[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIPyQu3EjWNGuVL1GonW7FrS_sb0vTJjz38hm8hdBd0Q":3,"$f9Ev5Y7GPGDbQqLV7DNG1BrETKjAIJI5Z3pmkClG15uQ":135,"$ffqXbRTwBZT4XSknm8hxbrfg65x9S1MEhpaKtboIhbLE":140},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":26,"fingerprints":26},"extensionlifecheck","ExtensionLifeCheck","1.0.0","themifyx","https:\u002F\u002Fprofiles.wordpress.org\u002Fthemifyx\u002F","\u003Cp>ExtensionLifeCheck scans the plugins installed on your site and compares them against the official WordPress.org Plugin API. It highlights plugins that may need attention because they have not been updated recently, are behind the latest release, or have not been tested against your current WordPress version.\u003C\u002Fp>\n\u003Cp>For plugins that need review, ExtensionLifeCheck also suggests one to three actively maintained alternatives from WordPress.org. Results are shown in a sortable admin dashboard and can be exported as a CSV audit report with one click.\u003C\u002Fp>\n\u003Ch4>What ExtensionLifeCheck does\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Reads installed plugins by using native WordPress functions only\u003C\u002Fli>\n\u003Cli>Queries the official WordPress.org Plugin API for plugin metadata\u003C\u002Fli>\n\u003Cli>Flags outdated, abandoned, incompatible, or unlisted plugins for review\u003C\u002Fli>\n\u003Cli>Explains each result in plain English for non-technical site owners\u003C\u002Fli>\n\u003Cli>Suggests actively maintained WordPress.org replacements for flagged plugins\u003C\u002Fli>\n\u003Cli>Exports a CSV report of the latest scan results\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>What ExtensionLifeCheck does not do\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>It does not deactivate, delete, or modify plugins\u003C\u002Fli>\n\u003Cli>It does not add anything to the front end of your site\u003C\u002Fli>\n\u003Cli>It does not collect or transmit personal data\u003C\u002Fli>\n\u003Cli>It only connects to the official WordPress.org Plugin API\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>ExtensionLifeCheck connects to \u003Ccode>api.wordpress.org\u003C\u002Fcode> to request public plugin metadata such as version, tested-up-to, last updated date, and active install counts. No personally identifiable information is sent. Responses are cached locally in WordPress transients for 12 hours to reduce repeated external requests.\u003C\u002Fp>\n","Scan your installed plugins for abandonment risk and discover actively maintained WordPress.org alternatives.",0,60,"2026-07-14T13:06:00.000Z","7.0.2","5.9","7.4",[18,19,20,21,22],"abandoned-plugins","maintenance","plugin-audit","plugins","security","https:\u002F\u002Fthemifyx.com\u002Fextensionlifecheck","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fextensionlifecheck.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},1,30,94,"2026-08-29T08:22:35.052Z",[36,57,75,93,115],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":32,"downloaded":44,"rating":45,"num_ratings":46,"last_updated":47,"tested_up_to":48,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":54,"download_link":55,"security_score":56,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"plugin-auditor","Plugin Auditor","2.4.3","Tom Greenwood","https:\u002F\u002Fprofiles.wordpress.org\u002Fwholegraindigital\u002F","\u003Cp>Have you ever had that situation where you have a bunch of plugins installed and you can’t remember why half of them are there?\u003C\u002Fp>\n\u003Cp>It is important to clean out unused plugins and keep your plugins up to date, but this can be difficult if you have forgotten why you installed them in the first place.  This is particularly true for sites with multiple admin users, and for agencies that manage their clients sites.\u003C\u002Fp>\n\u003Cp>You don’t want to delete an old plugin without being 100% sure why it was installed and therefore know if it is still needed.\u003C\u002Fp>\n\u003Cp>The Plugin Auditor tells you why each plugin was installed and also keeps a record of who installed it so that you know who to ask if you have any questions when performing maintenance on the site.\u003C\u002Fp>\n\u003Cp>Plugin Auditor can be installed at any time but to get the most benefit from it, it should be installed as the first plugin that you install on any WordPress site that you manage.\u003C\u002Fp>\n","Have you ever had that situation where you have a bunch of plugins installed and you can't remember why half of them are there?",4217,86,7,"2019-04-22T17:28:00.000Z","5.1.22","4.0","",[52,53,19,20,22],"audit","audit-trail","http:\u002F\u002Fwww.wholegraindigital.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fplugin-auditor.zip",85,{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":11,"downloaded":65,"rating":11,"num_ratings":11,"last_updated":66,"tested_up_to":67,"requires_at_least":68,"requires_php":69,"tags":70,"homepage":73,"download_link":74,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"the-viking-abandoned-monitor","The Viking Abandoned Monitor","1.0.1","Daniel van der Velden","https:\u002F\u002Fprofiles.wordpress.org\u002Fthevikingwebdesign\u002F","\u003Cp>The Viking Abandoned Monitor is a lightweight, admin-only WordPress plugin that helps you identify potentially abandoned or outdated plugins on your site. It scans all installed plugins and classifies them based on their last update date from the WordPress.org plugins API.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Automatic Plugin Scanning\u003C\u002Fstrong>: Scans all installed plugins and checks their last update date via WordPress.org API\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Status Classification\u003C\u002Fstrong>: Classifies plugins as Safe, Risk, or Abandoned based on configurable thresholds\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dashboard Overview\u003C\u002Fstrong>: Beautiful dashboard with summary cards and filterable plugin table\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Weekly Email Reports\u003C\u002Fstrong>: Automatically sends weekly summary emails with top abandoned and risk plugins\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optional Webhook Integration\u003C\u002Fstrong>: Send data to external services like n8n (completely optional, disabled by default)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WordPress.org Compliant\u003C\u002Fstrong>: Fully compliant with WordPress.org guidelines, no deceptive behavior\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight\u003C\u002Fstrong>: No external SDKs or bloat, uses WordPress core functions only\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure\u003C\u002Fstrong>: Proper nonces, capability checks, and data sanitization\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>How It Works:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>The plugin scans all installed plugins on your site\u003C\u002Fli>\n\u003Cli>For each plugin, it attempts to resolve the WordPress.org slug (from PluginURI, UpdateURI, or folder name)\u003C\u002Fli>\n\u003Cli>It fetches plugin information from WordPress.org API (with 48-hour caching to avoid rate limits)\u003C\u002Fli>\n\u003Cli>Plugins are classified based on their last update date:\n\u003Cul>\n\u003Cli>\u003Cstrong>Safe\u003C\u002Fstrong>: Updated within the risk threshold (default: 6 months)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Risk\u003C\u002Fstrong>: Updated between risk and abandoned thresholds (default: 6-12 months)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Abandoned\u003C\u002Fstrong>: Not updated within abandoned threshold (default: 12+ months)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unknown\u003C\u002Fstrong>: Could not be resolved or API error occurred\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Privacy & Data:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>All plugin data is fetched from public WordPress.org API\u003C\u002Fli>\n\u003Cli>Webhook functionality is completely optional and disabled by default\u003C\u002Fli>\n\u003Cli>If webhook is enabled, you can choose to redact plugin details and send only summary counts\u003C\u002Fli>\n\u003Cli>No data is sent anywhere unless explicitly configured by the site administrator\u003C\u002Fli>\n\u003C\u002Ful>\n","Scans installed plugins and classifies them as Safe \u002F Risk \u002F Abandoned based on last updated date.",268,"2026-01-07T21:02:00.000Z","6.9.5","5.0","7.2",[71,19,72,21,22],"abandoned","monitoring","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fthe-viking-abandoned-monitor\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fthe-viking-abandoned-monitor.1.0.1.zip",{"slug":76,"name":77,"version":78,"author":79,"author_profile":80,"description":81,"short_description":82,"active_installs":11,"downloaded":83,"rating":25,"num_ratings":31,"last_updated":84,"tested_up_to":14,"requires_at_least":85,"requires_php":16,"tags":86,"homepage":91,"download_link":92,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"upgrade-pilot","Upgrade Pilot","1.0.9","Luke W","https:\u002F\u002Fprofiles.wordpress.org\u002Flukeaxiomflow\u002F","\u003Cp>\u003Cstrong>WordPress tells you when a plugin has an update. It never tells you who is behind that update.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Plugins get sold. Authors walk away. Maintainers are quietly added to a project. Occasionally a plugin is closed on WordPress.org for a security problem, and the copy on your site keeps running as if nothing happened. In every one of those cases WordPress shows you exactly what it showed you yesterday: nothing.\u003C\u002Fp>\n\u003Cp>Upgrade Pilot watches the things WordPress does not.\u003C\u002Fp>\n\u003Ch4>Update trust: know who is behind your next update\u003C\u002Fh4>\n\u003Cp>Every day, Upgrade Pilot takes a snapshot of the public WordPress.org record of every plugin you have installed, and compares it to yesterday’s. It tells you when:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>The author changes.\u003C\u002Fstrong> A plugin that just changed hands is the single clearest signal to look before you leap. Ownership transfers are how a trusted plugin becomes an untrusted one, without a single line of visible change.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>New contributors appear.\u003C\u002Fstrong> Someone new now has commit access to code running on your site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>A plugin is closed or removed from WordPress.org\u003C\u002Fstrong>, along with the reason given. Closed plugins receive no further updates, and if the closure was for a security issue you are running known-vulnerable code.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Plugins and themes that have simply gone quiet – nobody has updated them in longer than a threshold you set – are reported in the readiness report rather than emailed to you as an alert, because abandonment is a slow fact, not an event that happened this morning.\u003C\u002Fp>\n\u003Cp>You can then \u003Cstrong>freeze automatic updates for that one plugin\u003C\u002Fstrong>, so a bad release cannot install itself overnight while you decide. The freeze is per plugin, opt in, and never touches WordPress core. Manual updates always remain available. It will not help you hide from a security fix.\u003C\u002Fp>\n\u003Ch4>Upgrade readiness: know the upgrade will not break the site\u003C\u002Fh4>\n\u003Cp>Before you move to a new PHP or WordPress version, Upgrade Pilot answers whether it is safe:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Server checks.\u003C\u002Fstrong> Your PHP version against WordPress’s actual minimum and against the version you plan to move to. Your database version against the requirement of the update WordPress is really being offered, read live from WordPress itself rather than from a number hardcoded by us. Memory limit, extensions, HTTPS.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP security support.\u003C\u002Fstrong> How long the PHP branch you are running still receives security fixes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Every plugin and theme, cross-referenced against WordPress.org.\u003C\u002Fstrong> Which ones declare a PHP requirement higher than your target, which have not been tested against recent WordPress releases, which have not been updated in years, and which have been closed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>A local scan of your plugins’ PHP code\u003C\u002Fstrong>, flagging what modern PHP removed or deprecated, down to the file and line. It runs in small time-sliced batches, so it does not time out, and a file that has not changed since the last scan is not analysed again.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Findings that are honest about their own certainty\u003C\u002Fh4>\n\u003Cp>Deterministic results are labelled \u003Cstrong>fact\u003C\u002Fstrong>. Static-analysis results are labelled \u003Cstrong>advisory\u003C\u002Fstrong>, and never drive the verdict on their own, because version-guarded code and unreachable branches legitimately trigger them. Anything you have inspected and cleared can be suppressed permanently, and the suppression survives future scans.\u003C\u002Fp>\n\u003Ch4>Read only, always\u003C\u002Fh4>\n\u003Cp>Upgrade Pilot never updates, deactivates, installs, or rewrites anything. The one thing it can change is a per-plugin automatic-update hold, and only when you click the button yourself.\u003C\u002Fp>\n\u003Ch4>Also included\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Site Health integration\u003C\u002Fli>\n\u003Cli>Dashboard summary widget\u003C\u002Fli>\n\u003Cli>Email alerts: immediate for critical events, a daily digest for warnings (informational events stay in the UI)\u003C\u002Fli>\n\u003Cli>A weekly scheduled re-scan\u003C\u002Fli>\n\u003Cli>WP-CLI: \u003Ccode>wp upgrade-pilot scan\u003C\u002Fcode>, \u003Ccode>status\u003C\u002Fcode> and \u003Ccode>report\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Machine-readable export, ungated: \u003Ccode>wp upgrade-pilot scan --format=json\u003C\u002Fcode> and \u003Ccode>wp upgrade-pilot report --format=json\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>A REST endpoint for dashboards and fleet tooling: \u003Ccode>GET \u002Fwp-json\u002Fupgrade-pilot\u002Fv1\u002Freport\u003C\u002Fcode>, available to administrators (the \u003Ccode>manage_options\u003C\u002Fcode> capability; super admins on a network)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Works on multisite\u003C\u002Fh4>\n\u003Cp>On a WordPress network, Upgrade Pilot runs at network level, because that is where the truth is: a network shares one copy of each plugin’s files, so who wrote a plugin, whether it was closed, and whether its updates are held are facts about the whole network, not about one subsite. The free version installs network-wide, stores its data once, and is managed by a super admin from the Network Admin screens. Freezing a plugin’s automatic updates holds it across the network, because there is only one copy of the file to hold.\u003C\u002Fp>\n\u003Ch4>Upgrade Pilot Pro\u003C\u002Fh4>\n\u003Cp>Pro adds the things you need when the site belongs to someone else:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>A branded, white-label client report (PDF\u002Fprint) – your name, your colour, no product footer.\u003C\u002Fli>\n\u003Cli>The readiness summary emailed to your client, on a schedule you choose, to as many addresses as you like – and you are told if it fails to send.\u003C\u002Fli>\n\u003Cli>Slack and webhook alerts for update-trust events.\u003C\u002Fli>\n\u003Cli>Automatic update-hold policies: hold a plugin’s automatic updates for a cooling-off period the moment it changes owner or gains a contributor.\u003C\u002Fli>\n\u003Cli>Daily and twice-daily re-scans.\u003C\u002Fli>\n\u003Cli>On a network, the Network Overview: every subsite’s readiness and update-trust status on one screen, and – the question you actually have when a plugin changes hands – exactly which of your sites are running it.\u003C\u002Fli>\n\u003Cli>A private email channel with the developer.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Four things are free that people usually assume are paid, so they are worth saying plainly.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>The machine-readable export is free.\u003C\u002Fem> WP-CLI \u003Ccode>--format=json\u003C\u002Fcode> and the REST endpoint are part of the free version and are not gated, metered or licence-checked.\u003C\u002Fp>\n\u003Cp>\u003Cem>The digest email is free.\u003C\u002Fem> The free version already emails you, the site administrator, immediately when a plugin is closed or flagged, and a daily digest of everything else. What Pro adds is sending the readiness summary to \u003Cem>other people\u003C\u002Fem> – your client – on a schedule you pick, and telling you when a send fails.\u003C\u002Fp>\n\u003Cp>\u003Cem>The weekly re-scan is free\u003C\u002Fem>, and on by default. What Pro adds is running it daily or twice daily.\u003C\u002Fp>\n\u003Cp>\u003Cem>Multisite is free, in full.\u003C\u002Fem> Upgrade Pilot installs network-wide, stores its data once, is managed by a super admin from the Network Admin screens, and a freeze holds across the whole network. What Pro adds on a network is the Network Overview screen described above – not multisite itself.\u003C\u002Fp>\n\u003Cp>Freezing a plugin by hand is free too. What Pro adds is doing it automatically, on a policy.\u003C\u002Fp>\n\u003Cp>Every paid tier includes every feature; tiers differ only by how many sites your licence covers. On a network, each subsite counts as one of those sites, and you activate the licence once from Network Admin to cover them all.\u003C\u002Fp>\n\u003Cp>Pro is a separate download, not an in-place upgrade. When you buy or start a trial you download the Pro build and upload it like any other plugin; it installs alongside this free copy, and activating it switches the free copy off for you. Your settings, scan history and freeze list carry over untouched.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>Upgrade Pilot uses WordPress.org, always. It uses Freemius – who sell and license the paid version – only when you go looking for the paid version, and only in the four situations listed below.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. WordPress.org Plugin and Theme API (api.wordpress.org)\u003C\u002Fstrong>\u003Cbr \u002F>\nThis is the plugin’s data source and is always used.\u003Cbr \u002F>\n\u003Cem>What is sent:\u003C\u002Fem> the public slug of a plugin or theme installed on your site. Nothing else. No site URL, no user data, no configuration. The requests identify themselves only as “UpgradePilot\u002F” followed by the plugin version.\u003Cbr \u002F>\n\u003Cem>When:\u003C\u002Fem> when you run a readiness scan, and once daily as part of the update-trust snapshot that detects author changes, new contributors, closures, and abandonment.\u003Cbr \u002F>\n\u003Cem>Why:\u003C\u002Fem> to read the public directory record for that plugin (author, contributors, last updated, tested-up-to, required PHP, and whether it has been closed).\u003Cbr \u002F>\n\u003Cem>Note:\u003C\u002Fem> WordPress core already contacts this same API for its own update checks.\u003Cbr \u002F>\n\u003Cem>How much:\u003C\u002Fem> plugin lookups are batched – every plugin on the site is asked for in a single request, so a 40-plugin site makes one plugin request, not forty. The theme API has no batch mode, so themes cost one request each. Answers are cached for 24 hours (72 hours for “not in the directory”), and 429 or 5xx responses trigger a backoff that later calls respect. A typical 40-plugin, 3-theme site therefore makes about four or five requests a day in total.\u003Cbr \u002F>\nPrivacy: https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\u003Cbr \u002F>\nWordPress.org publishes a privacy policy but no separate terms-of-use document for this API. It is the same public API, on the same host, that WordPress core itself queries for update checks.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2. Freemius (freemius.com), who sell and license Upgrade Pilot Pro\u003C\u002Fstrong>\u003Cbr \u002F>\nFreemius is contacted in four situations. Every one of them is something you click. It is never contacted in the background.\u003C\u002Fp>\n\u003Cp>\u003Cem>You opt in, start a trial, or activate a licence.\u003C\u002Fem>\u003Cbr \u002F>\nSent to api.freemius.com: your site URL, your WordPress and PHP versions, and the email address of the account you activate with. This only happens after you explicitly opt in on the activation screen, or when you start a trial or activate a licence.\u003C\u002Fp>\n\u003Cp>\u003Cem>You open the “Upgrade” page.\u003C\u002Fem>\u003Cbr \u002F>\nThe plugin adds an “Upgrade” item to its own menu, and the Reports & Automation screen links to it. Opening that page asks Freemius for the current plan prices so it can show them to you (api.freemius.com), and that request carries your site URL. Nothing else is sent. This happens whoever you are, including if you skipped the opt-in – but only when you open that page. If you never open it, it never runs.\u003Cbr \u002F>\nThat request is made by your own server, not by your browser: the page talks to your site’s admin-ajax, and your site talks to Freemius. The page itself loads no third-party scripts at all. Everything it renders – the plan table, the icons, the payment-brand badges – is served from this plugin’s own folder. The payment SDK’s bundled pricing script used to inject Google Analytics and a remote checkout script into your dashboard on that page; this build removes both, along with the SDK’s remaining remote references (all four modifications are listed under “Source code” below).\u003C\u002Fp>\n\u003Cp>\u003Cem>You click “Contact Us”.\u003C\u002Fem>\u003Cbr \u002F>\nThat opens Freemius’s hosted support form (wp.freemius.com). The link carries your site URL and your WordPress login URL, so the form knows which site you are writing about.\u003C\u002Fp>\n\u003Cp>\u003Cem>You click a plan, to buy or to start a trial.\u003C\u002Fem>\u003Cbr \u002F>\nThat takes you to Freemius’s checkout page (checkout.freemius.com). It receives your site URL, your site name, your WordPress and PHP versions, and \u003Cstrong>your WordPress administrator email address, which is filled in for you – you do not have to type it, and it is sent whether you complete the purchase or not.\u003C\u002Fstrong> Freemius is the merchant of record for the sale.\u003Cbr \u002F>\nThat checkout page is Freemius’s, not ours, and like any hosted checkout it loads its own third-party scripts. At the time of writing those are: Stripe (js.stripe.com) and PayPal (www.paypal.com, www.paypalobjects.com) to take payment, Google Tag Manager (www.googletagmanager.com) for their analytics, and Freemius’s own scripts and images (js.freemius.com, cdnjs.cloudflare.com, s3-us-west-2.amazonaws.com). We do not control that list and it can change. What happens on that page is governed by Freemius’s privacy policy, linked below. If you never click a plan, none of it loads.\u003Cbr \u002F>\nTerms: https:\u002F\u002Ffreemius.com\u002Fterms\u002F – Privacy: https:\u002F\u002Ffreemius.com\u002Fprivacy\u002F\u003C\u002Fp>\n\u003Ch4>What does not happen\u003C\u002Fh4>\n\u003Cp>The list above is not written from memory. Every outbound request the plugin causes was logged, and these are the results: installing and activating the plugin, the opt-in screen itself, skipping the opt-in, every one of the plugin’s own screens, deactivating the plugin (the payment SDK’s deactivation-feedback dialog is switched off in this build, so deactivation is one click and sends nothing), WordPress’s plugin-update cycle, and every scheduled background task – all of them complete without contacting Freemius at all. No telemetry, no scan data, no site data. Every Freemius contact listed above is the direct result of something you clicked.\u003C\u002Fp>\n\u003Cp>The free plugin is fully functional whether you opt in or skip. If you would rather not use Freemius’s support form, the WordPress.org support forum for this plugin is linked from the same menu and sends nothing anywhere.\u003C\u002Fp>\n\u003Cp>There is no security feed to call, and no server of ours for this plugin to contact. Anything Upgrade Pilot knows about a plugin’s security standing, it learned from that plugin’s public WordPress.org record – most importantly, whether the directory has closed it, and the reason the directory gave.\u003C\u002Fp>\n\u003Ch3>Source code\u003C\u002Fh3>\n\u003Cp>Every line Upgrade Pilot itself runs ships in this plugin, unminified and unobfuscated. Its own CSS and JavaScript (\u003Ccode>admin\u002Fcss\u002Fupilot-admin.css\u003C\u002Fcode>, \u003Ccode>admin\u002Fjs\u002Fupilot-admin.js\u003C\u002Fcode>) are the files you read, not build output; there is no build step and no compiled asset.\u003C\u002Fp>\n\u003Cp>The one exception is the third-party payment SDK in \u003Ccode>vendor\u002Ffreemius\u002F\u003C\u002Fcode>, which ships pre-minified. Those files are the Freemius WordPress SDK, published under the GPL, and their unminified source and build tooling are public:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Freemius WordPress SDK: https:\u002F\u002Fgithub.com\u002FFreemius\u002Fwordpress-sdk\u003C\u002Fli>\n\u003Cli>The pricing screen bundled at \u003Ccode>vendor\u002Ffreemius\u002Fassets\u002Fjs\u002Fpricing\u002Ffreemius-pricing.js\u003C\u002Fcode>: https:\u002F\u002Fgithub.com\u002FFreemius\u002Fpricing-page\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The minified files under \u003Ccode>vendor\u002Ffreemius\u002F\u003C\u002Fcode> are: \u003Ccode>assets\u002Fjs\u002Fpricing\u002Ffreemius-pricing.js\u003C\u002Fcode>, \u003Ccode>assets\u002Fjs\u002Fpostmessage.js\u003C\u002Fcode>, \u003Ccode>assets\u002Fjs\u002Fnojquery.ba-postmessage.js\u003C\u002Fcode>, \u003Ccode>assets\u002Fjs\u002Fjquery.form.js\u003C\u002Fcode>, and thirteen stylesheets under \u003Ccode>assets\u002Fcss\u002F\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>Upgrade Pilot ships four deliberate modifications to that SDK, all in \u003Ccode>assets\u002Fjs\u002Fpricing\u002Ffreemius-pricing.js\u003C\u002Fcode>, all removing remote references from wp-admin, each marked with an “Upgrade Pilot:” comment at the patch site:\u003C\u002Fp>\n\u003Col>\n\u003Cli>The \u003Ccode>appendScripts()\u003C\u002Fcode> method is emptied. Upstream it injects \u003Ccode>https:\u002F\u002Fwww.google-analytics.com\u002Fanalytics.js\u003C\u002Fcode> and \u003Ccode>https:\u002F\u002Fcheckout.freemius.com\u002Fcheckout.js\u003C\u002Fcode> into wp-admin when the pricing screen renders. Neither belongs in a WordPress dashboard, and the analytics script ran even for people who had declined the opt-in.\u003C\u002Fli>\n\u003Cli>The Google Analytics pageview tracker is stubbed out. Upstream it reports pricing-page views to Freemius’s Analytics property whenever a GA object is already present in wp-admin (for example, loaded there by an unrelated plugin), stamping them with the Freemius user id.\u003C\u002Fli>\n\u003Cli>A loading-spinner image served from Freemius’s CDN (\u003Ccode>img.freemius.com\u003C\u002Fcode>) is replaced with an inline image.\u003C\u002Fli>\n\u003Cli>Testimonial author photos, which upstream loads from Gravatar or a remote URL supplied by the Freemius API, always use the bundled placeholder instead.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The pricing screen and the checkout both work without all four.\u003C\u002Fp>\n\u003Cp>Third-party libraries inside that SDK bundle, all GPL-compatible: React 17 (MIT), object-assign (MIT), is-buffer (MIT), and Font Awesome Free 5 (code MIT, icons CC BY 4.0). No library that WordPress itself ships is bundled anywhere in this plugin – jQuery and the other core scripts are used from WordPress’s own copies, by handle.\u003C\u002Fp>\n","Know when a plugin changes hands, gets abandoned, or is closed. Freeze its updates. And check your site survives the next WordPress and PHP upgrade.",57,"2026-07-17T03:22:00.000Z","6.2",[18,87,88,89,90],"php-compatibility","plugin-security","supply-chain","updates","https:\u002F\u002Fbuildsbyluke.com\u002Fplugins\u002Fupgrade-pilot","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fupgrade-pilot.1.0.9.zip",{"slug":94,"name":95,"version":96,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":101,"downloaded":102,"rating":103,"num_ratings":104,"last_updated":105,"tested_up_to":14,"requires_at_least":106,"requires_php":107,"tags":108,"homepage":111,"download_link":112,"security_score":113,"vuln_count":31,"unpatched_count":11,"last_vuln_date":114,"fetched_at":27},"hostinger","Hostinger Tools","3.0.72","Hostinger","https:\u002F\u002Fprofiles.wordpress.org\u002Fhostinger\u002F","\u003Cp>Hostinger Tools is an all-in-one plugin designed to streamline essential tasks for WordPress site administrators. This plugin offers a range of features to help you manage your site’s information, maintenance mode, security, and redirects effectively.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cem>Basic Info\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Displays the current WordPress version with automatic update checks.\u003C\u002Fli>\n\u003Cli>Shows the current PHP version with automatic update checks.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Maintenance Mode\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Easily enable or disable maintenance mode for your site.\u003C\u002Fli>\n\u003Cli>Provide a URL to bypass maintenance mode for selected users.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Security\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Enable or disable XML-RPC requests to enhance your site’s security.\u003C\u002Fli>\n\u003Cli>Enable or disable Authorize application page to enhance your site’s security.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Redirects\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Force all URLs to use HTTPS for secure browsing.\u003C\u002Fli>\n\u003Cli>Force all URLs to use WWW to ensure consistency in site access.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>LLMs.txt Generation\u003C\u002Fem>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Automatically generate a structured LLMs.txt file in Markdown format.\u003C\u002Fli>\n\u003Cli>Include website title, description, posts, pages, and products (if WooCommerce is active).\u003C\u002Fli>\n\u003Cli>Keep the file updated when content changes or new content is published.\u003C\u002Fli>\n\u003Cli>Help AI-powered tools better understand and interact with your website content.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Hostinger Tools is the new version of the previous Hostinger plugin, offering an updated and enhanced experience.\u003Cbr \u002F>\nThe Onboarding assistant and the Learning section previously included in this plugin were moved to the separate plugin Hostinger Easy Onboarding.\u003C\u002Fp>\n","Simplified WordPress management. Manage site info, maintenance, security, & redirects.",3000000,17985779,70,39,"2026-07-07T08:31:00.000Z","5.5","8.1",[94,109,19,22,110],"https","tools","https:\u002F\u002Fhostinger.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhostinger.3.0.72.zip",99,"2024-01-05 00:00:00",{"slug":116,"name":117,"version":118,"author":119,"author_profile":120,"description":121,"short_description":122,"active_installs":123,"downloaded":124,"rating":25,"num_ratings":125,"last_updated":126,"tested_up_to":14,"requires_at_least":127,"requires_php":69,"tags":128,"homepage":132,"download_link":133,"security_score":25,"vuln_count":31,"unpatched_count":11,"last_vuln_date":134,"fetched_at":27},"xo-security","XO Security","3.11.0","ishitaka","https:\u002F\u002Fprofiles.wordpress.org\u002Fishitaka\u002F","\u003Cp>XO Security is a plugin to enhance login related security.\u003Cbr \u002F>\nThis plugin does not write to .htaccess file. Besides Apache, LiteSpeed, Nginx and IIS also work.\u003C\u002Fp>\n\u003Ch4>Functions\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Record login log.\u003C\u002Fli>\n\u003Cli>Limit login attempts.\u003C\u002Fli>\n\u003Cli>Add Captcha to the login form and comment form.\u003C\u002Fli>\n\u003Cli>Change the URL of the login page.\u003C\u002Fli>\n\u003Cli>Enable two-factor authentication (2FA) for login.\u003C\u002Fli>\n\u003Cli>Login Alert.\u003C\u002Fli>\n\u003Cli>Disable login by mail address.\u003C\u002Fli>\n\u003Cli>Disable login by user name.\u003C\u002Fli>\n\u003Cli>Change login error message.\u003C\u002Fli>\n\u003Cli>Disable XML-RPC and XML-RPC Pingback.\u003C\u002Fli>\n\u003Cli>Disable REST API.\u003C\u002Fli>\n\u003Cli>Disable author archive page.\u003C\u002Fli>\n\u003Cli>Remove comment author class of comments list.\u003C\u002Fli>\n\u003Cli>Remove the username from the oEmbed response data.\u003C\u002Fli>\n\u003Cli>WooCommerce login page protection.\u003C\u002Fli>\n\u003Cli>Anti-spam comment.\u003C\u002Fli>\n\u003Cli>Hide WordPress version information.\u003C\u002Fli>\n\u003Cli>Edit the author slug.\u003C\u002Fli>\n\u003Cli>Disable RSS and Atom feeds.\u003C\u002Fli>\n\u003Cli>Activate maintenance mode.\u003C\u002Fli>\n\u003Cli>Delete the readme.html file.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WordPress multisite considerations\u003C\u002Fh4>\n\u003Cp>If you set the login page separately for the main site and the subsite, you will not be able to use the password loss function of the subsite. We recommend that you set the login page to be common to all sites.\u003C\u002Fp>\n","XO Security is a plugin to enhance login related security.",30000,397056,11,"2026-07-19T10:16:00.000Z","6.0",[129,130,19,22,131],"brute-force","login","two-factor","https:\u002F\u002Fxakuro.com\u002Fwordpress\u002Fxo-security\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fxo-security.3.11.0.zip","2017-02-07 00:00:00",{"error":136,"url":137,"statusCode":138,"statusMessage":139,"message":139},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fextensionlifecheck\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":11,"versions":141},[]]