Before an upgrade, schema migration, credential rotation or destructive maintenance, create an encrypted database backup and retain the current Free, Pro and Aurelia packages. Include booking snapshots, tax lines, payment and refund ledger, customer linkage, license state, OTA credentials and external inventory blocks in the recovery inventory. A theme rollback must not roll back booking data, and uninstall is never a rollback method. The backup manifest must explicitly list external inventory blocks.
Recovery sequence
- Record UTC time, active versions, schema options, cache layers and the first observed symptom. Stop only the affected integration; do not delete blocks or truncate logs to make the dashboard look healthy.
- Restrict administrator access, rotate exposed payment, license or iCal secrets, and purge cached pages or export URLs. Rotate WordPress salts when anonymous confirmation links may be compromised; previously issued signed links then become invalid.
- Restore a copy to staging and verify counts, booking totals, tax snapshots, ledger entries and inventory before considering production recovery.
- Re-run a minimal Search, Book Now, Payment/Pay at hotel and Confirmation smoke, then check iCal health and language routes.
- Preserve redacted logs and a timeline for the security owner. Notify guests or authorities only through the site’s approved privacy process.
Do not publish a database dump, raw webhook, signed URL, token or personal data while asking for support. If integrity is uncertain, classify the event as an incident and escalate before editing canonical records.