Mozzy Assistance connects a WordPress website to the Mozzy monitoring service.
A Mozzy account is required for hosted monitoring and remote management. Local backups, downloads and restoration remain available without an account. To connect, open Mozzy > Overview and
select Connect to Mozzy. Sign in, choose or create a project, and approve the
website. WordPress exchanges a short-lived authorization code directly with
Mozzy; the permanent connector token is never placed in a browser URL.
The plugin contacts
https://mozzy.au to authorize the connection and send the
monitoring information described in the Privacy section. Nothing is sent until
an administrator approves or manually configures a connection.
Mozzy Assistance can also create complete database and file archives, retain
protected local copies, and upload them directly to a Google Drive account using
Google's least-privilege drive.file permission. Backup contents upload directly
to Google. With easy connection, Mozzy securely manages Google authorization.
Advanced setup can keep your own Google application credentials in WordPress.
Administrators can instead send backups directly to Backblaze B2, Amazon S3,
Cloudflare R2, Wasabi, DigitalOcean Spaces, or another service with an
S3-compatible HTTPS endpoint. Credentials and archive contents are sent directly
from WordPress to the destination selected and configured by the administrator;
they never pass through Mozzy.
Protected updates let an administrator select pending plugin, theme, and
WordPress core updates. Mozzy Assistance creates and verifies a new full safety
backup first, requires any connected remote upload to succeed, applies updates
one at a time, refreshes inventory, and runs database and filesystem checks.
Normal WordPress automatic updates are not intercepted.
Maintenance Autopilot lets an authorized Mozzy user approve specific update
versions in Mozzy. The connected plugin receives those maintenance commands in
heartbeat responses and performs the same backup-gated updates locally. If
post-update verification fails, Mozzy can request an automatic rollback using
the verified pre-update archive. WordPress creates a failed-state safety backup
before restoring that archive; this rollback does not require a separate
confirmation in WordPress.
Remote recovery can browse Mozzy-created Google Drive, Backblaze B2, and
S3-compatible archives and download a selected copy into protected local storage
in resumable chunks. Transport and archive checks run before the existing
explicit guided-restore confirmation is enabled.
Optional encrypted backups use authenticated XChaCha20-Poly1305 chunks in a
Mozzy .mzb container. Encryption and decryption are resumable, plaintext working
archives are removed after encryption, and weak cryptographic fallbacks are not
used. Administrators can export offline recovery-key files and rotate to a new
key while retaining previous keys for older archives. Existing ZIP archives
remain fully supported.
New backups contain a small manifest archive and numbered component parts. Keep
all files in a set together: the manifest alone cannot restore the website.
Recent backups offers separate downloads for the manifest and every part.
Connected cloud destinations receive the parts before the final manifest.
- Install and activate Mozzy Assistance.
- Open Mozzy > Overview.
- Select Connect to Mozzy.
- Sign in to Mozzy and choose or create a project.
- Confirm the connection test in WordPress.
Administrators can alternatively paste a connector token from Mozzy. Monitoring
can be paused and local credentials can be removed from the settings page.
Verified local backups can be restored from Mozzy > Backups. Manual
guided restore requires explicit administrator confirmation, creates a fresh safety
backup first, preserves wp-config.php and the active Mozzy recovery component,
restores in background batches, and finishes with database and filesystem checks.
Website activation
Connecting to Mozzy activates this website against its project using a private
connection token. Each project can activate one WordPress website. Your account's
project allowance controls new activations. Existing connections remain active
when a plan limit is lowered. Remove a connection in Mozzy to revoke its token;
disconnecting in WordPress removes the local credentials. Local backup and restore
features remain available without a Mozzy activation. Activation status and plan
allowances refresh with successful monitoring heartbeats. Existing clients remain
compatible; upgrading adds website-URL checks to monitoring requests.