures for WordPress.org review.
2.9.0
- Add optional Geckada-managed backup schedules, including monthly and three-month intervals.
- Accept idempotent remote backup requests through the existing authenticated heartbeat.
- Report throttled backup progress and terminal results without sending archives or credentials.
- Keep destination credentials, encryption keys, emergency controls and restores in WordPress.
2.8.1
- Replace the generic WordPress shield menu icon with the Geckada brand mark.
2.8.0
- Move Geckada from Tools into its own top-level WordPress admin menu.
- Add dedicated Overview and Backups child pages.
- Keep backup, recovery, encryption, and protected-update workflows together on the Backups page.
- Correct the Geckada brand mark alignment in the administration header.
2.7.0
- Add optional authenticated XChaCha20-Poly1305 backup encryption using PHP sodium.
- Encrypt and authenticate large archives in resumable, independently verified chunks.
- Add offline recovery-key generation, protected key storage, import, export, and rotation.
- Retain previous keys so encrypted archives remain restorable after rotation.
- Add resumable authenticated decryption before guided restore begins destructive stages.
- Remove plaintext working archives after encryption and decrypted staging files after restore.
- Introduce the .mzb encrypted container while retaining full legacy ZIP compatibility.
- Block encryption when secure sodium support or a recovery key is unavailable.
2.6.0
- Add provider-neutral remote backup catalogue and recovery contracts.
- Browse Geckada-created Google Drive backups from the WordPress administration page.
- Download large remote archives in resumable background chunks with retry and cancellation controls.
- Add SHA-256 and site-identity metadata to new Google Drive backups.
- Verify remote MD5 metadata, SHA-256, ZIP integrity, and same-site identity before enabling guided restore.
- Clean partial recovery files safely and preserve verified copies under normal local retention.
2.5.0
- Add administrator-approved protected updates for plugins, themes, and WordPress core.
- Require a new verified safety backup and successful connected remote upload before updating.
- Apply approved updates one at a time in a recoverable background queue.
- Verify installed target versions, refresh Geckada inventory, and run post-update health checks.
- Preserve the safety archive as an explicit rollback source when an update or health check fails.
2.4.0
- Add guided restore for verified, same-site local backups.
- Create and verify a fresh safety backup before restoration begins.
- Restore files and database statements in resumable background batches.
- Protect wp-config.php and the active Geckada recovery runner during file restoration.
- Add path traversal protection, guarded cancellation, maintenance responses, retries, and post-restore health checks.
2.3.0
- Build database and file archives in resumable WP-Cron batches.
- Persist backup progress across requests and recover stalled jobs automatically.
- Add live progress, continue-now and safe cancellation controls.
- Retry failed stages three times and remove partial files after cancellation or failure.
2.2.0
- Add manual and scheduled full-site backups with protected local storage.
- Add direct Google Drive OAuth and resumable, chunked uploads.
- Add archive verification, SHA-256 checksums, execution locking, history, and retention.
- Add an extensible destination-provider contract for future storage services.
2.1.2
- Keep notices from other WordPress plugins outside the Geckada hero.
2.1.1
- Refresh WordPress update information before inventory scans and support third-party update payload formats.
2.1.0
- Include available WordPress, theme and plugin versions in inventory scans.
2.0.0
- Add secure one-click account pairing with PKCE.
- Store connection credentials in WordPress instead of plugin files.
- Start monitoring only after explicit administrator approval.
