[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7KYafrkuX3YcZpEsRDiyVIbGWRCtIipJLLv6275votQ":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"cypressnorth","https:\u002F\u002Fprofiles.wordpress.org\u002Fcypressnorth\u002F",2,0,93,30,89,"2026-08-29T08:22:21.205Z",[13,35],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":7,"num_ratings":7,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":32,"vuln_count":7,"unpatched_count":7,"last_vuln_date":33,"fetched_at":34},"cn-password-policy","Cypress North Password Policy","1.0.0","\u003Cp>Cypress North Password Policy enforces a strong, modern password policy on your WordPress site. Defaults align with NIST 800-63B guidance: length over composition rules, denylist screening, breach-corpus checks, and rate-limited login. Every setting is admin-configurable.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What you get\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A password rule engine that validates on user registration, password reset, and profile updates — covering minimum length, character requirements, breach-corpus check via the Have I Been Pwned k-anonymity API, denylist of common passwords, edit-distance check against the current password, and a per-user history check.\u003C\u002Fli>\n\u003Cli>Layered failed-login lockout: separate thresholds per IP and per username, with rolling windows and auto-release. Generic “invalid credentials” error responses so locked state is not disclosed to attackers.\u003C\u002Fli>\n\u003Cli>A soft-force interstitial that catches users at next login when their password is expired, breached, or below the active policy — they cannot escape without choosing a compliant new password.\u003C\u002Fli>\n\u003Cli>Daily email summary for administrators when attack rates spike.\u003C\u002Fli>\n\u003Cli>Per-user notification emails on password change, lockout, and expiration warnings.\u003C\u002Fli>\n\u003Cli>GDPR exporter + eraser that integrate with WordPress’s built-in Personal Data tools.\u003C\u002Fli>\n\u003Cli>Audit log of every relevant event (login failures, lockouts, password changes, compliance state transitions) viewable in the admin.\u003C\u002Fli>\n\u003Cli>Cleanup cron that trims old failed-attempt rows on a configurable schedule.\u003C\u002Fli>\n\u003Cli>WP-CLI \u003Ccode>wp cnpp unlock\u003C\u002Fcode> command to release a stuck IP or username without opening the admin.\u003C\u002Fli>\n\u003Cli>Multisite-aware: super-admin can globally configure or delegate per-site management.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Designed to coexist with WordPress core\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The plugin uses WordPress’s own password hashing (\u003Ccode>wp_hash_password\u003C\u002Fcode>) and never stores plaintext. The built-in zxcvbn strength meter is left intact. All integration is via documented WP filters and actions — deactivating the plugin removes its behavior cleanly.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to an API to check for known breached passwords.\u003C\u002Fp>\n\u003Cp>The Have I Been Pwned API (api.pwnedpasswords.com) receives only the first five characters of a SHA-1 hash — k-anonymity. No personally identifying information leaves the site and no plain text is transmitted. The check can be disabled entirely from \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Password Policy \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Policy\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>This service is provided by Have I Been Pwned (https:\u002F\u002Fhaveibeenpwned.com\u002F) : \u003Ca href=\"https:\u002F\u002Fhaveibeenpwned.com\u002FTermsOfUse\" rel=\"nofollow ugc\">terms of use\u003C\u002Fa> , \u003Ca href=\"https:\u002F\u002Fhaveibeenpwned.com\u002FPrivacy\" rel=\"nofollow ugc\">privacy policy\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>This plugin processes data necessary to enforce account security. The full privacy disclosure is contributed to \u003Cstrong>Tools \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Privacy Policy Guide\u003C\u002Fstrong> when the plugin is active.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What is collected\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Failed login attempts (IP, username attempted, timestamp).\u003C\u002Fli>\n\u003Cli>Lockout events (identifier, lockout-until timestamp).\u003C\u002Fli>\n\u003Cli>Password-change audit-log rows.\u003C\u002Fli>\n\u003Cli>Per-user: timestamp of last password change, compliance flag, a small queue of one-way hashes of previous passwords, and the most recent HIBP breach-check result (if enabled).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Lawful basis\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Legitimate interest in preventing brute-force credential attacks, plus regulatory and contractual obligations around password hygiene where applicable.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Retention\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Failed-attempt rows: pruned daily by cron, default kept for the duration of the lockout window (typically 24 hours).\u003C\u002Fli>\n\u003Cli>Audit-log rows: default 90 days, configurable.\u003C\u002Fli>\n\u003Cli>Per-user compliance and history data: kept while the user account exists; removed via the GDPR eraser on request.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Third parties\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The Have I Been Pwned API (api.pwnedpasswords.com) receives only the first five characters of a SHA-1 hash — k-anonymity. No personally identifying information leaves the site. The check can be disabled entirely from \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Password Policy \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Policy\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Exporter + eraser\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The plugin registers with WordPress’s built-in Personal Data tools (Tools \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Export Personal Data, Tools \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Erase Personal Data). Exports return four groups (failed attempts, lockouts, password-change events, compliance state). Erasure removes the password-change audit rows and every plugin-specific user_meta entry; lockout and failed-attempt rows are retained with the username field redacted so aggregate-attack statistics remain intact but the rows can no longer be linked to the individual.\u003C\u002Fp>\n","NIST-aligned password policy with HIBP breach checking, layered failed-login lockout, and an audit log.",62,"2026-07-16T14:50:00.000Z","7.0.2","6.0","8.1",[25,26,27,28,29],"brute-force-prevention","login-protection","nist","password","security","https:\u002F\u002Ftools.cypressnorth.com\u002Fpassword-policy-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcn-password-policy.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z",{"slug":36,"name":37,"version":38,"author":4,"author_profile":5,"description":39,"short_description":40,"active_installs":7,"downloaded":41,"rating":42,"num_ratings":43,"last_updated":44,"tested_up_to":45,"requires_at_least":46,"requires_php":47,"tags":48,"homepage":51,"download_link":52,"security_score":53,"vuln_count":7,"unpatched_count":7,"last_vuln_date":33,"fetched_at":34},"payment-gateway-payfabric","Payment Gateway for PayFabric","1.0.13","\u003Cp>Accept credit card payments easily and directly on your WooCommerce store via \u003Ca href=\"https:\u002F\u002Fwww.payfabric.com\u002F\" rel=\"nofollow ugc\">PayFabric\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Charge customer credit cards via PayFabric’s wallet and transaction APIs.\u003C\u002Fli>\n\u003Cli>Customers can safely and securely store their credit cards with PayFabric through their WooCommerce account.\u003C\u002Fli>\n\u003Cli>Process refunds directly from the WooCommerce order admin area.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Payment Gateway for PayFabric allows you to test your PayFabric integration in their \u003Ca href=\"http:\u002F\u002Fsandbox.payfabric.com\u002F\" rel=\"nofollow ugc\">sandbox environment\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Upgrade to the premium version of Payment Gateway for PayFabric directly from the WordPress admin area to unlock live payment capabilities.\u003C\u002Fp>\n\u003Cp>Visit \u003Ca href=\"https:\u002F\u002Ftools.cypressnorth.com\u002F\" rel=\"nofollow ugc\">tools.cypressnorth.com\u003C\u002Fa> for more information.\u003C\u002Fp>\n","Adds PayFabric as a payment gateway for WooCommerce.",1132,60,1,"2023-07-31T13:03:00.000Z","5.9.13","5.0","7.1",[49,50],"payfabric","woocommerce","https:\u002F\u002Ftools.cypressnorth.com\u002Fpayfabric-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpayment-gateway-payfabric.1.0.13.zip",85]