• Resolved Consciousness

    (@consciousness)


    Hello,
    This is probably a simple question…
    After Duplicator has successfully made a duplicate,
    Can (and should) I delete the “wp-snapshots” folder?
    (Or, if not the folder in its entirety, some of its contents?)

    I’ve heard that this may possibly be a security issue to not delete it.

    (Note: I will likely be using Duplicator again sometime in the future to make new duplicates of the updated site (the Duplicator plugin is deactivated but still installed), i.e. would not be exact same duplicate as the time when the wp-snapshots folder got stuff put into it.)

    Thank you for your guidance.

    https://wordpress.org/plugins/duplicator/

Viewing 7 replies - 1 through 7 (of 7 total)
  • Have done this following already without any improve yet:

    1. set the privilege of contain folder and the sub folders / files to 0777;

    Hey @consciousness

    There are no security issues that we know of… However if you have come across a valid technical resource that knows of any open holes please have them contact me directly. The wp-snapshots can be a security issue if you have web directory browsing enabled on the server. This is normally disabled on most hosts. Also you will want to make sure the permission sets are correctly. The files currently use a hash to create a unique name for the files, which in theory could be guessed, however it would be quite difficult as the hash is quite long.

    If you want to create a clean wp-snapshots folder, you don’t have delete the folder just create your packages download them to an offline location and then delete the packages in the interface.

    Hope that helps!

    Thread Starter Consciousness

    (@consciousness)

    This article (3 years old) is where I got that security implication from: http://serverpress.com/news/using-duplicator-to-import-a-live-website/

    So can I delete the wp-snapshots folder,or some its contents, if for nothing else than housekeeping, or is it needed for when I use Duplicator again for a new duplicate of updated site? Or needed for some other reason?

    I see, thxs…

    You should be able to remove the wp-snapshots folder, however if you have packages visible in the UI they will no longer be downloadable, because you would have removed the files they are pointing too. If you delete the folder and then try to create another package it should try and re-create the wp-snapshots folder again.

    Thread Starter Consciousness

    (@consciousness)

    Thank you for your communication.
    What I did was go in and deleted the old packages via the plugin settings and left the rest.

    Ah… That is another way as well 🙂

    Thanks for this guys.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Can/should I delete wp-snapshots folder after duplicate is made?’ is closed to new replies.