{"id":285416,"date":"2026-03-17T10:03:20","date_gmt":"2026-03-17T10:03:20","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/megamanager-connector\/"},"modified":"2026-07-27T17:34:17","modified_gmt":"2026-07-27T17:34:17","slug":"megamanager-connector","status":"publish","type":"plugin","link":"https:\/\/id.wordpress.org\/plugins\/megamanager-connector\/","author":23364777,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.4","stable_tag":"1.3.4","tested":"6.9.5","requires":"5.0","requires_php":"7.4","requires_plugins":null,"header_name":"MegaManager Connector","header_author":"MegaManager","header_description":"Connects your WordPress site to MegaManager for monitoring, backups, cache management, and remote management.","assets_banners_color":"30507a","last_updated":"2026-07-27 17:34:17","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wpmegamanager.com\/wordpress-plugin","header_author_uri":"https:\/\/wpmegamanager.com","rating":0,"author_block_rating":0,"active_installs":10,"downloads":874,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.2":{"tag":"1.2.2","author":"wpsupporting","date":"2026-03-17 10:03:02"},"1.2.3":{"tag":"1.2.3","author":"wpsupporting","date":"2026-03-17 21:52:34"},"1.2.4":{"tag":"1.2.4","author":"wpsupporting","date":"2026-03-17 23:01:59"},"1.2.5":{"tag":"1.2.5","author":"wpsupporting","date":"2026-03-27 12:31:00"},"1.2.6":{"tag":"1.2.6","author":"wpsupporting","date":"2026-03-27 19:12:22"},"1.2.7":{"tag":"1.2.7","author":"wpsupporting","date":"2026-03-28 10:21:18"},"1.2.8":{"tag":"1.2.8","author":"wpsupporting","date":"2026-03-29 15:38:22"},"1.2.9":{"tag":"1.2.9","author":"wpsupporting","date":"2026-04-04 10:50:10"},"1.3.0":{"tag":"1.3.0","author":"wpsupporting","date":"2026-04-12 07:09:12"},"1.3.1":{"tag":"1.3.1","author":"wpsupporting","date":"2026-04-12 13:39:09"},"1.3.2":{"tag":"1.3.2","author":"wpsupporting","date":"2026-05-05 07:28:14"},"1.3.4":{"tag":"1.3.4","author":"wpsupporting","date":"2026-07-27 17:34:17"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3484663,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3484663,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3484682,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3484682,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.0","1.3.1","1.3.2","1.3.4"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3484682,"resolution":"1","location":"assets","locale":"","width":1837,"height":983},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3484682,"resolution":"2","location":"assets","locale":"","width":1831,"height":916},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3484682,"resolution":"3","location":"assets","locale":"","width":1851,"height":975}},"screenshots":{"1":"Dashboard - connected site overview","2":"Cache management panel","3":"Connect token input"}},"plugin_section":[],"plugin_tags":[151,146,2156,5603,2550],"plugin_category":[52,54,59],"plugin_contributors":[248642],"plugin_business_model":[],"class_list":["post-285416","plugin","type-plugin","status-publish","hentry","plugin_tags-backup","plugin_tags-cache","plugin_tags-management","plugin_tags-monitoring","plugin_tags-updates","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-wpsupporting","plugin_committers-wpsupporting"],"banners":{"banner":"https:\/\/ps.w.org\/megamanager-connector\/assets\/banner-772x250.jpg?rev=3484682","banner_2x":"https:\/\/ps.w.org\/megamanager-connector\/assets\/banner-1544x500.jpg?rev=3484682","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/megamanager-connector\/assets\/icon-128x128.png?rev=3484663","icon_2x":"https:\/\/ps.w.org\/megamanager-connector\/assets\/icon-256x256.png?rev=3484663","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/megamanager-connector\/assets\/screenshot-1.png?rev=3484682","caption":"Dashboard - connected site overview"},{"src":"https:\/\/ps.w.org\/megamanager-connector\/assets\/screenshot-2.png?rev=3484682","caption":"Cache management panel"},{"src":"https:\/\/ps.w.org\/megamanager-connector\/assets\/screenshot-3.png?rev=3484682","caption":"Connect token input"}],"raw_content":"<!--section=description-->\n<p>MegaManager Connector allows you to connect your WordPress site to the <a href=\"https:\/\/wpmegamanager.com\">MegaManager<\/a> platform for:<\/p>\n\n<ul>\n<li><strong>Real-time Monitoring<\/strong> - Keep track of your site's health and uptime status<\/li>\n<li><strong>Automated Backups<\/strong> - Schedule and manage full-site cloud backups<\/li>\n<li><strong>Remote Updates<\/strong> - Update plugins, themes, and WordPress core remotely<\/li>\n<li><strong>Cache Management<\/strong> - Clear page, object, and OPcache directly from admin bar or dashboard<\/li>\n<li><strong>Plugin Management<\/strong> - Activate and deactivate plugins from the dashboard<\/li>\n<li><strong>Security<\/strong> - Secure communication with HMAC signatures<\/li>\n<li><strong>Database Optimization<\/strong> - Analyze and optimize database tables remotely<\/li>\n<li><strong>Maintenance Mode<\/strong> - Enable\/disable maintenance mode without writing files<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to the <strong>MegaManager<\/strong> platform API to provide remote site management features. The service is hosted at <code>https:\/\/wpmegamanager.com\/api\/fn<\/code>.<\/p>\n\n<p><strong>What data is sent and when:<\/strong><\/p>\n\n<ul>\n<li><strong>Site Registration (on connect):<\/strong> Your site URL, WordPress version, PHP version, and a generated site secret are sent once when you connect the plugin to MegaManager.<\/li>\n<li><strong>Heartbeat (every 5 minutes while connected):<\/strong> Site ID, WordPress version, PHP version, and site URL are sent to confirm your site is online and reachable. The heartbeat is essential for the connection status feature and runs automatically while the plugin is connected. It does NOT send any content, user data, or analytics \u2014 only basic environment identifiers.<\/li>\n<li><strong>Metrics (hourly, opt-in only):<\/strong> When you enable telemetry in the plugin settings, performance data (TTFB, page size, plugin list, theme, PHP\/WP versions, disk\/database size, activity logs) is sent hourly. This is disabled by default and requires explicit opt-in via the Settings &gt; MegaManager page. You can disable it at any time; the setting takes effect immediately.<\/li>\n<li><strong>Backup operations:<\/strong> During cloud backups, your database and wp-content files are uploaded to MegaManager cloud storage via signed URLs.<\/li>\n<\/ul>\n\n<p><strong>No data is sent until you explicitly connect the plugin<\/strong> by entering a Connect Token from the MegaManager dashboard.<\/p>\n\n<ul>\n<li>Terms of Service: <a href=\"https:\/\/wpmegamanager.com\/terms\">https:\/\/wpmegamanager.com\/terms<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/wpmegamanager.com\/privacy\">https:\/\/wpmegamanager.com\/privacy<\/a><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the megamanager-connector folder to the \/wp-content\/plugins\/ directory<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li>Go to Settings &gt; MegaManager in your WordPress admin<\/li>\n<li>Enter your Connect Token from the MegaManager dashboard<\/li>\n<li>Click \"Connect to MegaManager\"<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20connect%20my%20site%3F\"><h3>How do I connect my site?<\/h3><\/dt>\n<dd><p>After installing the plugin, go to Settings &gt; MegaManager in WordPress admin, enter your Connect Token from the MegaManager dashboard, and click Connect.<\/p><\/dd>\n<dt id=\"is%20my%20data%20secure%3F\"><h3>Is my data secure?<\/h3><\/dt>\n<dd><p>Yes. All communication between your site and MegaManager uses HMAC-signed requests. Your site secret is stored locally and never shared.<\/p><\/dd>\n<dt id=\"what%20caching%20plugins%20are%20supported%3F\"><h3>What caching plugins are supported?<\/h3><\/dt>\n<dd><p>MegaManager Connector supports WP Super Cache, W3 Total Cache, WP Fastest Cache, LiteSpeed Cache, WP Rocket, Autoptimize, SG Optimizer, Hummingbird, WP-Optimize, and Breeze.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20send%20data%20without%20my%20consent%3F\"><h3>Does this plugin send data without my consent?<\/h3><\/dt>\n<dd><p>No. The plugin only sends data after you explicitly connect it. The heartbeat (connection check) runs only while connected. Performance metrics require an additional opt-in via the telemetry toggle in the plugin settings. You can disable telemetry or disconnect entirely at any time.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.4<\/h4>\n\n<ul>\n<li>SECURITY: Restore\/download URLs are now restricted to an HTTPS cloud-storage allowlist (same as uploads), and plugin rollback is limited to official https:\/\/downloads.wordpress.org URLs \u2014 prevents server-side request forgery and installing arbitrary code from an untrusted source.<\/li>\n<li>SECURITY: All management REST endpoints now require a fresh HMAC signature (X-WPMegaManager-Signature + X-WPMegaManager-Timestamp) in addition to the site secret, closing a request-replay gap where a captured header could be reused. Requests older than 5 minutes are rejected.<\/li>\n<li>SECURITY\/PRIVACY: The backup temp directory now includes an index.php guard (blocks directory listing on servers that ignore .htaccess, e.g. Nginx\/LiteSpeed), and the on-disk archive is cleaned up when a backup is auto-failed after a crash \u2014 a full-database dump can no longer linger in the uploads directory.<\/li>\n<li>RELEASE: Download megamanager-connector-v1.3.4.zip \u2014 connector semver stays independent from the MegaManager web app.<\/li>\n<\/ul>\n\n<h4>1.3.2<\/h4>\n\n<ul>\n<li>BACKUP (WordPress): Backup Manager UI under MegaManager \u2014 create cloud backups, list recent jobs, live status and log output, AJAX-driven polling; cron hooks for restore checks and connection status while the site is connected; packaged as includes\/class-backup-manager.php (PHP-only, shared-hosting friendly).<\/li>\n<li>BACKUP (platform): POST \/api\/fn\/plugin-backup \u2014 timing-safe site secret verification, Backblaze B2 S3-compatible signed upload and download URLs (multipart database + wp-content), backup row lifecycle (init \u2192 complete), storage usage against the site backup plan, retention pruning when limits are exceeded, restore job hand-off, audit and failure alerts.<\/li>\n<li>RELEASE: Download megamanager-connector-v1.3.2.zip \u2014 connector semver stays independent from the MegaManager web app.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>RELEASE: MegaManager Connector 1.3.0 \u2014 connector package version line and readme stable tag decoupled from the SaaS app; same API-compatible PHP baseline. Download: megamanager-connector-v1.3.0.zip<\/li>\n<\/ul>\n\n<h4>1.4.4<\/h4>\n\n<ul>\n<li>APP: MegaManager web app 1.4.4 \u2014 Updates overview search filters visible plugin\/theme\/core rows per site; connector WordPress plugin remains v1.2.9 (semver independent from the SaaS app)<\/li>\n<\/ul>\n\n<h4>1.2.9<\/h4>\n\n<ul>\n<li>RELEASE: MegaManager Connector 1.2.9 \u2014 connector version line is independent from the SaaS app; ships with current API-compatible PHP; download zip remains megamanager-connector-v1.2.9.zip<\/li>\n<\/ul>\n\n<h4>1.4.3<\/h4>\n\n<ul>\n<li>NOTE (historical numbering): Previously shipped with app releases under the same number as the web app; connector versioning is now decoupled (see 1.2.9+). GDPR export\/delete\/retention APIs; uptime monitor schema and scheduler; unique email\/domain constraints; notification email dispatch; AI Tasks plugin list UX; Copilot parsing; admin credits TS fixes<\/li>\n<\/ul>\n\n<h4>1.4.2<\/h4>\n\n<ul>\n<li>RELEASE: App and connector semver aligned to 1.4.2; Release Operations shows live app version from build<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>FIX: Pending plugin\/theme\/core updates now collected reliably on cron and manual sync \u2014 load wp-admin plugin.php before update.php, run wp_version_check before wp_update_*, optional forced refresh on dashboard sync; safer new_version parsing for themes\/plugins (PHP 8+)<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>IMPROVE: Broader PHP debug.log level detection (PHP Error, memory limit, max execution time, uncaught Throwable) for monitoring and alerts<\/li>\n<li>FEATURE: Self-hosted MegaManager API: backup pipeline uses plugin-backup on the Node backend with Backblaze B2 (S3-compatible signed URLs); set WPMM_API_BASE to your \/api\/fn base and configure B2_* env vars on the server<\/li>\n<li>FIX: Alerts for PHP log issues can be stored when type is site_health (DB constraint extended in app migrations)<\/li>\n<\/ul>\n\n<h4>1.3.10<\/h4>\n\n<ul>\n<li>FIX: Remote plugin\/theme\/core update no longer reported as success when WordPress upgrader returns false (was treated as success due to !is_wp_error check)<\/li>\n<li>FIX: Reject success when installed version string unchanged after upgrade attempt<\/li>\n<\/ul>\n\n<h4>1.2.7<\/h4>\n\n<ul>\n<li>FEATURE: Auto updates default on for plugins\/themes; configurable check interval (15 min \/ 1 h \/ 12 h \/ daily) replaces maintenance window field in connector settings<\/li>\n<li>RELEASE: Aligned with MegaManager app (cookie consent, add-site connection gate, UI fixes)<\/li>\n<\/ul>\n\n<h4>1.2.6<\/h4>\n\n<ul>\n<li>FIX: Cache clear reporting \u2014 success only when something is actually cleared; OPcache unavailable or failed reset no longer reported as success<\/li>\n<li>IMPROVE: wp-content\/cache cleanup reports deleted file count; expired transients report row counts; skipped layers listed separately<\/li>\n<\/ul>\n\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>FEATURE: Switch User one-time login token support<\/li>\n<li>FIX: Auto-login now uses REST API switch-user endpoint instead of removed legacy wpmm_autologin<\/li>\n<li>FIX: Edge function auth headers corrected to use X-Site-Secret<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>COMPLIANCE: Added wpsupporting to Contributors in readme.txt<\/li>\n<li>COMPLIANCE: Removed define('FS_METHOD', 'direct') \u2014 no longer sets global constant; guides user to wp-config.php instead<\/li>\n<li>COMPLIANCE: Backup manager inline \/ replaced with wp_register_style\/wp_register_script + wp_add_inline_style\/wp_add_inline_script via admin_enqueue_scripts hook<\/li>\n<li>COMPLIANCE: Temp backup directory now uses wp_upload_dir() basedir with plugin-slug subfolder (megamanager-connector\/) instead of hardcoded WP_CONTENT_DIR path<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>SECURITY: Removed all sslverify=false from outbound requests; default SSL verification is now used<\/li>\n<li>STABILITY: Fixed is_plugin_active() fatal errors in cron\/frontend contexts by adding safe include guard<\/li>\n<li>STABILITY: Bounded disk usage scan (max 50,000 files) and media inventory (max 500 images) to prevent cron timeouts<\/li>\n<li>STABILITY: Wrapped RecursiveIteratorIterator in try\/catch for permission-denied safety<\/li>\n<li>CRON: Moved cron_schedules filter into class constructor for reliable early registration<\/li>\n<li>CRON: Ensured five_minutes schedule is always available before wp_schedule_event calls<\/li>\n<li>COMPLIANCE: Fully removed residual handle_autologin() method from plugin code<\/li>\n<li>COMPLIANCE: Updated readme External Services section with heartbeat data details<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>SECURITY: Removed insecure URL-based auto-login mechanism<\/li>\n<li>SECURITY: Hardened REST API permission callbacks for PHP 8+ null safety (returns WP_Error instead of fatal)<\/li>\n<li>COMPLIANCE: Added explicit telemetry opt-in toggle; metrics are disabled by default<\/li>\n<li>COMPLIANCE: Added External Services section to readme.txt with Terms\/Privacy links<\/li>\n<li>COMPLIANCE: Removed all direct wp-content file writes for maintenance mode<\/li>\n<li>COMPLIANCE: Refactored inline CSS\/JS to use wp_enqueue_script\/wp_enqueue_style and wp_add_inline_script\/wp_add_inline_style<\/li>\n<li>COMPLIANCE: Consistent plugin headers and author metadata referencing https:\/\/wpmegamanager.com<\/li>\n<li>FIX: Replaced direct emoji characters in PHP with HTML entities for shared-hosting compatibility<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Added backward-compatible remote backup support and command routing fixes<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<\/ul>","raw_excerpt":"Connects your WordPress site to MegaManager for monitoring, backups, cache management, and remote administration.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/285416","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=285416"}],"author":[{"embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wpsupporting"}],"wp:attachment":[{"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=285416"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=285416"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=285416"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=285416"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=285416"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/id.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=285416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}