Flexa Site Migrator – Migration & Staging
Migrate WordPress from production to staging with no shell access. Creates a package (files + database + installer) that runs anywhere.
Solid choice
Flexa Site Migrator is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 3 weeks ago, and scores 64/100 on our health check.
- Actively developed — last update 3 weeks ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Flexa Site Migrator stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| backup | >100 |
| clone | >100 |
| duplicate | >100 |
| migration | >100 |
| staging | >100 |
About Flexa Site Migrator
From the official readme · v1.1.0Description
Flexa Site Migrator migrates a WordPress site from production to staging. It builds a package made of one or more archive-*.zip files (site files, split automatically), a database.sql dump, and a standalone installer.php. It works whether staging is on the same server or a different one, and requires no shell/SSH access — everything runs through the WordPress admin over regular HTTP.
Key features
- Chunked build — the database is exported in chunks (using
mysqldumpwhen available, otherwise pure PHP) and files are compressed in chunks to avoid timeouts. - Three ways to deploy to staging — pull-by-link, wp-admin import, or a standalone installer for empty sites.
- Serialize-safe search-replace — URLs are updated with a recursive unserialize → replace → re-serialize algorithm, so serialized options/widgets never get corrupted.
- Handles large sites — the build is fully chunked and files are split into ~200MB archive parts; the database deploy runs in a single request (check the System check panel for your PHP limits before importing very large databases).
- Token-protected transfers — pull links carry an SHA-256 hashed token (only the hash is stored on the server), with optional password and IP allowlist restrictions.
Deployment methods
Method A — Pull via link (simplest): Install the plugin on both production and staging. Build the package on production, copy the link, paste it on staging under Site Migrator → Import, and click Pull & Migrate. Staging downloads the files from production (byte-range supported) and runs extraction, DB import, and search-replace on its own.
Method B — wp-admin import: Copy the package folder to staging’s wp-content/flexasm-packages/, then run the migration from Site Migrator → Import.
Method C — Standalone installer: For an empty staging site with no WordPress. Upload installer.php and the package files to the site root, open installer.php in a browser, enter the database details, and start the migration.
External services
Your migration packages, tokens, and settings stay in your own WordPress installation. The plugin makes two kinds of outbound request, described below.
Migration transfer (your own sites)
The main outbound request goes to the production site URL you paste on the staging side (Site Migrator > Import > “Pull from production via link”). When you click Test connection or Pull & Migrate, staging contacts that URL to download the migration package (site files and the database dump) you created on production. The request carries the access token from the link, and, if the package is password-protected, the password you enter (sent in a request header). No third party is involved: both ends are your own sites, and nothing is transmitted until you paste a link and start a pull.
Deactivation feedback (Flexa Product Intelligence)
When you go to deactivate Flexa Site Migrator on the Plugins screen, a short optional survey asks why. It is served by Flexa’s product intelligence service at https://product-intelligence.flexacommerce.com. It runs only on wp-admin/plugins.php, never on the front end, and never blocks or delays deactivation.
What is sent, and when:
- On opening the Plugins screen: a request to
/api/v1/config(product slug and tier) to load the survey configuration. Cached for 6 hours. - When you deactivate or interact with the survey: the reason you pick and any optional message you type, sent to
/api/v1/deactivations,/api/v1/events,/api/v1/feedback,/api/v1/feature-requests, and/api/v1/recovery-events.
Every request includes an anonymous per-site identifier (a random UUID), the plugin version and tier, and by default your WordPress/PHP version and locale. No email, site domain, user identity, or raw IP is collected. Turn environment reporting off with add_filter( 'flexa_site_migrator/deactivation_survey/config', fn( $c ) => array( 'collect_environment' => false ) + $c ); and disable the whole survey with add_filter( 'flexa_site_migrator/deactivation_survey/enabled', '__return_false' );.
Service terms and privacy policy: https://flexacommerce.com/pages/terms and https://flexacommerce.com/pages/privacy
Installation
- Upload the
flexa-site-migratorfolder to/wp-content/plugins/on the production site (or install it through Plugins → Add New → Upload Plugin). - Activate the plugin through the Plugins menu in WordPress.
- Go to Site Migrator → Export to build a package.
- To deploy via link or wp-admin import, install and activate the plugin on the staging site as well, then use Site Migrator → Import.
Frequently asked questions
Does it require SSH or WP-CLI?
No. The whole build and import process runs inside the WordPress admin over normal HTTP requests.
Will I get logged out after importing on staging?
Possibly. After the database is overwritten, the users table belongs to production, so you may need to log back in with a production account.
Does it handle multi-gigabyte databases?
The build side is fully chunked, so exporting is safe at any size. The import on staging runs in a single request through wp-admin; for very large databases, check the System check panel and raise max_execution_time/memory_limit in php.ini first, or use the standalone installer (Method C).
Is the transfer secure?
Pull links carry an SHA-256 hashed token — only the hash is stored on production, and the real token stays in the link. You can additionally protect a package with a password and restrict it to specific IP addresses. Always delete the package after the migration is complete.
What happens to my staging site?
Staging is completely overwritten (files and database). Only use it with a staging site you can safely throw away.
Is it translation-ready?
Yes. All admin-facing strings (PHP and JavaScript) are internationalized under the flexa-site-migrator text domain, and a languages/flexa-site-migrator.pot template is included.
Changelog
Adds an optional, admin-only deactivation feedback survey. It never blocks deactivation and can be turned off with a filter. See the External services section for what is sent.
1.1.0
- New: an optional deactivation feedback survey. If you deactivate the plugin, a short survey asks why, so we know what to improve. It is entirely optional, admin-only, and never blocks or delays deactivation. See the External services section for exactly what is sent and how to turn it off.
1.0.8
- New: an “Advanced options” section on the Export page lets you exclude parts of the site to shrink the package — whole folders (media library, themes, must-use plugins, plugins) are skipped in the file archive, and spam comments and post revisions (with their metadata) are trimmed from the database dump.
- Change: the protection password, IP restriction, and exclusion controls are now grouped under a collapsible “Advanced options” toggle to keep the export screen uncluttered.
- Change: renamed the plugin to “Flexa Site Migrator – Migration & Staging”.
1.0.7
- New: the downloaded package .zip now includes a README.txt with step-by-step migration instructions (standalone installer, wp-admin import, and pull-by-link). The installer’s one-click cleanup removes it from the server along with the other migration files.
- Change: the protection password field (Export) and the pull password field (Import) are now masked password inputs with a show/hide eye toggle, and no longer trigger browser autofill.
1.0.6
- Fix: the build now stops immediately with a clear message if WordPress core, a plugin, or a theme is updated on the source site while the package is being built. Previously the chunked build silently produced a torn package that mixed files from two versions (new files missing, removed files still present), which could fatal the migrated site.
- Change: WordPress automatic updates are held off while a package build is in progress (released as soon as the build finishes, or within ~15 minutes if a build is abandoned).
- Security: the mysqldump fast-path now passes the database password via the environment instead of the command line, so it is no longer visible in the server process list while the dump runs.
- Fix: bundled translations in
/languagesare now loaded (load_plugin_textdomain), so translations work outside WordPress.org distribution too.
1.0.5
- Change: the plugin now has its own top-level admin menu Site Migrator (with Export and Import submenus) instead of living under Tools.
1.0.4
- Compatibility: tested up to WordPress 7.1.
- Docs: added an “External services” section documenting the pull request to the production URL you provide (no third-party service is contacted).
Screenshots
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Flexa Site Migrator alternatives
All backup plugins →FAQ
Flexa Site Migrator: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 10, 2026
Is Flexa Site Migrator free?
Yes. Flexa Site Migrator is free to download and use from the official WordPress.org plugin directory.
Is Flexa Site Migrator safe to use in 2026?
Flexa Site Migrator is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 3 weeks ago, and scores 64/100 on our health check.
How many websites use Flexa Site Migrator?
Flexa Site Migrator is active on <10 WordPress websites and has been downloaded 311 times since it launched in August 2026. It was downloaded 150 times in the last 30 days.
Does Flexa Site Migrator work with WordPress 7.1?
Yes. The developer has tested Flexa Site Migrator up to WordPress 7.1.3, the latest release. It requires WordPress 6.2 or newer.
What PHP version does Flexa Site Migrator need?
Flexa Site Migrator requires PHP 7.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Flexa Site Migrator last updated?
The latest version, 1.1.0, was released on September 20, 2026 (3 weeks ago).
Who makes Flexa Site Migrator?
Flexa Site Migrator is developed and maintained by FlexaTech.
What are the best alternatives to Flexa Site Migrator?
The most popular alternatives to Flexa Site Migrator are All-in-One WP Migration and… (5M+ installs), UpdraftPlus: WP Backup & Mi… (4M+ installs) and Jetpack (3M+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card