# Backup.sql file not deleted following import

**URL:** https://community.kinsta.com/t/backup-sql-file-not-deleted-following-import/1501
**Category:** Installation
**Created:** [May 25, 2022, 10:07am UTC](https://community.kinsta.com/t/backup-sql-file-not-deleted-following-import/1501 "2022-05-25T10:07:56Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![dgilfillan](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/dgilfillan/32/1122_2.png) [@dgilfillan](https://community.kinsta.com/u/dgilfillan)
#### Post date: [May 25, 2022, 10:07am UTC](https://community.kinsta.com/t/backup-sql-file-not-deleted-following-import/1501/1 "2022-05-25T10:07:56Z")

</div>

Hi, following an import from Kinsta a backup.sql file gets created, however it is not removed upon completion?

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [May 25, 2022, 5:08pm UTC](https://community.kinsta.com/t/backup-sql-file-not-deleted-following-import/1501/2 "2022-05-25T17:08:23Z")

</div>

Hi @dgilfillan, thanks for bringing this up. I’ve noticed this as well and have asked our devs for more clarification as to why it isn’t removed.

---

<div class="post-metadata">

### Author: ![Kevin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/kevin/32/808_2.png) [@Kevin](https://community.kinsta.com/u/Kevin)
#### Post date: [May 26, 2022, 11:25pm UTC](https://community.kinsta.com/t/backup-sql-file-not-deleted-following-import/1501/3 "2022-05-26T23:25:01Z")

</div>

It looks like we will start deleting the backup.sql in one of the upcoming updates, @dgilfillan; thank you for reporting this!

---

<div class="post-metadata">

### Author: ![Riku\_O](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/riku_o/32/3645_2.png) [@Riku\_O](https://community.kinsta.com/u/Riku_O)
#### Post date: [June 26, 2024, 1:09pm UTC](https://community.kinsta.com/t/backup-sql-file-not-deleted-following-import/1501/4 "2024-06-26T13:09:47Z")

</div>

Hey,

2 years later this is still an issue with the latest version of DevKinsta. I just bumped into these mysterious backup.zip files in public folder of two of the sites we host and found out they were created when I pulled the sites to my local environment.

Both databases have thousands of users with all their meta data and that info was available to all the world to download in a file with a known name. Am I wrong to say that this is a huge security issue? Not just that the file is left behind, but also the fact that it always has the same name. The naming issue also applies to downloadable backups in kinsta {sitename}.zip, but that’s a different story.

I am disappointed.

---

<div class="post-metadata">

### Author: ![jackirish](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/jackirish/32/1361_2.png) [@jackirish](https://community.kinsta.com/u/jackirish)
#### Post date: [June 26, 2024, 10:03pm UTC](https://community.kinsta.com/t/backup-sql-file-not-deleted-following-import/1501/5 "2024-06-26T22:03:22Z")

</div>

Hi there! 👋

Hm. We should be removing this file; however I will point out that we do also have a rule on the server that blocks access to .SQL files on the site (except over SSH/SFTP) so there should not be any security concerns with having that file in the directory in question.

I’ll reach out to our internal teams to see if we can determine why the file wasn’t removed if you can DM me the name of the site in question.
