Mozzy Assistance Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Mozzy Assistance connects a WordPress website to the Mozzy monitoring service.
A Mozzy account is required. After activation, open Mozzy Assistance > Overview and
select Connect to Mozzy. Sign in, choose or create a project, and approve the
website. WordPress exchanges a short-lived authorization code directly with
Mozzy; the permanent connector token is never placed in a browser URL.
The plugin contacts https://mozzy.au to authorize the connection and send the
monitoring information described in the Privacy section. Nothing is sent until
an administrator approves or manually configures a connection.
Mozzy Assistance can also create complete database and file archives, retain
protected local copies, and upload them directly to a Google Drive account using
Google’s least-privilege drive.file permission. Backup credentials and archive
contents never pass through Mozzy.
Administrators can instead send backups directly to Backblaze B2, Amazon S3,
Cloudflare R2, Wasabi, DigitalOcean Spaces, or another service with an
S3-compatible HTTPS endpoint. Credentials and archive contents are sent directly
from WordPress to the destination selected and configured by the administrator;
they never pass through Mozzy.
Protected updates let an administrator select pending plugin, theme, and
WordPress core updates. Mozzy Assistance creates and verifies a new full safety
backup first, requires any connected remote upload to succeed, applies updates
one at a time, refreshes inventory, and runs database and filesystem checks.
Normal WordPress automatic updates are not intercepted.
Maintenance Autopilot lets an authorized Mozzy user approve specific update
versions in Mozzy. The connected plugin receives those maintenance commands in
heartbeat responses and performs the same backup-gated updates locally. If
post-update verification fails, Mozzy can request an automatic rollback using
the verified pre-update archive. WordPress creates a failed-state safety backup
before restoring that archive; this rollback does not require a separate
confirmation in WordPress.
Remote recovery can browse Mozzy-created Google Drive, Backblaze B2, and
S3-compatible archives and download a selected copy into protected local storage
in resumable chunks. Transport and archive checks run before the existing
explicit guided-restore confirmation is enabled.
Optional encrypted backups use authenticated XChaCha20-Poly1305 chunks in a
Mozzy .mzb container. Encryption and decryption are resumable, plaintext working
archives are removed after encryption, and weak cryptographic fallbacks are not
used. Administrators can export offline recovery-key files and rotate to a new
key while retaining previous keys for older archives. Existing ZIP archives
remain fully supported.
External services
Mozzy
The plugin contacts https://mozzy.au only after an administrator connects the
site or manually saves a connector token. It sends the monitoring and backup
status and maintenance progress listed in the Privacy section to provide the
Mozzy monitoring and maintenance service. Heartbeat responses can contain managed
backup settings and requests, approved maintenance updates, or automatic rollback
commands as described in the FAQ. Mozzy does not receive backup archives,
destination credentials, or recovery keys.
Mozzy privacy policy: https://mozzy.au/privacy
Mozzy terms: https://mozzy.au/terms
Google Drive
The plugin contacts Google only after an administrator supplies Google OAuth
application credentials and selects Connect Google Drive. It uses
https://accounts.google.com for authorization, https://oauth2.googleapis.com for
OAuth token exchange and revocation, and https://www.googleapis.com for Drive
file operations. OAuth identifiers, authorization codes, access and refresh
tokens, backup archives, filenames, sizes, checksums, and plugin-created folder
metadata are sent directly to Google as required to store, list, download, and
remove retained backups in the administrator’s Drive account.
Google privacy policy: https://policies.google.com/privacy
Google terms: https://policies.google.com/terms
Backblaze B2 and S3-compatible storage
The plugin contacts an object-storage service only after an administrator saves
its HTTPS endpoint and credentials. It sends signed S3 API requests, the access
key identifier, backup archives, filenames, sizes, and storage metadata directly
to that endpoint to test the connection and to store, list, download, and remove
retained backups. The secret key remains stored encrypted in WordPress and is
used locally to sign requests. Supported services include Backblaze B2, Amazon
S3, Cloudflare R2, Wasabi, DigitalOcean Spaces, and other administrator-selected
S3-compatible services. Use of a configured service is governed by that
provider’s terms and privacy policy.
For Amazon S3, the standard API endpoint is https://s3.amazonaws.com. An Amazon
Web Services account, an S3 bucket, an access key ID, and a secret access key are
required. Administrators must explicitly enter their provider’s HTTPS endpoint;
the plugin does not prefill or contact one merely by being activated or viewed.
Requests begin only after an administrator saves the destination and explicitly
tests it or runs a backup, recovery, retention, or restore operation. This is an
optional storage API integration, not a source of remotely loaded JavaScript,
CSS, images, fonts, or executable code.
Backblaze privacy: https://www.backblaze.com/company/policy/privacy
Backblaze terms: https://www.backblaze.com/company/policy/terms-of-service
AWS privacy: https://aws.amazon.com/privacy/
AWS service terms: https://aws.amazon.com/service-terms/
Cloudflare privacy: https://www.cloudflare.com/privacypolicy/
Cloudflare terms: https://www.cloudflare.com/terms/
Wasabi privacy: https://wasabi.com/legal/privacy-policy
Wasabi terms: https://wasabi.com/legal/terms-of-use
DigitalOcean privacy: https://www.digitalocean.com/legal/privacy-policy
DigitalOcean terms: https://www.digitalocean.com/legal/terms-of-service-agreement
Privacy
When connected and enabled, the plugin sends data to https://mozzy.au. Data can
include health heartbeats; WordPress, PHP, theme and plugin names and versions;
active plugin status; fatal error messages, file locations, line numbers and the
affected URL; database error messages; backup state, progress, filenames, sizes
and destination labels; maintenance command identifiers, update and rollback
progress, results and backup filenames; failed email events; and supported
scheduled-task failures.
The plugin does not intentionally send passwords, cookies, form contents,
database records, WordPress users, visitor IP addresses, backup archives, storage
credentials or recovery keys. Review Mozzy’s privacy policy at
https://mozzy.au/privacy and terms at https://mozzy.au/terms.
Screenshots
No screenshots provided
