[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPgF8uowMIIbty10_6W94t-BPTbV1TyIVw2FvPwvCCv0":3,"$fqoxcq1Q_AlX5DvLyTmchgC6cOfxvUfy58-ucI7uJMc8":137,"$ffh0HZavgHOSy3kQBupv_a-lrL3zKSCSbaGhGpZoGzJw":142},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"archivioid","ArchivioID","5.1.0","mtnviewpro","https:\u002F\u002Fprofiles.wordpress.org\u002Fmtnviewpro\u002F","\u003Cp>\u003Cstrong>ArchivioID\u003C\u002Fstrong> is an add-on plugin for \u003Cstrong>ArchivioMD\u003C\u002Fstrong> that adds a full cryptographic identity and signature layer to your WordPress site. It manages GPG public keys, verifies detached OpenPGP signatures on posts, supports multi-signer workflows with configurable thresholds, and exposes public proof pages so anyone can verify authenticity without logging in.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Public Key Management\u003C\u002Fstrong>: Store, manage, and rotate GPG public keys with expiry tracking and administrator alerts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Post Signature Verification\u003C\u002Fstrong>: Upload detached .asc signature files for posts — verified automatically using phpseclib v3\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Browser-Based Signing\u003C\u002Fstrong>: Sign posts directly in the WordPress admin using a browser-held key — no server-side key material required\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Signature Workflows\u003C\u002Fstrong>: Collect signatures from multiple key holders on a single post; each signer identified by key fingerprint and timestamp\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Signature Threshold\u003C\u002Fstrong>: Require a minimum number of verified signatures before a post displays the verified badge — configurable globally or per post type\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Algorithm Enforcement Floor\u003C\u002Fstrong>: Block weak signature algorithms (MD5, SHA-1) and enforce minimum RSA\u002FDSA key sizes at upload, REST submission, and re-verification time\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automated Re-Verification\u003C\u002Fstrong>: Daily WP-Cron job re-verifies all signed posts and flags content that has changed since signing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Key Expiry Notifications\u003C\u002Fstrong>: Email alerts at 30, 14, and 3 days before a key expires, sent to the key owner or site admin\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Key Rotation Workflow\u003C\u002Fstrong>: Admin UI for generating replacement keys, migrating existing signatures, and retiring old keys\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk Verification\u003C\u002Fstrong>: Verify all signed posts in a single admin action with per-post status reporting\u003C\u002Fli>\n\u003Cli>\u003Cstrong>REST API\u003C\u002Fstrong>: Full REST endpoint for programmatic signature submission, key retrieval, and verification status\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Key Server\u003C\u002Fstrong>: Publishes active public keys at a stable well-known endpoint for external verifiers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bundle Download\u003C\u002Fstrong>: Downloadable evidence package (hash, signatures, key fingerprints, timestamps) for any post\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Public Proof Pages\u003C\u002Fstrong>: Stable public permalink at \u003Ccode>\u002Farchivio-id\u002Fverify\u002F{post_id}\u003C\u002Fcode> — renders full chain of custody without requiring admin access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Audit Logging\u003C\u002Fstrong>: Immutable log of all verification attempts, key changes, and rotation events\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WP-CLI Support\u003C\u002Fstrong>: Full CLI interface for batch operations and automated pipelines\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Visual Status Badges\u003C\u002Fstrong>: Front-end badge showing verified \u002F unverified \u002F threshold-unmet status on every post\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Requirements\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>WordPress 6.0 or higher\u003C\u002Fli>\n\u003Cli>PHP 7.4 or higher (tested up to PHP 8.5)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>ArchivioMD plugin version 1.5.0 or higher\u003C\u002Fstrong> (required parent plugin)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Upload your GPG public key via the ArchivioID \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Key Management admin page\u003C\u002Fli>\n\u003Cli>Create or edit a post in WordPress\u003C\u002Fli>\n\u003Cli>Upload a detached .asc signature file for the post, or sign directly in the browser\u003C\u002Fli>\n\u003Cli>ArchivioID verifies the signature immediately and on every subsequent automated re-verify run\u003C\u002Fli>\n\u003Cli>A verification badge appears on the front end; a public proof page is available at a stable permalink\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Technical Details\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Uses \u003Cstrong>phpseclib v3\u003C\u002Fstrong> for all cryptographic operations — no system GPG installation required\u003C\u002Fli>\n\u003Cli>Uses \u003Cstrong>OpenPGP-PHP\u003C\u002Fstrong> for packet parsing and key handling\u003C\u002Fli>\n\u003Cli>All key material and signatures stored in dedicated WordPress database tables\u003C\u002Fli>\n\u003Cli>Algorithm enforcement floor consulted at upload, REST submission, and re-verification time\u003C\u002Fli>\n\u003Cli>Multi-signature threshold evaluated before displaying the verified badge\u003C\u002Fli>\n\u003Cli>Public proof pages require no admin login — safe to share externally\u003C\u002Fli>\n\u003Cli>Fully WordPress coding standards compliant\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>External Services\u003C\u002Fh4>\n\u003Cp>This plugin can make outbound HTTP requests to the following third-party services. \u003Cstrong>All external lookups are opt-in\u003C\u002Fstrong> and can be disabled under ArchivioID \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Key Server Lookup.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>keys.openpgp.org (VKS API)\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen an administrator uses the Key Management page to look up a GPG public key by fingerprint or email address, the plugin sends a GET request to \u003Ccode>https:\u002F\u002Fkeys.openpgp.org\u002Fvks\u002Fv1\u002F\u003C\u002Fcode>. No personal data beyond the fingerprint or email address entered by the administrator is transmitted. This request is made only on explicit administrator action and only when the “Allow key server lookup” setting is enabled.\u003Cbr \u002F>\n* Service: https:\u002F\u002Fkeys.openpgp.org\u003Cbr \u002F>\n* Privacy policy: https:\u002F\u002Fkeys.openpgp.org\u002Fabout\u002Fprivacy\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WKD — Web Key Directory (user’s email domain)\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen an administrator looks up a key by email address, the plugin may also query the Web Key Directory endpoint on the domain portion of that email address (e.g. \u003Ccode>https:\u002F\u002Fexample.com\u002F.well-known\u002Fopenpgpkey\u002F\u003C\u002Fcode>). This follows the OpenPGP Web Key Directory specification (draft-koch-openpgp-webkey-service). The request is made only on explicit administrator action and only when key server lookup is enabled.\u003Cbr \u002F>\n* Specification: https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fdraft-koch-openpgp-webkey-service\u002F\u003Cbr \u002F>\n* The domain contacted is determined entirely by the email address the administrator enters; it is not a fixed third-party service.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Identity Proof URLs (user-supplied)\u003C\u002Fstrong>\u003Cbr \u002F>\nAdministrators may optionally store a public identity proof URL alongside each key (for example, a Keyoxide or Keybase profile page). These URLs are stored in the WordPress database and displayed as links in the frontend badge tooltip. The plugin itself makes no outbound request to these URLs; they are rendered as standard hyperlinks for visitors to follow voluntarily.\u003Cbr \u002F>\n* Keyoxide: https:\u002F\u002Fkeyoxide.org\u003Cbr \u002F>\n* Keybase: https:\u002F\u002Fkeybase.io\u003Cbr \u002F>\n* Any HTTPS URL may be entered; the plugin validates only that the value is a well-formed HTTPS URL.\u003C\u002Fp>\n\u003Ch3>Source Code for Bundled Minified JavaScript\u003C\u002Fh3>\n\u003Cp>This plugin includes \u003Ccode>assets\u002Fjs\u002Fopenpgp.min.js\u003C\u002Fcode>, the minified build of \u003Cstrong>OpenPGP.js\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Project home\u003C\u002Fstrong>: https:\u002F\u002Fopenpgpjs.org\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Source code\u003C\u002Fstrong>: https:\u002F\u002Fgithub.com\u002Fopenpgpjs\u002Fopenpgpjs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>License\u003C\u002Fstrong>: LGPL-3.0-or-later\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Version used\u003C\u002Fstrong>: 5.x (see \u003Ccode>assets\u002Fjs\u002Fopenpgp.min.js\u003C\u002Fcode> file header for exact version)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>To reproduce the minified file from source:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>`\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>git clone https:\u002F\u002Fgithub.com\u002Fopenpgpjs\u002Fopenpgpjs.git\u003Cbr \u002F>\ncd openpgpjs\u003Cbr \u002F>\nnpm install\u003Cbr \u002F>\nnpm run build          # produces dist\u002Fopenpgp.min.js\u003Cbr \u002F>\n    `\u003C\u002Fp>\n\u003Cp>Copy \u003Ccode>dist\u002Fopenpgp.min.js\u003C\u002Fcode> to \u003Ccode>assets\u002Fjs\u002Fopenpgp.min.js\u003C\u002Fcode> in this plugin.\u003C\u002Fp>\n\u003Ch3>Security\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>All inputs sanitized and validated; all outputs escaped\u003C\u002Fli>\n\u003Cli>Nonce verification on all forms and AJAX handlers\u003C\u002Fli>\n\u003Cli>Capability checks (\u003Ccode>manage_options\u003C\u002Fcode>) on all admin actions\u003C\u002Fli>\n\u003Cli>REST API write endpoints require authentication\u003C\u002Fli>\n\u003Cli>SQL prepared statements throughout; no raw query interpolation\u003C\u002Fli>\n\u003Cli>Algorithm enforcement floor blocks known-weak cryptographic primitives\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support, please visit: https:\u002F\u002Fmountainviewprovisions.com\u002Farchivio-id\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under GPLv2 or later.\u003C\u002Fp>\n","OpenPGP signature verification, multi-signer workflows, key lifecycle management, and public proof pages for ArchivioMD.",0,630,"2026-03-24T00:17:00.000Z","6.9.5","6.0","7.4",[18,19,20,21,22],"authenticity","cryptography","digital-signature","openpgp","security","https:\u002F\u002Fmountainviewprovisions.com\u002FArchivioID","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Farchivioid.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},2,30,94,"2026-08-29T04:18:56.551Z",[36,50,71,89,113],{"slug":37,"name":38,"version":39,"author":7,"author_profile":8,"description":40,"short_description":41,"active_installs":11,"downloaded":42,"rating":11,"num_ratings":11,"last_updated":43,"tested_up_to":14,"requires_at_least":44,"requires_php":16,"tags":45,"homepage":48,"download_link":49,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"archiviomd","ArchivioMD","1.19.3","\u003Cp>ArchivioMD gives WordPress sites a cryptographic proof layer. Every post, page, and document gets a verifiable integrity record — independently checkable without trusting the platform, the host, or the database.\u003C\u002Fp>\n\u003Cp>Built for journalists, compliance teams, legal publishers, and anyone for whom the question “was this changed after it was published?” has a real answer.\u003C\u002Fp>\n\u003Ch4>Content Hashing\u003C\u002Fh4>\n\u003Cp>Every post and page is hashed deterministically on publish and update. A verification badge (✓ Verified \u002F ✗ Unverified \u002F − Not Signed) appears on every post. Verification files are downloadable for offline confirmation. Shortcode: \u003Ccode>[hash_verify]\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>Supported algorithms include SHA-256\u002F384\u002F512 family, SHA-3, BLAKE2b\u002F2s, BLAKE3, SHAKE, RIPEMD-160, Whirlpool, and GOST variants.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>HMAC Integrity Mode\u003C\u002Fstrong> adds a shared-secret layer on top of hashing. The key lives in \u003Ccode>wp-config.php\u003C\u002Fcode> — never the database — so an adversary with database access alone cannot silently update a hash.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>define('ARCHIVIOMD_HMAC_KEY', 'your-secret-key');\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Document Signing\u003C\u002Fh4>\n\u003Cp>All signing methods sign the same canonical message and run independently. Any combination can be active simultaneously.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Ed25519\u003C\u002Fstrong> (recommended for most sites) — uses PHP sodium (\u003Ccode>ext-sodium\u003C\u002Fcode>). Private key in \u003Ccode>wp-config.php\u003C\u002Fcode>; public key published at \u003Ccode>\u002F.well-known\u002Fed25519-pubkey.txt\u003C\u002Fcode>. In-browser keypair generator included. Supports DSSE envelope mode (Sigstore spec) with PAE binding to prevent cross-protocol replay.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>SLH-DSA \u002F SPHINCS+ (post-quantum)\u003C\u002Fstrong> — pure-PHP implementation of NIST FIPS 205. No extensions, no Composer dependencies; works on any shared host running PHP 7.4+. Security rests on SHA-256 alone — not on factoring or discrete logarithms. Four parameter sets: SLH-DSA-SHA2-128s (default, 7,856-byte signatures), -128f (faster, 17,088 bytes), -192s, -256s. Signing takes 200–600 ms on shared hosting per publish event — front-end rendering is not affected. Running Ed25519 and SLH-DSA together (hybrid mode) provides both classical and quantum verifiability from a single DSSE envelope.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>ECDSA P-256\u003C\u002Fstrong> ⚠️ Enterprise\u002Fcompliance mode only. Enable when an external framework (eIDAS, SOC 2, HIPAA, government PKI) explicitly requires X.509 certificate-backed ECDSA. For all other sites, Ed25519 is recommended. Nonce generation is 100% delegated to OpenSSL.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>RSA\u003C\u002Fstrong> ⚠️ Legacy compatibility only. Enable when a downstream system cannot accept Ed25519, ECDSA, or SLH-DSA keys.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>CMS \u002F PKCS#7\u003C\u002Fstrong> — Detached DER signatures importable into Adobe Acrobat, Windows Explorer, and enterprise DMS platforms. Reuses your ECDSA or RSA key.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>JSON-LD \u002F W3C Data Integrity\u003C\u002Fstrong> — Produces \u003Ccode>eddsa-rdfc-2022\u003C\u002Fcode> and \u003Ccode>ecdsa-rdfc-2019\u003C\u002Fcode> proof blocks per post and publishes a \u003Ccode>did:web\u003C\u002Fcode> DID document at \u003Ccode>\u002F.well-known\u002Fdid.json\u003C\u002Fcode>. Compatible with ActivityPub, W3C Verifiable Credentials, and decentralised identity wallets.\u003C\u002Fp>\n\u003Cp>All private keys are stored in \u003Ccode>wp-config.php\u003C\u002Fcode> — never in the database. PEM files uploaded via the admin UI are stored outside \u003Ccode>DOCUMENT_ROOT\u003C\u002Fcode>, chmod 0600, with an \u003Ccode>.htaccess\u003C\u002Fcode> Deny guard.\u003C\u002Fp>\n\u003Ch4>DANE \u002F DNS Key Corroboration\u003C\u002Fh4>\n\u003Cp>Publishes every active signing key as a DNSSEC-protected DNS TXT record, giving verifiers a trust path entirely independent of your web server and TLS certificate. An attacker must compromise both your web host and your DNS zone simultaneously to forge a key.\u003C\u002Fp>\n\u003Cp>Records use the \u003Ccode>amd1\u003C\u002Fcode> tag-value format (modelled on DKIM):\u003C\u002Fp>\n\u003Cpre>\u003Ccode>_archiviomd._domainkey.example.com.  IN TXT \"v=amd1; k=ed25519; p=\u003Cbase64-pubkey>\"\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>When ECDSA P-256 is configured, an optional TLSA record (RFC 6698, DANE-EE, Selector=1) binds the leaf certificate to your HTTPS service. A machine-readable discovery endpoint at \u003Ccode>\u002F.well-known\u002Farchiviomd-dns.json\u003C\u002Fcode> lists all active records and expected values. A self-describing format specification is served at \u003Ccode>\u002F.well-known\u002Farchiviomd-dns-spec.json\u003C\u002Fcode> regardless of whether DANE is enabled.\u003C\u002Fp>\n\u003Cp>Weekly passive health checks via wp-cron surface failures as dismissible admin notices. Key rotation mode suppresses false-positive mismatch warnings during DNS TTL expiry. Full WP-CLI support: \u003Ccode>wp archiviomd dane-check\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>DNSSEC is required for DANE to provide actual security. Most registrars offer it with a single toggle.\u003C\u002Fp>\n\u003Ch4>External Anchoring\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>RFC 3161 Trusted Timestamps\u003C\u002Fstrong> — Sends content hashes to a Time Stamp Authority on every anchor job. The signed \u003Ccode>.tsr\u003C\u002Fcode> token binds the hash to a specific time and is independently verifiable offline with OpenSSL. Built-in providers: FreeTSA.org, DigiCert, GlobalSign, Sectigo. Custom endpoint supported.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Sigstore \u002F Rekor Transparency Log\u003C\u002Fstrong> — Submits a \u003Ccode>hashedrekord\u003C\u002Fcode> entry to the public Rekor append-only log (rekor.sigstore.dev) on every anchor job. Entries are immutable and publicly verifiable without an account or API key. When Ed25519 keys are configured, entries are signed with the site key; otherwise an ephemeral keypair is generated automatically.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Git Repository Anchoring\u003C\u002Fstrong> — Commits integrity records to GitHub or GitLab (public, private, or self-hosted) on every anchor job, creating an independent audit trail in commit history.\u003C\u002Fp>\n\u003Cp>All three anchoring methods can run simultaneously on every job.\u003C\u002Fp>\n\u003Ch4>Document Management\u003C\u002Fh4>\n\u003Cp>Browser-based editing (no FTP) for Markdown meta-documentation (security.txt, privacy policy, terms of service, etc.) and SEO\u002Fcompliance files: robots.txt, llms.txt, ads.txt, app-ads.txt, sellers.json, ai.txt. Documents get automatic UUID assignment, SHA-256 checksum tracking, and an append-only changelog. Standard and comprehensive XML sitemaps included.\u003C\u002Fp>\n\u003Ch4>Compliance & Audit Tools\u003C\u002Fh4>\n\u003Cp>Metadata CSV, Compliance JSON, and Backup ZIP exports each generate a companion \u003Ccode>.sig.json\u003C\u002Fcode> integrity receipt (SHA-256 hash + optional cryptographic signature). The Compliance JSON export preserves full relationships between posts, hash history, anchor log entries, and RFC 3161 TSR manifests — suitable for legal evidence packages and SIEM ingestion.\u003C\u002Fp>\n\u003Cp>Manual checksum verification (read-only; does not modify anything). Backup & Restore with mandatory dry-run before any restore operation.\u003C\u002Fp>\n\u003Cp>WP-CLI: \u003Ccode>wp archiviomd process-queue\u003C\u002Fcode>, \u003Ccode>anchor-post \u003Cid>\u003C\u002Fcode>, \u003Ccode>verify \u003Cid>\u003C\u002Fcode>, \u003Ccode>prune-log\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch4>Canary Tokens (Steganographic Fingerprinting)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Entirely opt-in. Nothing is injected unless you explicitly enable it.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Embeds an invisible, HMAC-authenticated fingerprint (post ID + timestamp + 48-bit MAC) into published content at render time — stored content is never modified. Fingerprints survive copy-paste and can identify the source of scraped content. A built-in decoder and DMCA Notice Generator are included. Signed evidence packages (\u003Ccode>.sig.json\u003C\u002Fcode>) can be generated after a successful decode for use in legal proceedings.\u003C\u002Fp>\n\u003Cp>Encoding operates across up to 14 channels in three layers:\u003C\u002Fp>\n\u003Cp>\u003Cem>Unicode layer\u003C\u002Fem> (survives copy-paste; stripped by OCR): zero-width characters, thin-space variants, apostrophe variants, soft hyphens.\u003C\u002Fp>\n\u003Cp>\u003Cem>Semantic layer\u003C\u002Fem> (survives OCR and Unicode normalisation; each opt-in): contraction encoding, synonym substitution, punctuation choice, spelling variants, hyphenation choices, number\u002Fdate style, punctuation style II, citation\u002Ftitle style.\u003C\u002Fp>\n\u003Cp>\u003Cem>Structural layer\u003C\u002Fem> (CDN-proof): sentence-count parity, word-count parity.\u003C\u002Fp>\n\u003Cp>Each bit is encoded three times per active channel with majority-vote redundancy. A cache compatibility layer ensures fingerprints survive HTML minification by WP Super Cache, W3 Total Cache, LiteSpeed Cache, WP Rocket, and similar plugins. The Canary Coverage meta box on the post edit screen shows per-channel slot availability before you publish.\u003C\u002Fp>\n\u003Ch4>Ideal For\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Journalists and news publishers requiring tamper-evident records\u003C\u002Fli>\n\u003Cli>Legal teams and compliance departments needing auditable document trails\u003C\u002Fli>\n\u003Cli>Organisations subject to HIPAA, ISO 27001, SOC 2, or NIST SP 800-171 requirements\u003C\u002Fli>\n\u003Cli>Whistleblower platforms and activist publishers requiring integrity without platform trust\u003C\u002Fli>\n\u003Cli>Security researchers requiring transparent, verifiable publish records\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Important Notes\u003C\u002Fh4>\n\u003Cp>All metadata is stored in the WordPress database. Regular database backups are required. All verification, export, and backup operations are admin-triggered and read-only — the plugin does not prevent or block modifications. Markdown and SEO files are stored in \u003Ccode>uploads\u002Fmeta-docs\u002F\u003C\u002Fcode> and are preserved on uninstall.\u003C\u002Fp>\n\u003Ch3>Getting Started\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>Flush Permalinks\u003C\u002Fstrong> — Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Permalinks \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Save Changes. Required for all \u003Ccode>.well-known\u002F\u003C\u002Fcode> endpoints.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Create your first document\u003C\u002Fstrong> — Go to Meta Docs & SEO, pick a predefined file (e.g. security.txt.md), enter content, save. UUID and first changelog entry are created automatically.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Enable content hashing\u003C\u002Fstrong> — Go to Cryptographic Verification \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Settings, choose a hash algorithm (SHA-256 default), save. New and updated posts are hashed automatically from that point.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Configure Ed25519 signing\u003C\u002Fstrong> (optional) — Use the in-browser keypair generator, add both constants to \u003Ccode>wp-config.php\u003C\u002Fcode>, enable signing. Posts, pages, and media are signed automatically on save.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Configure SLH-DSA\u003C\u002Fstrong> (optional) — Navigate to Cryptographic Verification \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> SLH-DSA. Select a parameter set, generate a keypair server-side, add the three constants to \u003Ccode>wp-config.php\u003C\u002Fcode>, enable. Can run alongside Ed25519 (hybrid mode) or standalone.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Enable Rekor \u002F RFC 3161 \u002F Git anchoring\u003C\u002Fstrong> (optional) — Each is configured independently under the ArchivioMD Tools menu. All three can run simultaneously on every anchor job.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Configure DANE\u003C\u002Fstrong> (optional) — Requires at least one signing key. Publish the DNS TXT records shown in the admin panel, enable DNSSEC on your zone, then enable DANE Corroboration and run the health check.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n","Cryptographic content integrity for WordPress — hashing, signing, RFC 3161 timestamps, Rekor transparency log, and DANE corroboration.",720,"2026-05-09T20:06:00.000Z","5.0",[46,47,19,20,22],"compliance","content-integrity","https:\u002F\u002Fmountainviewprovisions.com\u002FArchivioMD","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Farchiviomd.1.19.3.zip",{"slug":51,"name":52,"version":53,"author":54,"author_profile":55,"description":56,"short_description":57,"active_installs":25,"downloaded":58,"rating":25,"num_ratings":59,"last_updated":60,"tested_up_to":61,"requires_at_least":62,"requires_php":63,"tags":64,"homepage":69,"download_link":70,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"24tt-document-verifier","24TT Document Verifier","2.2.0","24 Tech Time","https:\u002F\u002Fprofiles.wordpress.org\u002F24techtime\u002F","\u003Cp>The \u003Cstrong>24TT Document Verifier\u003C\u002Fstrong> is a powerful, enterprise-grade solution designed for institutions, universities, businesses, and government bodies globally to prove the authenticity of their issued documents.\u003C\u002Fp>\n\u003Cp>By embedding a secure verification portal directly into your WordPress website, you instantly protect your institution’s credibility and prevent the dissemination of counterfeit certificates, fake ID cards, and forged official letters.\u003C\u002Fp>\n\u003Ch3>🚀 What’s New in Version 2.2.0? (Expiration Engine & Future-Proofing)\u003C\u002Fh3>\n\u003Cp>Version 2.2.0 brings crucial compliance tools and prepares the plugin for an exciting future!\u003Cbr \u002F>\n* \u003Cstrong>Document Expiration Engine:\u003C\u002Fstrong> You can now set strict “Valid Until” \u002F Expiration dates for time-sensitive documents (like annual licenses, temporary IDs, or limited-term contracts).\u003Cbr \u002F>\n* \u003Cstrong>Bulk Upload Expiration Support:\u003C\u002Fstrong> The Bulk Add tool has been fully upgraded to allow mass-importing of expiration dates directly into your database.\u003Cbr \u002F>\n* \u003Cstrong>Opt-In & Upgrade Bridge:\u003C\u002Fstrong> We’ve integrated a secure, optional connectivity engine (powered by Freemius) to keep you updated on security patches and pave the way for upcoming premium features!\u003C\u002Fp>\n\u003Ch3>🎨 Version 2.1.0 Highlights (Branding & Data Integrity)\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom Branding Engine:\u003C\u002Fstrong> Match your institution’s exact brand colors using new intuitive color pickers for the frontend portal (Background, Button, and Hover states).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Duplicate Data Shield:\u003C\u002Fstrong> A strict new database constraint automatically prevents administrators from accidentally creating multiple documents with the exact same Verification ID via the standard editor or the Bulk Upload tool.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Legacy Duplicate Cleaner:\u003C\u002Fstrong> An automated background sweep that instantly detects and neutralizes any existing duplicate IDs in your database to protect systemic integrity.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🌟 Version 2.0.0 Highlights (The Architecture Overhaul)\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>The “Kill Switch” (Global Settings):\u003C\u002Fstrong> Instant, granular control over your data. Easily toggle which document categories are accessible via the public search portal.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Native File Uploads:\u003C\u002Fstrong> Integrates directly with the native WordPress Media Library to visually upload and attach PDF or JPG files to any document record.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dynamic UI Customizer:\u003C\u002Fstrong> Change the frontend search label instantly from the Settings dashboard.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The “Clean Workspace” Engine:\u003C\u002Fstrong> A premium admin dashboard that suppresses third-party marketing banners for a professional workspace.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart Front-End Rendering:\u003C\u002Fstrong> A modern success card that intelligently hides empty data fields for a flawless user presentation.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Core Features:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom Verification Database:\u003C\u002Fstrong> Manage thousands of verifiable documents directly within a secure WordPress interface.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comprehensive Data Fields:\u003C\u002Fstrong> Store exact details including Verification ID, Recipient Name, Grade\u002FPerformance, Issuing Authority, Expiration Dates, and PDF links.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk Upload Tool:\u003C\u002Fstrong> Massively accelerate your workflow with dynamic, auto-expanding data rows.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Frontend Verification Portal:\u003C\u002Fstrong> Paste the \u003Ccode>[ttdvr_verify_document]\u003C\u002Fcode> shortcode on any page to deploy a beautiful, responsive search form.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Category Segmentation:\u003C\u002Fstrong> Organize records effortlessly using custom taxonomy tags.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Short Description\u003C\u002Fh3>\n\u003Cp>The ultimate enterprise-grade document verification system. Securely issue and verify certificates, ID cards, letters, and receipts directly on your WordPress website.\u003C\u002Fp>\n","The 24TT Document Verifier is a powerful, enterprise-grade solution designed for institutions, universities, businesses, and government bodies globall &hellip;",1736,4,"2026-05-28T08:20:00.000Z","7.0.2","5.8","",[18,65,66,67,68],"certificate-validation","document-verification","enterprise-security","portal","https:\u002F\u002Fwordpress.24techtime.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F24tt-document-verifier.2.2.0.zip",{"slug":72,"name":73,"version":74,"author":75,"author_profile":76,"description":77,"short_description":78,"active_installs":11,"downloaded":79,"rating":11,"num_ratings":11,"last_updated":80,"tested_up_to":14,"requires_at_least":81,"requires_php":82,"tags":83,"homepage":87,"download_link":88,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"signed-posts","Signed Posts","0.5","Marc Armengou","https:\u002F\u002Fprofiles.wordpress.org\u002Fmarc4\u002F","\u003Cp>Signed Posts allows authors to sign posts, assuring content integrity. Signature verification proves post-signing alteration hasn’t occurred.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>In-browser verification:\u003C\u002Fstrong> The signature verification is done on the client side (in the visitor’s browser).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Methods:\u003C\u002Fstrong> OpenPGP (ASCII-armored detached signature) and DID (did:key, did:web) using Ed25519 detached JWS (b64=false).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Source of trust:\u003C\u002Fstrong> For OpenPGP, the author specifies the URL of their public key in their profile. For DID, the author sets their DID (did:key or did:web). For did:web, the plugin fetches \u003Ccode>https:\u002F\u002F\u003Chost>\u002F.well-known\u002Fdid.json\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Status block:\u003C\u002Fstrong> An informative block is automatically added to the end of each signed article, showing the verification status (valid, invalid, or error).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Author badge:\u003C\u002Fstrong> The author name in posts is enhanced with an icon and KeyID\u002Ffingerprint text.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Source Code and Libraries\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>OpenPGP.js\u003C\u002Fstrong>\u003Cbr \u002F>\n* \u003Cstrong>Version:\u003C\u002Fstrong> 6.2.2\u003Cbr \u002F>\n* \u003Cstrong>License:\u003C\u002Fstrong> LGPL-3.0-or-later\u003Cbr \u002F>\n* \u003Cstrong>Public Source Code:\u003C\u002Fstrong> https:\u002F\u002Fgithub.com\u002Fopenpgpjs\u002Fopenpgpjs\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Web Crypto API\u003C\u002Fstrong>\u003Cbr \u002F>\n* Used to verify Ed25519 signatures for DID.\u003C\u002Fp>\n","Signed Posts allows authors to sign posts, assuring content integrity. Signature verification proves post-signing alteration hasn't occurred.",440,"2026-03-07T18:29:00.000Z","6.9","8.2",[84,21,22,85,86],"did","signature","verification","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsigned-posts\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsigned-posts.0.5.zip",{"slug":90,"name":91,"version":92,"author":93,"author_profile":94,"description":95,"short_description":96,"active_installs":97,"downloaded":98,"rating":33,"num_ratings":99,"last_updated":100,"tested_up_to":61,"requires_at_least":101,"requires_php":102,"tags":103,"homepage":108,"download_link":109,"security_score":110,"vuln_count":111,"unpatched_count":11,"last_vuln_date":112,"fetched_at":27},"wordfence","Wordfence Security – Firewall, Malware Scan, and Login Security","8.2.2","Mark Maunder","https:\u002F\u002Fprofiles.wordpress.org\u002Fmmaunder\u002F","\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fi4ZN2TwlaBE?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>THE MOST POPULAR WORDPRESS FIREWALL & SECURITY SCANNER\u003C\u002Fh4>\n\u003Cp>WordPress security requires a team of dedicated analysts researching the latest malware variants and WordPress exploits, turning them into firewall rules and malware signatures, and releasing those to customers in real-time.\u003C\u002Fp>\n\u003Cp>Choose the right protection for you: \u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fproducts\u002Fpricing\u002F\" rel=\"nofollow ugc\">Wordfence Free, Premium, Care or Response\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Wordfence is widely acknowledged as the number one WordPress security research team in the World. Our plugin provides a comprehensive suite of security features, and our team’s research is what powers our plugin and provides the level of security that we are known for.\u003C\u002Fp>\n\u003Cp>At Wordfence, WordPress security isn’t a division of our business – WordPress security is all we do. We employ a global 24-hour dedicated incident response team that provides our priority customers with a 1 hour response time for any security incident.\u003C\u002Fp>\n\u003Cp>The sun never sets on our global security team and we run a sophisticated threat intelligence platform to aggregate, analyze and produce ground breaking security research on the newest security threats.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Wordfence Security includes an endpoint firewall, malware scanner, robust login security features, live traffic views, and more.\u003C\u002Fstrong> Our \u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002F\" rel=\"nofollow ugc\">Threat Defense Feed\u003C\u002Fa> arms Wordfence with the newest firewall rules, malware signatures, and malicious IP addresses it needs to keep your website safe.\u003C\u002Fp>\n\u003Cp>Rounded out by 2FA and a suite of additional features, Wordfence is the most comprehensive WordPress security solution available.\u003C\u002Fp>\n\u003Ch3>🔥 WORDPRESS FIREWALL\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Ffirewall\u002F\" rel=\"nofollow ugc\">Web Application Firewall\u003C\u002Fa>\u003C\u002Fstrong> identifies and blocks malicious traffic. Built and maintained by a large team focused 100% on WordPress security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time firewall rule and malware signature [Premium]\u003C\u002Fstrong> updates via the Threat Defense Feed (free version is delayed by 30 days).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Fblocking\u002F\" rel=\"nofollow ugc\">Real-time IP Blocklist\u003C\u002Fa> [Premium]\u003C\u002Fstrong> blocks all requests from the most malicious IPs, protecting your site while reducing load.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Protects your site at the endpoint\u003C\u002Fstrong>, enabling deep integration with WordPress. Unlike cloud alternatives, it does not break encryption, cannot be bypassed and cannot leak data.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Fscan\u002F\" rel=\"nofollow ugc\">Integrated malware scanner\u003C\u002Fa>\u003C\u002Fstrong> blocks requests that include malicious code or content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Ffirewall\u002Fbrute-force\u002F\" rel=\"nofollow ugc\">Protection from brute force\u003C\u002Fa>\u003C\u002Fstrong> attacks by limiting login attempts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📡 WORDPRESS SECURITY SCANNER\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Malware scanner\u003C\u002Fstrong> checks core files, themes and plugins for malware, bad URLs, backdoors, SEO spam, malicious redirects and code injections.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time malware signature updates [Premium]\u003C\u002Fstrong> via the Threat Defense Feed (free version is delayed by 30 days).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compares with WordPress.org repository\u003C\u002Fstrong> your core files, themes and plugins, checking their integrity and reporting any changes to you.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Repair WordPress core, theme, and plugin files\u003C\u002Fstrong> that have changed by overwriting them with a pristine, original version. Delete any files that don’t belong easily within the Wordfence interface.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Malware Removal Tools\u003C\u002Fstrong> “Delete File” and “Delete All Deletable Files” options allow for efficient malware removal. Remember to investigate the scan results and backup files first!\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checks your site for known security vulnerabilities\u003C\u002Fstrong> and alerts you to any issues. Also alerts you to potential security issues when a plugin has been closed or abandoned.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checks your content safety\u003C\u002Fstrong> by scanning file contents, posts and comments for dangerous URLs and suspicious content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Checks to see if your site or IP have been blocklisted [Premium]\u003C\u002Fstrong> for malicious activity, generating spam or other security issues.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔒 LOGIN SECURITY\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Ftools\u002Ftwo-factor-authentication\u002F\" rel=\"nofollow ugc\">Two-factor authentication (2FA)\u003C\u002Fa>\u003C\u002Fstrong>, one of the most secure forms of remote system authentication available via any TOTP-based authenticator app or service.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Flogin-security\u002F\" rel=\"nofollow ugc\">Login Page CAPTCHA\u003C\u002Fa>\u003C\u002Fstrong> stops bots from logging in.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Flogin-security\u002F#woocommerce-and-custom-integrations\" rel=\"nofollow ugc\">2FA for WooCommerce and custom integrations\u003C\u002Fa>\u003C\u002Fstrong> allow for 2FA to be setup on custom account pages\u003C\u002Fli>\n\u003Cli>\u003Cstrong>XML-RPC\u003C\u002Fstrong> options including disabling or adding 2FA.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Password Security:\u003C\u002Fstrong> Block logins for administrators using known compromised passwords.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>📋 SECURITY AUDIT LOG [Premium]\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Faudit-log\" rel=\"nofollow ugc\">The Audit Log\u003C\u002Fa>\u003C\u002Fstrong> monitors all changes and actions in security-sensitive areas of the site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Remote tamper-proof data storage\u003C\u002Fstrong> via Wordfence Central.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Monitor events and actions\u003C\u002Fstrong> ranging  from user creation and editing to plugin\u002Ftheme installation and updates to post and page changes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable\u003C\u002Fstrong> to log all events or significant events only, which includes all authentication, site configuration, and site functionality events.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🌐 WORDFENCE CENTRAL\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fproducts\u002Fwordfence-central\u002F\" rel=\"nofollow ugc\">Wordfence Central\u003C\u002Fa>\u003C\u002Fstrong> is a powerful and efficient way to manage the security for multiple sites in one place.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Centralized management:\u003C\u002Fstrong> Efficiently assess the security status of all your websites in one view. View detailed security findings without leaving Wordfence Central.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Powerful templates\u003C\u002Fstrong> make configuring Wordfence a breeze.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Highly configurable alerts\u003C\u002Fstrong> can be delivered via email, SMS or Slack. Improve the signal to noise ratio by leveraging severity level options and a daily digest option.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Track and alert on important security events\u003C\u002Fstrong> including administrator logins, breached password usage and surges in attack activity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free to use\u003C\u002Fstrong> for unlimited sites.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🛠️ SECURITY TOOLS\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Ftools\u002Flive-traffic\u002F\" rel=\"nofollow ugc\">Live Traffic\u003C\u002Fa>\u003C\u002Fstrong> monitors visits and hack attempts not shown in other analytics packages in real time; including origin, their IP address, the time of day and time spent on your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Block attackers by IP\u003C\u002Fstrong> or build advanced rules based on IP Range, Hostname, User Agent and Referrer.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fhelp\u002Fblocking\u002Fcountry-blocking\u002F\" rel=\"nofollow ugc\">Country blocking\u003C\u002Fa>\u003C\u002Fstrong> available with Wordfence Premium.\u003C\u002Fli>\n\u003C\u002Ful>\n","Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.",5000000,419061680,4958,"2026-05-13T15:42:00.000Z","4.7","7.0",[104,105,106,107,22],"2fa","firewall","malware","scanner","https:\u002F\u002Fwww.wordfence.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwordfence.8.2.2.zip",96,12,"2022-09-06 00:00:00",{"slug":114,"name":115,"version":116,"author":117,"author_profile":118,"description":119,"short_description":120,"active_installs":121,"downloaded":122,"rating":123,"num_ratings":124,"last_updated":125,"tested_up_to":61,"requires_at_least":126,"requires_php":127,"tags":128,"homepage":132,"download_link":133,"security_score":134,"vuln_count":135,"unpatched_count":11,"last_vuln_date":136,"fetched_at":27},"hostinger","Hostinger Tools","3.0.72","Hostinger","https:\u002F\u002Fprofiles.wordpress.org\u002Fhostinger\u002F","\u003Cp>Hostinger Tools is an all-in-one plugin designed to streamline essential tasks for WordPress site administrators. This plugin offers a range of features to help you manage your site’s information, maintenance mode, security, and redirects effectively.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Basic Info\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Displays the current WordPress version with automatic update checks.\u003C\u002Fli>\n\u003Cli>Shows the current PHP version with automatic update checks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Maintenance Mode\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Easily enable or disable maintenance mode for your site.\u003C\u002Fli>\n\u003Cli>Provide a URL to bypass maintenance mode for selected users.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Security\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enable or disable XML-RPC requests to enhance your site’s security.\u003C\u002Fli>\n\u003Cli>Enable or disable Authorize application page to enhance your site’s security.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Redirects\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Force all URLs to use HTTPS for secure browsing.\u003C\u002Fli>\n\u003Cli>Force all URLs to use WWW to ensure consistency in site access.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>LLMs.txt Generation\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Automatically generate a structured LLMs.txt file in Markdown format.\u003C\u002Fli>\n\u003Cli>Include website title, description, posts, pages, and products (if WooCommerce is active).\u003C\u002Fli>\n\u003Cli>Keep the file updated when content changes or new content is published.\u003C\u002Fli>\n\u003Cli>Help AI-powered tools better understand and interact with your website content.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Hostinger Tools is the new version of the previous Hostinger plugin, offering an updated and enhanced experience.\u003Cbr \u002F>\nThe Onboarding assistant and the Learning section previously included in this plugin were moved to the separate plugin Hostinger Easy Onboarding.\u003C\u002Fp>\n","Simplified WordPress management. Manage site info, maintenance, security, & redirects.",3000000,17985779,70,39,"2026-07-07T08:31:00.000Z","5.5","8.1",[114,129,130,22,131],"https","maintenance","tools","https:\u002F\u002Fhostinger.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhostinger.3.0.72.zip",99,1,"2024-01-05 00:00:00",{"error":138,"url":139,"statusCode":140,"statusMessage":141,"message":141},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Farchivioid\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":135,"versions":143},[144],{"version":145,"download_url":146,"svn_tag_url":147,"released_at":26,"has_diff":148,"diff_files_changed":149,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":150,"is_current":148}," 5.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Farchivioid. 5.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Farchivioid\u002Ftags\u002F 5.1.0\u002F",false,[],[]]