Strategic Overview

Avg CVSSHigh
7.8/ 10
Patch Coverage100%
Open

0

Fixed

5

Get automatic notifications for all WP-DBManager vulnerabilities before they are exploited.

Vulnerability Records

5 records
WP-DBManager banner
Latestv3.0.0

WP-DBManager

Lester Chan

Author

Lester Chan

4.4(94)
88/100
Last Updated
2026-07-25 (4d ago)
Active Installs
60,000+
Downloads
3,138,952
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.0.2
Created
2006-01-03 (21y ago)

Allows you to optimize database, repair database, backup database, restore database, delete backup database , drop/empty tables and run selected queries. Supports automatic scheduling of backing up, optimizing and repairing of database. General Usage Activate WP-DBManager Plugin The script will automatically create a folder called backup-db in the wp-content folder if that folder is writable. If it is not created, please create the folder and ensure that the folder is writable Go to WP-Admin -> Database -> DB Options to configure the database options Secure the backup folder, see below Go to WP-Admin -> Database -> Backup DB, which checks whether the folder is actually reachable over HTTP and tells you if it is Securing The Backup Folder A database backup contains everything, including your users table. Anyone who can guess a backup file name can download the lot, so the folder must not be served over HTTP. The reliable option, on any server: set Path To Backup under WP-Admin -> Database -> DB Options to a folder outside your web root, for example /var/www/example.com/backup-db when WordPress lives in /var/www/example.com/public_html. Nothing served, nothing to configure. If the folder has to stay inside the web root: Apache — move htaccess.txt from Folder: wp-content/plugins/wp-dbmanager to Folder: wp-content/backup-db/.htaccess IIS — move Web.config.txt from Folder: wp-content/plugins/wp-dbmanager to Folder: wp-content/backup-db/Web.config nginx — nginx does not read .htaccess files, so the file above does nothing. Add this to your server block and reload nginx: location ^~ /wp-content/backup-db/ { deny all; } Move index.php from Folder: wp-content/plugins/wp-dbmanager to Folder: wp-content/backup-db/index.php as well, so the folder cannot be listed. The Backup DB page requests a file from the folder and reports what the server actually returns, so you can confirm the folder is closed rather than assume it. Development https://github.com/lesterchan/wp-dbmanager Credits Plugin icon by Freepik from Flaticon Donations I spent most of my free time creating, updating, maintaining and supporting these plugins, if you really love my plugins and could spare me a couple of bucks, I will really appreciate it. If not feel free to use it without any obligations.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C