Amadalis WordPress migration

Migration assessment

Your site has twelve parts.
We show you which ones survive the move.

Choose how much access you are comfortable giving us. We run a real migration into a disposable workspace and hand back an honest receipt over 12 tracked categories — including the engine's own named reason for every part of your site it could not reach.

Read-only at every level Disposable workspace · deleted after 30 minutes Nothing is published, anywhere, ever

Step one

What are you willing to hand over?

Four ways in. Each one reaches a different region of your site — the anatomy below re-machines itself as you choose. Every figure on this page is generated by the same code that runs a paying migration, not written by us.

Choose how much access to give us

Your export file and an application password are not the same size of the same thing. Each reaches something the other cannot — which is why their silhouettes differ in shape rather than simply growing. The engine reports it category by category below; only our read-only plugin reaches all 12.

Step two

The anatomy of your site

12 categories, drawn as 12 plates. Thickness is coverage: solid means it arrives whole, thin and hatched means it arrives incomplete, and a dashed outline means we cannot reach it at all. Depth is derived — the plates at the top are the ones every option reaches, the plates at the bottom the ones only one option can.

Complete the picture

Read-only · no write path · delete it when the receipt is signed

Anatomy · 12 tracked categories Whole Partial Out of reach
EVERY OPTION SOME OPTIONS PLUGIN ONLY Content Complete Media Partial Taxonomies and terms Complete Users and author identities Partial Menus and navigation Complete Builder metadata Complete Forms Partial Commerce Partial Plugin-owned constructs Partial WordPress options and settings Out of reach Redirects Out of reach Theme data Out of reach

Depth is how far out of sight a category lives. The plates at the top are reached, at least in part, by every option; the plates at the bottom are reached by one option alone — which is why every option except our read-only plugin leaves the bottom of the stack hollow.

Step three

What each option actually reaches

12 categories, measured by the migration engine on every run. Where something is out of reach, the engine says why — in the table, not in the footnotes.

Coverage of 12 migration categories across 4 access options
Category 01 Site URL 0 of 12 complete 02 Export file 4 of 12 complete 03 App password 2 of 12 complete 04 Reader plugin 12 of 12 complete
Reached by every option · 3 categories
content Posts, pages, custom post types, drafts and private items Partial Anonymous wp/v2 exposes only public REST-visible content; draft, private, password-protected, and non-REST content remains unavailable. Complete Complete Complete
media Attachments, their source URLs and their metadata Partial Anonymous wp/v2 exposes only public media rows and source URLs, without private assets or exporter integrity evidence. Partial WXR carries attachment metadata and source URLs, but not exporter byte checksums or guaranteed binaries. Complete Complete
taxonomies and terms Categories, tags, custom taxonomies and their hierarchy Partial Core public categories and tags may be visible, but complete taxonomy acquisition is not authorized. Complete Partial Core categories and tags are acquired; custom taxonomy completeness is not established. Complete
Reached by some options · 6 categories
users and author identities Accounts, roles and author identities Out of reach users and author identities requires exporter, authenticated source evidence, or WXR and is unavailable to anonymous REST. Partial WXR carries author identities, but not the complete safe users table. Partial Embedded author evidence may be visible, but the full safe users table is not acquired. Complete
menus and navigation Nav menus, their nested items and link targets Out of reach menus and navigation requires exporter, authenticated source evidence, or WXR and is unavailable to anonymous REST. Complete Out of reach The canonical live adapter does not ingest an authenticated menu endpoint. Complete
builder metadata Elementor, Divi, WPBakery and block layout data Out of reach Rendered HTML is not authority for unavailable builder metadata. Complete Out of reach Unregistered builder postmeta cannot be inferred from rendered HTML or assumed present. Complete
forms Form definitions, plugin settings and submissions Out of reach forms requires exporter, authenticated source evidence, or WXR and is unavailable to anonymous REST. Partial Form post types and postmeta may be present, but plugin settings and submissions are not guaranteed. Out of reach Form definitions and plugin settings are not acquired by the authenticated REST adapter. Complete
commerce Products, orders, inventory and store settings Out of reach commerce requires exporter, authenticated source evidence, or WXR and is unavailable to anonymous REST. Partial Post-based products and legacy records may be present, but HPOS/custom tables and settings are not guaranteed. Out of reach WooCommerce operational tables and settings are not acquired by the authenticated REST adapter. Complete
plugin-owned constructs Custom database tables written by plugins Out of reach plugin-owned constructs requires exporter, authenticated source evidence, or WXR and is unavailable to anonymous REST. Partial Post-based plugin constructs may be present; plugin tables and options are outside standard WXR. Out of reach Plugin tables and options are not acquired by wp/v2. Complete
Reached only by our read-only plugin · 3 categories
WordPress options and settings Permalinks, front page, site identity and other wp_options Out of reach WordPress options and settings requires exporter, authenticated source evidence, or WXR and is unavailable to anonymous REST. Out of reach A standard WXR does not carry wp_options, Customizer, or widget settings. Out of reach Application-password REST does not expose wp_options to the canonical live adapter. Complete
redirects Legacy URLs, 301 chains and regex rules Out of reach redirects requires exporter, authenticated source evidence, or WXR and is unavailable to anonymous REST. Out of reach Plugin-owned redirect tables are outside standard WXR. Out of reach Plugin-owned redirect tables are not exposed by authenticated wp/v2. Complete
theme data Active theme, theme mods, widgets and global styles Out of reach theme data requires exporter, authenticated source evidence, or WXR and is unavailable to anonymous REST. Out of reach A standard WXR does not carry the active theme, theme mods, or complete global styles. Out of reach Active theme, Customizer, widget, and global-style values are not acquired. Complete

Rendered from the migration engine's own acquisition report — the same code that stamps the receipt on a paying migration. Every mark, count, reason and stratum on this page is its output; none of it is written by hand.

Step four

Run it on your own site

Every option below runs the same engine, on the same code path, as a paying migration — into a workspace that deletes itself after 30 minutes. Options 01 and 02 need no credentials at all.

Option 01

Paste your site’s URL

Nothing to install, nothing to upload. We read what your site already shows the public.

We only read what's public through your site's WordPress API. Nothing is changed on your site.

Option 02

Drop your export file

Two minutes in wp-admin: Tools → Export → All content. No credentials, nothing installed — and it carries far more of your site than the public web does.

Drop your .xml export here wp-admin → Tools → Export → All content · up to 100 MB

We read the file you upload. The only thing we ask your live site for is the images your content points at — a WordPress export file carries the links, not the pictures. Nothing is changed on your site.

Options 03 and 04

Connect with an application password

WordPress has a built-in way to give an outside tool read access without handing over your login: an application password. You create it, we use it once, you revoke it. Below is how — including where the revoke button is. If the read-only exporter is installed on your site, this same form runs option 04: the engine always selects the strongest access it is authorised to use, and the receipt says which it used.

Must be https:// — WordPress turns application passwords off on unencrypted connections, and so do we.

The user you created the application password for. It needs WordPress’s Export permission — an administrator has it by default.

Never your login password. This is the 24-character token WordPress generated for you — spaces and all, or with them removed; either works.

Your application password is used for this one import and then discarded — never stored, never written to our logs. It's a revocable token, not your login password, and we'll show you where to revoke it when you're done. We only read: nothing on your WordPress site is created, changed, or deleted.

Not comfortable with this? Use option 02 — an export file needs no credentials, and it carries the page-builder layouts and menus this route cannot reach. Installing the read-only exporter turns this same form into option 04. How to install it →

How to create an application password (five steps)
  1. In wp-admin, go to Users → Profile. (If you’re managing someone else’s user, Users → All Users, then edit that user.)
  2. Scroll down to the Application Passwords section.
  3. In the name box, type Amadalis migration — the name is only a label, but naming it after the tool is what lets you find it again to revoke it. Then click Add New Application Password.
  4. WordPress shows the password once. Copy it and paste it above. It is not your login password, and WordPress will never show it to you again.
  5. When your preview is done, revoke it — see below. It takes one click.

No Application Passwords section? WordPress hides it on sites served over plain http://. That’s a WordPress security measure, not a fault on your site — and it’s why we ask for https://. If your site is local or staging-only, use option 02 instead.

When you’re done: revoke it

Your preview expires on its own, and we discard the password when the import finishes — but you shouldn’t have to take our word for it. Go back to Users → Profile → Application Passwords, find the row named Amadalis migration, and revoke it. That kills our access immediately and permanently, whatever we do.

Revoking one application password doesn’t affect your login, your other tools, or anyone else’s access.

Option 04 · the plugin

The only version of your site that is all of your site.

Your application password is used for this one import and then discarded — never stored, never written to our logs. The plugin only reads: there is no write path in it, and you delete it when you're done.

Get the read-only plugin
Read-only by constructionThere is no write path in the plugin’s code.
Your password is used onceThen discarded — never stored, never logged.
Delete it when you are doneIt is needed for the migration, not after it.

Reached by the plugin and by nothing else on this page — each line is the engine’s own reason an export file cannot carry it

  • WordPress options and settings. A standard WXR does not carry wp_options, Customizer, or widget settings.
  • Redirects. Plugin-owned redirect tables are outside standard WXR.
  • Theme data. A standard WXR does not carry the active theme, theme mods, or complete global styles.

12 of 12 · whole

01 · Real, not estimated

We actually run the migration

Your site is rebuilt as drafts in a disposable workspace, so the receipt describes what happened rather than what we predict would happen. The workspace deletes itself after 30 minutes, and nothing is published anywhere, ever.

02 · Nothing is written

Every option is read-only

A scan reads public pages. A file is a file. An application password is revocable from your profile in one click, is used once and then discarded. The plugin has no write path at all.

03 · Limits are the product

The engine names what it missed

Every reason on this page is generated by the migration engine itself. If a category cannot be moved at the level you chose, you read it here — by name, before you commit, not after.