[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGX-XngIV0qWNPN3RHo7uJKdE80fm04So7vrDnxIbms0":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"toply","TonioWeb","https:\u002F\u002Fprofiles.wordpress.org\u002Ftoply\u002F",3,0,100,30,94,"2026-08-29T01:03:46.907Z",[14,35,53],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":8,"num_ratings":8,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"tonioweb-ai-content-generator","TonioWeb AI Content Generator","1.3.3","\u003Cp>TonioWeb AI Content Generator does what WordPress’s built-in AI cannot: \u003Cstrong>process your entire site in bulk, in the background, while you do something else.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>WordPress 7.0 added AI writing assistance inside the editor — great for one post at a time. TonioWeb AI Content Generator is for the other problem: you have 3 000 products without alt text, 800 posts without meta descriptions, a media library full of unnamed images. You need results in minutes, not weeks.\u003C\u002Fp>\n\u003Ch4>Why not just use WordPress’s built-in AI?\u003C\u002Fh4>\n\u003Cp>  WordPress editor AI\u003Cbr \u002F>\n  TonioWeb AI Content Generator\u003C\u002Fp>\n\u003Cp>  Works on\u003Cbr \u002F>\n  One post at a time\u003Cbr \u002F>\n  Entire site at once\u003C\u002Fp>\n\u003Cp>  Alt text\u003Cbr \u002F>\n  Not supported\u003Cbr \u002F>\n  Full Media Library, WCAG 2.2\u003C\u002Fp>\n\u003Cp>  SEO meta\u003Cbr \u002F>\n  Not supported\u003Cbr \u002F>\n  Writes to Yoast, Rank Math, AIOSEO, SEOPress\u003C\u002Fp>\n\u003Cp>  Translation\u003Cbr \u002F>\n  Not supported\u003Cbr \u002F>\n  Polylang & WPML native adapters\u003C\u002Fp>\n\u003Cp>  Background processing\u003Cbr \u002F>\n  No\u003Cbr \u002F>\n  Action Scheduler queue, resumable\u003C\u002Fp>\n\u003Cp>  Provider choice per feature\u003Cbr \u002F>\n  No\u003Cbr \u002F>\n  OpenAI for alt text, Claude for translations, Gemini for excerpts — your call\u003C\u002Fp>\n\u003Cp>  Fallback provider\u003Cbr \u002F>\n  No\u003Cbr \u002F>\n  Automatic failover if primary is rate-limited\u003C\u002Fp>\n\u003Cp>  Undo \u002F rollback\u003Cbr \u002F>\n  No\u003Cbr \u002F>\n  7-day rollback log, per-item undo\u003C\u002Fp>\n\u003Cp>  WooCommerce products\u003Cbr \u002F>\n  Basic\u003Cbr \u002F>\n  Titles, descriptions, attributes, custom fields\u003C\u002Fp>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Get an API key from OpenAI, Anthropic or Google (all offer pay-as-you-go, no monthly subscription required)\u003C\u002Fli>\n\u003Cli>Add the key in \u003Cstrong>WordPress Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Connectors\u003C\u002Fstrong> — this is a built-in WordPress 7.0 feature for managing AI provider credentials\u003C\u002Fli>\n\u003Cli>Open \u003Cstrong>TonioWeb AI Content Generator\u003C\u002Fstrong> from the admin menu\u003C\u002Fli>\n\u003Cli>Scan, preview the items found, select which ones to process, and run the bulk job\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>That’s it. No separate account, no credit card for this plugin, no data sent to our servers — everything goes directly between your site and the AI provider you chose.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>🖼️ Bulk AI Alt Text Generator\u003C\u002Fstrong>\u003Cbr \u002F>\nScan your entire Media Library and generate accessible alt text for every image using AI vision. WCAG 2.2 compliant, multilingual, SEO-optimized. Preview thumbnails before generating. Skip images that already have alt text or force-regenerate selected ones. Undo per-image or in bulk. Works on thousands of images — not just the one currently open in the editor.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>📝 AI SEO Meta Description Generator\u003C\u002Fstrong>\u003Cbr \u002F>\nGenerate 155-character SEO meta descriptions for all your posts, pages and products at once. Writes directly into Yoast SEO, Rank Math, All in One SEO, and SEOPress fields — your SEO plugin stays in control of display. Bulk-process your entire archive in one job.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🌍 AI Auto-Translate\u003C\u002Fstrong>\u003Cbr \u002F>\nTranslate posts, pages, products, taxonomies, and custom fields into 100+ languages. Native Polylang and WPML adapter — translations go to the right language slots automatically. Not a simple word-for-word translation: the AI adapts tone for natural reading in the target language.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>✂️ AI Excerpt Generator\u003C\u002Fstrong>\u003Cbr \u002F>\nReplace empty or auto-truncated excerpts with engaging 1–3 sentence summaries across your entire site. Content-type detection adapts tone automatically: news, e-commerce, blog, tutorial, product page.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>⚙️ Multi-Provider Routing with Fallback\u003C\u002Fstrong>\u003Cbr \u002F>\nAssign a different AI provider to each feature. Use Gemini for alt text (cheapest per image), Claude for translations (best quality), GPT-4o for meta descriptions. Set a fallback provider per feature — if your primary hits a rate limit, the job continues without interruption.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>↩️ Full Rollback & Undo\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery bulk operation is logged. Undo a single item or roll back an entire job up to 7 days later. No risk of irreversible changes.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🔌 WordPress 7.0 Connector Native\u003C\u002Fstrong>\u003Cbr \u002F>\nZero key management inside the plugin. Uses the Connector registry already built into WordPress 7.0 — one place for all your AI credentials across the whole site.\u003C\u002Fp>\n\u003Ch4>Who Should Use This Plugin?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>WooCommerce stores\u003C\u002Fstrong> with hundreds or thousands of products that need alt text, meta descriptions, and translations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content sites\u003C\u002Fstrong> with a large archive of legacy posts missing SEO meta or excerpts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agencies & freelancers\u003C\u002Fstrong> onboarding new client sites — fill in all the missing content fields in one session\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual sites\u003C\u002Fstrong> using Polylang or WPML that need translations without a SaaS subscription\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Accessibility-focused publishers\u003C\u002Fstrong> who need WCAG\u002FEAA-compliant alt text across their entire Media Library\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Supported AI Providers\u003C\u002Fh4>\n\u003Cp>TonioWeb AI Content Generator reads provider credentials from the WordPress 7.0 Connectors registry. Currently supported:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>OpenAI\u003C\u002Fstrong> — GPT-4o, GPT-4.5, GPT-5 and Vision models for alt text\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anthropic Claude\u003C\u002Fstrong> — Claude 4.x for translations and long-form excerpts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Gemini\u003C\u002Fstrong> — Gemini 2.x for cost-efficient bulk processing\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Additional providers will be supported as WordPress 7.x ships new Connector packages.\u003C\u002Fp>\n\u003Ch4>Privacy & Data Handling\u003C\u002Fh4>\n\u003Cp>TonioWeb AI Content Generator is a thin orchestration layer. It sends your content directly from your WordPress site to the AI provider you selected, using YOUR API key. \u003Cstrong>We never see, store, or proxy your data.\u003C\u002Fstrong> No telemetry. No analytics. No phone-home.\u003C\u002Fp>\n\u003Ch4>Source Code\u003C\u002Fh4>\n\u003Cp>The plugin PHP source code is in \u003Ccode>src\u002F\u003C\u002Fcode>. The React admin UI source is in \u003Ccode>admin\u002Fsrc\u002F\u003C\u002Fcode>. The compiled admin bundle (\u003Ccode>admin\u002Fbuild\u002F\u003C\u002Fcode>) is generated with \u003Ccode>@wordpress\u002Fscripts\u003C\u002Fcode>. To rebuild: \u003Ccode>npm install && npm run build\u003C\u002Fcode>.\u003C\u002Fp>\n","Bulk AI for your entire site: generate alt text, SEO meta, translations and excerpts for hundreds of items at once — not just the post you have open.",483,"2026-06-29T09:30:00.000Z","7.0.2","7.0","8.0",[26,27,28,29,30],"ai","alt-text","bulk","seo","woocommerce","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftonioweb-ai-content-generator.1.3.3.zip",null,"2026-07-22T17:31:50.256Z",{"slug":36,"name":37,"version":38,"author":4,"author_profile":6,"description":39,"short_description":40,"active_installs":8,"downloaded":41,"rating":8,"num_ratings":8,"last_updated":42,"tested_up_to":43,"requires_at_least":44,"requires_php":45,"tags":46,"homepage":31,"download_link":51,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":52},"toply-return-risk-predictor","Toply Return Risk Predictor","1.0.2","\u003Cp>Toply Return Risk Predictor is an essential tool for any WooCommerce store that offers cash-on-delivery (COD) payment. The plugin automatically analyzes your order history and identifies customers who have a pattern of returning or refusing parcels.\u003C\u002Fp>\n\u003Cp>Statistics show that a single refused parcel can wipe out the profit from 3-4 successfully completed orders due to round-trip shipping costs. Toply Return Risk Predictor gives you full visibility into these losses directly in your admin panel.\u003C\u002Fp>\n\u003Ch4>Key Benefits\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Risk Scoring:\u003C\u002Fstrong> See the return rate percentage for each customer directly in the orders list.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Financial Analysis:\u003C\u002Fstrong> A modern dashboard that calculates the total value of capital lost to returns and failures.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Phone Detection:\u003C\u002Fstrong> Detects problematic customers even if they use different email addresses.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero Configuration:\u003C\u002Fstrong> Install it and it immediately starts analyzing your existing data.\u003C\u002Fli>\n\u003C\u002Ful>\n","Identify high-risk customers for WooCommerce stores using historical order analysis.",77,"2026-04-07T21:01:00.000Z","6.9.4","5.0","7.4",[47,48,49,50,30],"blacklist","cash-on-delivery","fraud-prevention","returns","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftoply-return-risk-predictor.1.0.2.zip","2026-04-16T10:56:18.058Z",{"slug":54,"name":55,"version":56,"author":5,"author_profile":6,"description":57,"short_description":58,"active_installs":8,"downloaded":59,"rating":8,"num_ratings":8,"last_updated":60,"tested_up_to":22,"requires_at_least":61,"requires_php":45,"tags":62,"homepage":67,"download_link":68,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"toply-skimshield","Toply SkimShield","1.0.4","\u003Ch4>The Problem\u003C\u002Fh4>\n\u003Cp>Imagine a hacker silently adds a piece of JavaScript code to your WooCommerce checkout page. Every time a customer types in their credit card number, that hidden code copies it and sends it to the hacker — without you or your customer ever knowing. This type of attack is called \u003Cstrong>checkout skimming\u003C\u002Fstrong>, and it is one of the most common ways online stores get compromised.\u003C\u002Fp>\n\u003Cp>Toply SkimShield protects you by watching your checkout page and alerting you the moment anything changes.\u003C\u002Fp>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Step 1 — Takes a snapshot\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen you run the first scan, the plugin looks at every JavaScript file loaded on your checkout page and saves a unique fingerprint (a hash) for each one. This becomes your approved baseline — the “normal” state of your checkout.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 2 — Watches for changes\u003C\u002Fstrong>\u003Cbr \u002F>\nEvery time someone visits your checkout page, the plugin silently compares the live scripts against that saved baseline. If everything matches, nothing happens. If a new script appears or an existing one has been modified, the plugin raises an alert immediately.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 3 — Notifies you by email\u003C\u002Fstrong>\u003Cbr \u002F>\nThe moment a suspicious change is detected, you receive an email with details: which script changed, what it looked like before, what it looks like now, and a direct link to review it in your dashboard.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 4 — You decide what is legitimate\u003C\u002Fstrong>\u003Cbr \u002F>\nIn the admin dashboard you see a list of all scripts found on your checkout page. You approve the ones you recognise (WooCommerce, Stripe, PayPal, Google Analytics, etc.) and block anything that looks suspicious. The plugin remembers your decisions.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step 5 — Optionally block unauthorised scripts entirely (CSP)\u003C\u002Fstrong>\u003Cbr \u002F>\nOnce you have approved all your legitimate scripts, you can turn on the Content Security Policy feature. This tells the browser: “do not run any script on the checkout page that is not on the approved list.” Even if a hacker manages to inject a script, the browser will refuse to execute it.\u003C\u002Fp>\n\u003Ch4>Think of It Like a Security Camera for Your Checkout\u003C\u002Fh4>\n\u003Cp>The first scan registers who is allowed in. Every visit after that checks: is there anyone new? If yes — alarm. No technical knowledge required to use it.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Script monitoring\u003C\u002Fstrong> — detects new or modified scripts on every checkout page load\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Instant email alerts\u003C\u002Fstrong> — notified the moment something changes, via the standard WordPress email system\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Script whitelist\u003C\u002Fstrong> — approve or block scripts with one click from the admin dashboard\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Content Security Policy\u003C\u002Fstrong> — automatically generates a CSP header based on your approved scripts; start in Report-Only mode to avoid breaking checkout, then switch to Enforce when ready\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PCI-DSS compliance report\u003C\u002Fstrong> — generates a printable report covering requirements 6.4.3 and 12.10, ready to show to your payment processor or auditor\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No external dependencies\u003C\u002Fstrong> — everything runs on your own server, no API keys, no third-party services, no data sent anywhere\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Needs This\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Any WooCommerce store that accepts card payments\u003C\u002Fli>\n\u003Cli>Store owners who want to know immediately if their checkout page is tampered with\u003C\u002Fli>\n\u003Cli>Agencies managing WooCommerce stores on behalf of clients\u003C\u002Fli>\n\u003Cli>Stores that need to demonstrate PCI-DSS compliance\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How to Test This Plugin\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Prerequisites:\u003C\u002Fstrong> WooCommerce must be active with at least one published product and a functioning checkout page (your shop must have a \u003Ccode>\u002Fcheckout\u002F\u003C\u002Fcode> page set up by WooCommerce).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Step-by-step test procedure:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Install and activate\u003C\u002Fstrong> the plugin. Navigate to \u003Cstrong>SkimShield\u003C\u002Fstrong> in the admin sidebar.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Run a manual scan\u003C\u002Fstrong> — on the Dashboard tab, click the \u003Cstrong>Scan Now\u003C\u002Fstrong> button. The plugin fetches the WooCommerce checkout page and extracts every script tag (both external \u003Ccode>\u003Cscript src=\"…\">\u003C\u002Fcode> and inline \u003Ccode>\u003Cscript>…\u003C\u002Fscript>\u003C\u002Fcode>).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>View detected scripts\u003C\u002Fstrong> — click the \u003Cstrong>Script Whitelist\u003C\u002Fstrong> tab. You will see a table listing all scripts found on the checkout page, each with its handle, source URL (or inline snippet), type (enqueued\u002Finline), SHA-256 hash, and status (Pending).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Approve scripts\u003C\u002Fstrong> — click the \u003Cstrong>Approve\u003C\u002Fstrong> button next to each legitimate script. The status changes to “Approved”.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Verify real-time monitoring\u003C\u002Fstrong> — visit your store’s checkout page as a normal visitor (front-end). The plugin hooks into \u003Ccode>wp_enqueue_scripts\u003C\u002Fcode> at priority \u003Ccode>PHP_INT_MAX\u003C\u002Fcode> and records every script loaded. New scripts trigger an entry in the Incidents log.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Check the Incidents tab\u003C\u002Fstrong> — any scripts detected for the first time generate an incident with severity “High”. A hash change (simulating a tampering event) generates a “Critical” incident.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Test email alerts\u003C\u002Fstrong> — make sure the Alert Email address in \u003Cstrong>Settings\u003C\u002Fstrong> is a deliverable inbox. Visit the checkout page with a browser. If any new script is detected, an HTML email is sent immediately via \u003Ccode>wp_mail()\u003C\u002Fcode>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Enable CSP (optional)\u003C\u002Fstrong> — go to \u003Cstrong>Settings\u003C\u002Fstrong>, enable “CSP Header”, leave “Report-Only Mode” checked, and save. Visit the checkout page. The \u003Ccode>Content-Security-Policy-Report-Only\u003C\u002Fcode> HTTP header will now be present (verify with browser DevTools \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Network \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> checkout request headers).\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Generate a compliance report\u003C\u002Fstrong> — click the \u003Cstrong>PCI-DSS Report\u003C\u002Fstrong> tab and review the auto-generated report covering requirements 6.4.3 and 12.10.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Expected results after running Scan Now:\u003C\u002Fstrong>\u003Cbr \u002F>\n– The Script Whitelist tab shows all scripts that are on the checkout page\u003Cbr \u002F>\n– Each row shows the script handle, source, type (enqueued or inline), a truncated SHA-256 hash, and status\u003Cbr \u002F>\n– Approve\u002FBlock\u002FRemove action buttons are functional\u003Cbr \u002F>\n– The Dashboard shows the count of Approved, Pending, and Blocked scripts\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin does \u003Cstrong>not\u003C\u002Fstrong> connect to any external service for its core functionality. All script monitoring and hashing is performed locally on your server.\u003C\u002Fp>\n\u003Cp>The auto-generated Content Security Policy (CSP) template includes default \u003Ccode>frame-src\u003C\u002Fcode> origins for common payment gateways (\u003Ccode>https:\u002F\u002Fwww.paypal.com\u003C\u002Fcode>, \u003Ccode>https:\u002F\u002Fjs.stripe.com\u003C\u002Fcode>, \u003Ccode>https:\u002F\u002Ffonts.gstatic.com\u003C\u002Fcode>). These are included only as a default starting point to prevent checkout from breaking when you first enable the CSP feature. No data is transmitted by this plugin to those domains — the browser uses the CSP header to decide which external resources to load, independently of this plugin.\u003C\u002Fp>\n\u003Cp>If your store does not use PayPal or Stripe, you can remove those origins via the Custom CSP Directives field in Settings.\u003C\u002Fp>\n","Real-time script integrity monitoring and CSP automation for WooCommerce checkout. No API dependencies. Detects unauthorized scripts on checkout.",141,"2026-05-31T13:25:00.000Z","5.8",[63,64,65,66,30],"checkout","pci-dss","script-monitoring","security","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Ftoply-skimshield\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftoply-skimshield.1.0.4.zip"]