Unlock and Verify a QCBM Recovery Package

Before QCBM allows recovery work, unlock the standalone Recovery Runner with the four-digit PIN assigned to that Backup Set and verify every backup part against the package manifest.

Do not continue to target or database changes until Verify Backup succeeds. Verification is the point where QCBM proves that the package you moved to the destination is complete and unchanged.

Extract the Complete Package into the Target Root

  1. Copy the complete Recovery Package ZIP to the intended destination.
  2. Extract it directly into the Joomla root you intend to recover.
  3. Confirm that qcbm-recover.php, the temporary launcher, instructions, manifest, and all backup parts are present.

Extraction temporarily replaces the destination root index.php with QCBM's Recovery Runner launcher, so do this only when you are ready to recover the destination.

Open the Recovery Runner

Visit the destination domain, preferably over HTTPS. The temporary index.php redirects to qcbm-recover.php. You can also open qcbm-recover.php directly.

The runner calculates the target Joomla root from its own physical directory. That locked root cannot be changed with a browser field.

Enter the Four-Digit Recovery PIN

Enter the PIN assigned when the Backup Set was created. The PIN belongs to this Recovery Package; a newer PIN currently shown in the QCBM administrator does not unlock an older package if that older package was created with different digits.

If you do not know the correct PIN, stop and retrieve it from the authorized backup records rather than repeatedly guessing.

Run Verify Backup

Select Verify Backup. QCBM reads the manifest and verifies each required recovery part.

For every part, the runner requires complete recovery metadata, confirms the file is present/readable, checks its exact size, and computes SHA-256 to compare with the recorded hash.

What a Verification Failure Means

A missing part, wrong size, incomplete metadata, or SHA-256 mismatch means the package is not safe to use as-is. Do not bypass that result and do not begin destructive recovery.

Return to a known-good Recovery Package or recopy the package from trusted storage, then verify again.

Continue with Target and Database Tests

Package verification is only the first safety gate. After it passes, use Test Locked Destination and, for database/full recovery, Test Database before selecting Recover Site.

Verification Checklist

  • The package is extracted into the intended target root.
  • The correct PIN unlocks the runner.
  • Verify Backup completes without missing-part, size, or SHA-256 errors.
  • The source/backup type shown by the runner matches the package you intended to restore.
  • You still retain an untouched off-server copy of the Recovery Package.

Community Discussion

Want to compare workflows, share practical tips, or discuss how you use this QCBM feature? Visit the QC Backup Manager Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.