[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqIV2IGVMp0LjAXXh9mUCWwq-UOAZOxHJ2rF8pAJv2RA":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"savedprompt","https:\u002F\u002Fprofiles.wordpress.org\u002Fsavedprompt\u002F",1,0,100,30,94,"2026-08-29T04:03:54.456Z",[13],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":7,"num_ratings":7,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"secure-draft-preview-links","Secure Draft Preview Links","1.0.1","\u003Cp>\u003Cstrong>Secure Draft Preview Links\u003C\u002Fstrong> lets you generate a cryptographically secure, unguessable link for any draft post so that people without a WordPress account can read it before it goes live.\u003C\u002Fp>\n\u003Ch4>How it works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Open any draft post or page in the editor.\u003C\u002Fli>\n\u003Cli>Check \u003Cstrong>Enable public preview\u003C\u002Fstrong> in the Publish panel (Classic Editor) or Status & Visibility panel (Block Editor).\u003C\u002Fli>\n\u003Cli>Copy the generated link and share it with anyone.\u003C\u002Fli>\n\u003Cli>The recipient can view the draft without logging in.\u003C\u002Fli>\n\u003Cli>Uncheck the box or set the expiry to \u003Cstrong>Expired\u003C\u002Fstrong> to revoke access immediately.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Editor features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Works with both the \u003Cstrong>Classic Editor\u003C\u002Fstrong> and the \u003Cstrong>Block Editor\u003C\u002Fstrong> (Gutenberg).\u003C\u002Fli>\n\u003Cli>Checkbox to enable \u002F disable preview — shown even on auto-draft posts (disabled with a “save first” hint).\u003C\u002Fli>\n\u003Cli>When a post is published the checkbox automatically disables and shows “Not available for published posts”.\u003C\u002Fli>\n\u003Cli>Preview URL displayed in a monospace code box — horizontally scrollable, click to select all.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Copy\u003C\u002Fstrong> button and \u003Cstrong>Open preview\u003C\u002Fstrong> button inline with the URL box.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Generate new link\u003C\u002Fstrong> button — invalidates the old link immediately, with a confirmation step before firing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stop sharing\u003C\u002Fstrong> confirmation bar — shown when unchecking the checkbox, requires explicit confirmation before removing the link.\u003C\u002Fli>\n\u003Cli>Expiry selector with four options:\n\u003Cul>\n\u003Cli>\u003Cstrong>48 hours\u003C\u002Fstrong> — default, shows exact time remaining (e.g. “Expires on: Apr 29 · 14:32 (4h 12m remaining)”).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Always available\u003C\u002Fstrong> — link never expires.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom time\u003C\u002Fstrong> — set Days, Hours, and Minutes; live “Expires on:” display updates as you type; shows error if all fields are cleared without saving.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Expired (disable now)\u003C\u002Fstrong> — immediately invalidates the link without deleting the token.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Expiry settings auto-save on change with a “Expiry setting saved.” confirmation message.\u003C\u002Fli>\n\u003Cli>Block Editor: snackbar notices for every action (enable, disable, copy, generate new link).\u003C\u002Fli>\n\u003Cli>Block Editor: \u003Cstrong>Open public preview\u003C\u002Fstrong> item added to the Preview dropdown (WordPress 6.7+).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Preview Links admin page\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Dedicated \u003Cstrong>Preview Links\u003C\u002Fstrong> menu item in the WordPress admin sidebar.\u003C\u002Fli>\n\u003Cli>Two tabs: \u003Cstrong>Active\u003C\u002Fstrong> and \u003Cstrong>Expired\u003C\u002Fstrong>, each showing a count badge.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Paginated table\u003C\u002Fstrong> — 20 items per page, with top and bottom pagination controls.\u003C\u002Fli>\n\u003Cli>Per-row columns: Post title, Post type, Exact expiry time, Preview URL, Share buttons, Actions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Copy URL\u003C\u002Fstrong> and \u003Cstrong>Open preview\u003C\u002Fstrong> icon buttons inline with the URL.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Share buttons\u003C\u002Fstrong>: Facebook, X (Twitter), LinkedIn, Email — captions include the post title and expiry time (omitted for never-expires links).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Regenerate\u003C\u002Fstrong> button — generates a new token with a confirmation dialog; old link stops working immediately.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Stop Sharing\u003C\u002Fstrong> button — removes the token with a confirmation dialog.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Edit Post\u003C\u002Fstrong> link opens in a new tab.\u003C\u002Fli>\n\u003Cli>Confirmation dialogs use an inline modal (no browser \u003Ccode>confirm()\u003C\u002Fcode>) with clear messaging about consequences.\u003C\u002Fli>\n\u003Cli>Toast notifications slide up from the bottom-right on every action.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Tokens are 64-character cryptographically random hex strings generated with \u003Ccode>random_bytes()\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>Token validation uses \u003Ccode>hash_equals()\u003C\u002Fcode> to prevent timing attacks.\u003C\u002Fli>\n\u003Cli>Expired links return a \u003Cstrong>410 Gone\u003C\u002Fstrong> HTTP response.\u003C\u002Fli>\n\u003Cli>Invalid tokens return a \u003Cstrong>403 Forbidden\u003C\u002Fstrong> HTTP response.\u003C\u002Fli>\n\u003Cli>Preview link is automatically removed when a post is published, made private, or trashed.\u003C\u002Fli>\n\u003Cli>All AJAX endpoints are protected with nonces and capability checks.\u003C\u002Fli>\n\u003Cli>No data is exposed to unauthenticated users beyond the post content itself.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Post list table\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Public Preview\u003C\u002Fstrong> badge shown next to post titles that have an active preview link.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Public Preview\u003C\u002Fstrong> filter view in the post list table to quickly find all posts with active links.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Technical\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Works with all viewable public post types (posts, pages, and custom post types).\u003C\u002Fli>\n\u003Cli>Pagination links on multi-page posts are rewritten to include the preview token.\u003C\u002Fli>\n\u003Cli>Token meta is registered with the REST API for block editor compatibility.\u003C\u002Fli>\n\u003Cli>No external dependencies — pure PHP, jQuery (Classic Editor), and WordPress’s own React\u002Fwp-components (Block Editor).\u003C\u002Fli>\n\u003C\u002Ful>\n","Share draft posts with anyone via a secure, time-limited preview link — no login required.",175,"2026-07-17T22:36:00.000Z","7.0.2","6.5","8.0",[25,26,27,28,29],"draft","preview","preview-link","public","share","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsecure-draft-preview-links\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsecure-draft-preview-links.1.0.1.zip",null,"2026-07-22T17:31:50.256Z"]