[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3sL0yryk4s2UO_vgL-PtmB4P35kj4KncC6ZVIs37Z-E":3,"$fZH0LpGJwyYhDTr1e7hlfWawvhLk0PassGvLlxP5f578":116,"$fHwEPU6Pkp3gwLlnhBnAfH1Fx5l1lltT68tpDk8L7muc":121},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":27,"fingerprints":27},"npc-maintenance-inspector","NPC Maintenance Inspector","1.0.1","npc01","https:\u002F\u002Fprofiles.wordpress.org\u002Fnpc01\u002F","\u003Cp>NPC Maintenance Inspector performs 9-point health diagnostics on your WordPress site directly from the admin dashboard:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>WordPress core updates\u003C\u002Fstrong> — Detect missing core updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin updates\u003C\u002Fstrong> — List plugins with available updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Site Health issues\u003C\u002Fstrong> — Extract critical issues from WP standard Site Health API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PHP version\u003C\u002Fstrong> — Warn on end-of-life PHP versions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Error log analysis\u003C\u002Fstrong> — Summarize debug.log entries and save a one-click backup to uploads\u002F for safe review.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File integrity\u003C\u002Fstrong> — Detect suspicious code patterns in core files (eval \u002F base64_decode \u002F etc.) by comparing checksums against the WordPress.org Checksum API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suspicious files\u003C\u002Fstrong> — Find unexpected PHP files in wp-content\u002Fuploads\u002F, with built-in whitelist for known legitimate plugin files (Ajax Load More templates, WP STAGING index.php, AIOS firewall rules, etc.).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SSL certificate\u003C\u002Fstrong> — Check days until expiration (warn under 30 days, critical at 0).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>File permissions\u003C\u002Fstrong> — Check critical files like wp-config.php, .htaccess, wp-content\u002F.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Operational features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>History\u003C\u002Fstrong> — Keep the last 10 diagnoses as a custom post type.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scheduled auto-check\u003C\u002Fstrong> — Run daily, weekly, or monthly via WP Cron.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email notifications\u003C\u002Fstrong> — Send alerts only on critical issues.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>One-click debug.log clear\u003C\u002Fstrong> — Truncate the log while preserving file permissions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optional AI report\u003C\u002Fstrong> — Generate maintenance suggestions via Anthropic Claude API. Disabled by default; opt-in via a wp-config.php constant.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin is locked to the user who activated it and to the original site URL, so it stays inert after backup restores to a different domain.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin can optionally connect to the \u003Cstrong>Anthropic Claude API\u003C\u002Fstrong> (\u003Ccode>https:\u002F\u002Fapi.anthropic.com\u002Fv1\u002Fmessages\u003C\u002Fcode>) to generate AI-powered maintenance reports. This is the only external service the plugin ever contacts.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When is data sent?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>When you manually click the “Generate AI Report” button in the admin.\u003C\u002Fli>\n\u003Cli>When an automatic scheduled diagnosis detects a critical issue \u003Cstrong>and\u003C\u002Fstrong> notifications are enabled. In that case the AI report is generated once per critical run and attached to the notification email.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What data is sent?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>The diagnosis result text only:\n\u003Cul>\n\u003Cli>Site URL, site name, WordPress version, theme name\u003C\u002Fli>\n\u003Cli>Counts of plugin updates \u002F Site Health issues \u002F error-log entries\u003C\u002Fli>\n\u003Cli>PHP version, memory limit, max upload size\u003C\u002Fli>\n\u003Cli>SSL expiration date and days remaining\u003C\u002Fli>\n\u003Cli>File-permission status of critical files\u003C\u002Fli>\n\u003Cli>Suspicious code patterns detected (function names like \u003Ccode>eval\u003C\u002Fcode>, \u003Ccode>base64_decode\u003C\u002Fcode>)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>No login data, no post content, no personal data of site visitors.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Is the data sent unconditionally?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>No. The AI feature is \u003Cstrong>completely disabled\u003C\u002Fstrong> unless you define \u003Ccode>NPCMI_API_KEY\u003C\u002Fcode> in \u003Ccode>wp-config.php\u003C\u002Fcode>. Without that constant, no external connection to Anthropic is ever made.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Anthropic’s terms and privacy policy:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Consumer Terms of Service: https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fconsumer-terms\u003C\u002Fli>\n\u003Cli>Privacy Policy: https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fprivacy\u003C\u002Fli>\n\u003Cli>Commercial Terms of Service (if you use a paid API plan): https:\u002F\u002Fwww.anthropic.com\u002Flegal\u002Fcommercial-terms\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>By enabling the AI report feature (i.e. by defining \u003Ccode>NPCMI_API_KEY\u003C\u002Fcode>), you agree to Anthropic’s applicable terms.\u003C\u002Fp>\n","WordPress maintenance health-check tool with 9-point diagnostics, history tracking, and optional AI-powered reports.",20,211,0,"2026-05-20T09:32:00.000Z","7.0.2","6.0","7.4",[19,20,21,22,23],"diagnostics","healthcheck","maintenance","monitoring","security","https:\u002F\u002Fn-pc.jp\u002Fproducts\u002Fmaintenance-inspector\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnpc-maintenance-inspector.1.0.1.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":33,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},3,50,30,94,"2026-08-26T03:37:17.090Z",[38,55,70,86,101],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":13,"downloaded":46,"rating":13,"num_ratings":13,"last_updated":47,"tested_up_to":15,"requires_at_least":48,"requires_php":49,"tags":50,"homepage":53,"download_link":54,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"aegra-site-monitor","Aegra Site Monitor","1.0.55","Rob Art","https:\u002F\u002Fprofiles.wordpress.org\u002Frobword\u002F","\u003Cp>Aegra Site Monitor gives you a single place to understand what is happening on your WordPress site. The free version provides snapshots and lists across ten modules. The Pro version adds history, trends, alerts, and automation.\u003C\u002Fp>\n\u003Ch4>Free Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Dashboard overview with live stats\u003C\u002Fli>\n\u003Cli>Activity log — admin sessions, logins, plugin changes\u003C\u002Fli>\n\u003Cli>Broken link scanner — manual scan with recheck\u003C\u002Fli>\n\u003Cli>Content audit — post counts, drafts, missing images\u003C\u002Fli>\n\u003Cli>Database overview — table sizes, autoload, transients\u003C\u002Fli>\n\u003Cli>Media library overview — counts, file types, alt text gaps\u003C\u002Fli>\n\u003Cli>Traffic — page views, referrers, devices, countries\u003C\u002Fli>\n\u003Cli>Users — roles, last login\u003C\u002Fli>\n\u003Cli>System info — WP, PHP, server environment\u003C\u002Fli>\n\u003Cli>Plugin and theme list with update status\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Pro Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Full audit trail — who changed what, when\u003C\u002Fli>\n\u003Cli>Database snapshots and comparison\u003C\u002Fli>\n\u003Cli>Slow query monitor\u003C\u002Fli>\n\u003Cli>Scheduled scans and reports\u003C\u002Fli>\n\u003Cli>Email alerts and thresholds\u003C\u002Fli>\n\u003Cli>File integrity monitoring\u003C\u002Fli>\n\u003Cli>Performance over time — memory, AJAX, slow pages\u003C\u002Fli>\n\u003Cli>Core Web Vitals collection\u003C\u002Fli>\n\u003Cli>Content freshness, orphan detection, SEO structure checks\u003C\u002Fli>\n\u003Cli>WooCommerce deep analytics\u003C\u002Fli>\n\u003Cli>Multi-site monitoring\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Uninstall\u003C\u002Fh3>\n\u003Cp>When you delete Aegra Site Monitor from the Plugins screen, the uninstall script automatically removes all plugin data stored in your WordPress database, including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>All plugin settings and configuration options\u003C\u002Fli>\n\u003Cli>Licence key and validation data\u003C\u002Fli>\n\u003Cli>Traffic tracking settings and recorded visitor data\u003C\u002Fli>\n\u003Cli>Security settings, IP block rules, and brute-force records\u003C\u002Fli>\n\u003Cli>Login attempt log\u003C\u002Fli>\n\u003Cli>Activity log and session records\u003C\u002Fli>\n\u003Cli>Broken link scan results\u003C\u002Fli>\n\u003Cli>Performance snapshot history\u003C\u002Fli>\n\u003Cli>Scheduled report configuration\u003C\u002Fli>\n\u003Cli>Media confirmation records\u003C\u002Fli>\n\u003Cli>All cached scan results and authentication transients\u003C\u002Fli>\n\u003Cli>All scheduled cron jobs registered by the plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The uninstall script does \u003Cstrong>not\u003C\u002Fstrong> delete:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Any site content (posts, pages, media files, users, etc.)\u003C\u002Fli>\n\u003Cli>The optional MaxMind GeoLite2 database file, if you downloaded one (stored under your uploads directory) — remove it manually if you no longer need it\u003C\u002Fli>\n\u003Cli>Any data held by external services — see the External Services section below for the only outbound connection this plugin makes\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Aegra Site Monitor creates four custom database tables (\u003Ccode>wp_aegra_traffic\u003C\u002Fcode>, \u003Ccode>wp_aegra_login_attempts\u003C\u002Fcode>, \u003Ccode>wp_aegra_activity_sessions\u003C\u002Fcode>, \u003Ccode>wp_aegra_broken_links\u003C\u002Fcode>). All four are fully dropped on uninstall.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>Aegra Site Monitor uses the following external service:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>MaxMind GeoLite2 (optional)\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The Traffic feature can use the MaxMind GeoLite2 database to show the country of visitor IP addresses. The database is downloaded to your own server only when you choose to enable this feature and provide your own free MaxMind account credentials. When you request the download, the plugin contacts MaxMind to retrieve the database file; your MaxMind account ID and licence key are sent to MaxMind to authenticate that download. During normal operation no visitor data is sent to MaxMind — IP lookups happen locally against the downloaded database. If you never enable this feature, the plugin makes no external requests.\u003C\u002Fp>\n\u003Cp>Provided by MaxMind, Inc.:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>GeoLite2 End User License Agreement: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fgeolite\u002Feula\u003C\u002Fli>\n\u003Cli>Privacy Policy: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fprivacy-policy\u003C\u002Fli>\n\u003Cli>Website Terms of Use: https:\u002F\u002Fwww.maxmind.com\u002Fen\u002Fterms-of-use\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No other data is sent to any external service without your action.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For documentation, guides, and FAQs visit the \u003Ca href=\"https:\u002F\u002Frobsnow.eu\u002Fplugins-wordpress-development\u002Fhelp-documentation-wp\u002F\" rel=\"nofollow ugc\">Help & Documentation\u003C\u002Fa> page.\u003C\u002Fp>\n\u003Cp>For bug reports or feature requests, please use the support forum on the plugin page or contact us via the \u003Ca href=\"https:\u002F\u002Frobsnow.eu\u002Fplugins-wordpress-development\u002Faegra-site-monitor\u002F\" rel=\"nofollow ugc\">Aegra Site Monitor plugin page\u003C\u002Fa>.\u003C\u002Fp>\n","The all-seeing WordPress monitor. Track admin activity, audit content, find broken links, and keep an eye on system health — all from one dashboard.",204,"2026-06-28T14:50:00.000Z","6.2","8.0",[51,19,22,52,23],"analytics","performance","https:\u002F\u002Frobsnow.eu\u002Fplugins-wordpress-development\u002Faegra-site-monitor\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faegra-site-monitor.1.0.55.zip",{"slug":56,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":13,"downloaded":63,"rating":13,"num_ratings":13,"last_updated":64,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":65,"homepage":68,"download_link":69,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"csgaku-site-state-check","CSGaku Site State Check","1.0.0","csgaku","https:\u002F\u002Fprofiles.wordpress.org\u002Fcsgaku\u002F","\u003Cp>CSGaku Site State Check is a lightweight plugin for reviewing basic WordPress site status from the admin area.\u003C\u002Fp>\n\u003Cp>The plugin is designed for administrators and developers who want to check important maintenance and security-related signals on demand. It does not automatically repair, delete, or change site settings. It presents the current state so the site administrator can decide what to review next.\u003C\u002Fp>\n\u003Cp>CSGaku Site State Check does not use external API communication or external vulnerability database lookups for its checks. It uses information available within the WordPress site and server environment.\u003C\u002Fp>\n\u003Cp>The plugin can run on PHP 7.4 or later, but PHP 8.2 or later is recommended.\u003C\u002Fp>\n\u003Cp>Design principles:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>No external API or external service communication for normal checks\u003C\u002Fli>\n\u003Cli>No automatic repair\u003C\u002Fli>\n\u003Cli>No automatic deletion\u003C\u002Fli>\n\u003Cli>No automatic setting changes\u003C\u002Fli>\n\u003Cli>No direct display of secret values or full file contents\u003C\u002Fli>\n\u003Cli>Results organized by status and severity\u003C\u002Fli>\n\u003Cli>Latest result, simple local history, and CSV export support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Main checks include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>PHP version\u003C\u002Fli>\n\u003Cli>WordPress version\u003C\u002Fli>\n\u003Cli>Site URL and home URL\u003C\u002Fli>\n\u003Cli>SSL status\u003C\u002Fli>\n\u003Cli>Sitemap\u003C\u002Fli>\n\u003Cli>Debug settings\u003C\u002Fli>\n\u003Cli>wp-config.php\u003C\u002Fli>\n\u003Cli>.htaccess\u003C\u002Fli>\n\u003Cli>index.php\u003C\u002Fli>\n\u003Cli>wp-admin, wp-content, and wp-includes\u003C\u002Fli>\n\u003Cli>Public access protection for debug.log\u003C\u002Fli>\n\u003Cli>PHP execution prevention setting in uploads\u003C\u002Fli>\n\u003Cli>wp-config.php structure and location\u003C\u002Fli>\n\u003Cli>SALT constants\u003C\u002Fli>\n\u003Cli>Administrator user count\u003C\u002Fli>\n\u003Cli>Presence of the admin username\u003C\u002Fli>\n\u003Cli>Older administrator accounts\u003C\u002Fli>\n\u003Cli>Application passwords\u003C\u002Fli>\n\u003Cli>Search engine visibility setting\u003C\u002Fli>\n\u003Cli>XML-RPC status\u003C\u002Fli>\n\u003Cli>Core, plugin, and theme update status\u003C\u002Fli>\n\u003Cli>Inactive plugins\u003C\u002Fli>\n\u003Cli>Unused theme candidates\u003C\u002Fli>\n\u003Cli>444 and 555 permissions under wp-content\u003C\u002Fli>\n\u003Cli>uploads\u002FYYYY\u002F.htaccess and uploads\u002FYYYY\u002FMM\u002F.htaccess\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>About obfuscation-related checks:\u003C\u002Fp>\n\u003Cp>CSGaku Site State Check can review index.php for patterns that are sometimes associated with obfuscation, such as base64, eval, gzinflate, long Base64-like strings, hex escapes, and chr concatenation. If such patterns are found, they are shown as items to review. They are not treated as final proof of malicious code by themselves.\u003C\u002Fp>\n\u003Cp>About permissions:\u003C\u002Fp>\n\u003Cp>The plugin checks 444 and 555 permissions under wp-content. These permissions may be intentional in some environments, but they can also affect updates, deletion, and maintenance work. When such items are found under themes, the plugin can note that they may be intentional depending on the environment.\u003C\u002Fp>\n\u003Cp>About uploads security:\u003C\u002Fp>\n\u003Cp>The plugin checks whether uploads\u002F.htaccess contains PHP execution prevention rules, and it also checks for .htaccess files under uploads year\u002Fmonth folders. If relevant .htaccess files are found in those locations, they are shown for review without displaying file contents.\u003C\u002Fp>\n\u003Cp>About CSV export:\u003C\u002Fp>\n\u003Cp>The latest result can be exported as CSV with a UTF-8 BOM for compatibility with spreadsheet applications. To reduce CSV formula injection risk, values starting with dangerous leading characters are escaped before export.\u003C\u002Fp>\n\u003Cp>Important limitations:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>This plugin is a confirmation tool.\u003C\u002Fli>\n\u003Cli>It does not provide malware cleanup.\u003C\u002Fli>\n\u003Cli>It does not provide automatic remediation.\u003C\u002Fli>\n\u003Cli>It does not provide complete vulnerability assessment.\u003C\u002Fli>\n\u003Cli>It does not guarantee detection of all issues.\u003C\u002Fli>\n\u003Cli>Final review and response should be handled by the site administrator.\u003C\u002Fli>\n\u003C\u002Ful>\n","Checks key WordPress site status items from the admin area without external API communication or automatic changes.",129,"2026-06-04T06:02:00.000Z",[66,19,21,23,67],"admin","tools","https:\u002F\u002Fwp-r.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcsgaku-site-state-check.1.0.0.zip",{"slug":71,"name":72,"version":73,"author":74,"author_profile":75,"description":76,"short_description":77,"active_installs":13,"downloaded":78,"rating":13,"num_ratings":13,"last_updated":79,"tested_up_to":80,"requires_at_least":81,"requires_php":17,"tags":82,"homepage":84,"download_link":85,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"fae-herald","Fae Herald","1.1.0","Frederik Rosendahl-Kaa","https:\u002F\u002Fprofiles.wordpress.org\u002Ffrederik-rosendahl-kaa\u002F","\u003Cp>Fae Herald helps you maintain a secure WordPress site by monitoring when your installed plugins were last updated and alerting you to potential security risks.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Last Version Release Monitoring\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Shows exact date for plugins updated within 6 months, “X months ago” for 6-12 months\u003C\u002Fli>\n\u003Cli>Warning: not updated in over 1 year\u003C\u002Fli>\n\u003Cli>Critical: not updated in over 2 years\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Closed Plugin Detection\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Detects closed\u002Fremoved plugins from wordpress.org\u003C\u002Fli>\n\u003Cli>Shows closure reason, date, and full explanation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Dashboard Widget\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Get an overview of plugin issues directly on your WordPress dashboard. Instantly see which plugins are closed or outdated, helping you prioritize what needs attention.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>This plugin does not collect, store, or transmit any personal data. It only:\u003Cbr \u002F>\n* Queries the public WordPress.org Plugin API for plugin information\u003Cbr \u002F>\n* Stores Fae Herald data locally in your WordPress database\u003Cbr \u002F>\n* Does not track users or send data to external services\u003C\u002Fp>\n","Keep your WordPress site secure by monitoring plugin releases and spotting closed plugins.",300,"2025-12-20T11:33:00.000Z","6.9.5","5.3",[21,22,23,83],"status","https:\u002F\u002Ffmrk.dk\u002Fplugins\u002Ffae-herald\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffae-herald.1.1.0.zip",{"slug":87,"name":88,"version":89,"author":87,"author_profile":90,"description":91,"short_description":92,"active_installs":13,"downloaded":93,"rating":13,"num_ratings":13,"last_updated":94,"tested_up_to":15,"requires_at_least":95,"requires_php":96,"tags":97,"homepage":99,"download_link":100,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"pingvera","Pingvera","0.4.4","https:\u002F\u002Fprofiles.wordpress.org\u002Fpingvera\u002F","\u003Cp>Pingvera is a monitoring service for studios and agencies that maintain many\u003Cbr \u002F>\nclient websites. This plugin is the “level 3” connector: it looks at the site\u003Cbr \u002F>\nfrom the inside and reports the following to your dashboard:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Inventory: WordPress core, PHP and database versions, active theme, plugins and their versions.\u003C\u002Fli>\n\u003Cli>Updates: available core and plugin updates.\u003C\u002Fli>\n\u003Cli>Security: predictable admin login name, debug mode left on, core file integrity (checksums).\u003C\u002Fli>\n\u003Cli>Performance: object cache presence, size of autoloaded options.\u003C\u002Fli>\n\u003Cli>Availability: REST loopback, recent PHP fatal errors (a count only, never the log itself).\u003C\u002Fli>\n\u003Cli>Configuration: WP-Cron mode and task lag; mail\u002FSMTP.\u003C\u002Fli>\n\u003Cli>Commerce: WooCommerce orders (failed-order spikes, order “droughts”), payment gateways, checkout reachability, a daily smoke run.\u003C\u002Fli>\n\u003Cli>Files: write permissions on wp-config.php.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>What the plugin does NOT do: it opens no inbound ports, executes no remote\u003Cbr \u002F>\ncommands, and never transmits passwords, database contents, or visitor\u003Cbr \u002F>\npersonal data. All communication is outbound HTTPS to your own dashboard.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin is the connector for Pingvera, an external website-monitoring\u003Cbr \u002F>\nservice (https:\u002F\u002Fpingvera.com). The plugin exists to send your site’s technical\u003Cbr \u002F>\nhealth to your Pingvera dashboard, so using it requires that service. It talks to\u003Cbr \u002F>\nthe dashboard you configure — a hosted dashboard such as pingvera.com, or your\u003Cbr \u002F>\nown self-hosted\u002Fon-prem instance — over outbound HTTPS only.\u003C\u002Fp>\n\u003Cp>What is sent and when:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Pairing (once, when you click “Connect”): the one-time pairing code and your\u003Cbr \u002F>\nsite URL are sent to obtain a scoped access token. Endpoint: \u002Fcms\u002Fv1\u002Fpair.\u003C\u002Fli>\n\u003Cli>Sync (once an hour via WP-Cron, and on “Sync now”): technical health and\u003Cbr \u002F>\ninventory — WordPress, PHP and database versions; the active theme and the list\u003Cbr \u002F>\nof plugins with their versions; available updates; security, performance and\u003Cbr \u002F>\nconfiguration findings; WooCommerce order statistics and payment gateway \u002F\u003Cbr \u002F>\ncheckout status; and a count of recent PHP fatal errors. Endpoint: \u002Fcms\u002Fv1\u002Fsync.\u003Cbr \u002F>\nPasswords, database contents, post content and visitor personal data are never\u003Cbr \u002F>\nsent.\u003C\u002Fli>\n\u003Cli>Real User Monitoring (only if enabled for your site in the dashboard): a small\u003Cbr \u002F>\nasynchronous script is loaded on the front end to collect anonymous Core Web\u003Cbr \u002F>\nVitals (loading and interaction timings) of your own pages. Endpoint: \u002Frum\u002Fv1\u002F.\u003Cbr \u002F>\nNo personal data is collected.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Service provided by Pingvera:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Terms of Service: https:\u002F\u002Fpingvera.com\u002Fterms.html\u003C\u002Fli>\n\u003Cli>Privacy Policy: https:\u002F\u002Fpingvera.com\u002Fprivacy.html\u003C\u002Fli>\n\u003C\u002Ful>\n","Inside-out WordPress diagnostics for the Pingvera monitoring service. Sends site health to your dashboard over outbound HTTPS only.",43,"2026-07-19T19:20:00.000Z","5.0","7.2",[19,22,52,23,98],"uptime","https:\u002F\u002Fpingvera.com\u002Fblog\u002Fwordpress-health-monitoring-inside.html","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpingvera.0.4.4.zip",{"slug":102,"name":103,"version":104,"author":105,"author_profile":106,"description":107,"short_description":108,"active_installs":13,"downloaded":109,"rating":13,"num_ratings":13,"last_updated":110,"tested_up_to":15,"requires_at_least":111,"requires_php":17,"tags":112,"homepage":114,"download_link":115,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"spm-by-marwan","SPM by Marwan","1.2.7","Marwan Hatem","https:\u002F\u002Fprofiles.wordpress.org\u002Fmarwanhatem\u002F","\u003Cp>SPM by Marwan is a professional-grade diagnostics and intelligence platform designed for WordPress administrators and developers. It provides deep visibility into your WordPress ecosystem, offering real-time monitoring, security auditing, and performance profiling to ensure your site remains fast, secure, and stable.\u003C\u002Fp>\n\u003Ch3>The Problem\u003C\u002Fh3>\n\u003Cp>Managing a modern WordPress ecosystem is inherently complex. Site owners and developers frequently struggle with:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Slow Extensions:\u003C\u002Fstrong> Identifying which specific extension is degrading page load times or consuming excessive server resources.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hidden PHP Errors:\u003C\u002Fstrong> Unseen warnings and fatal errors that silently break functionality or create vulnerabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security Risks:\u003C\u002Fstrong> Unmaintained, abandoned, or vulnerable code exposing the site to potential exploits.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trust Issues:\u003C\u002Fstrong> Uncertainty regarding an extension’s origin, development standards, and code quality.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Update Degradation:\u003C\u002Fstrong> Performance regressions and unexpected conflicts introduced immediately after updates.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Core Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Real-Time Monitoring Engine:\u003C\u002Fstrong> Actively tracks resource consumption, database queries, and execution times for every active extension. Identifies performance bottlenecks as they happen, preventing systemic slowdowns.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Performance Diagnostics:\u003C\u002Fstrong> Deep-dive profiling for individual extensions. Analyzes memory footprint and script execution to provide actionable intelligence on resource utilization.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security & Integrity Scanner:\u003C\u002Fstrong> Proactively audits installed extensions against known vulnerability databases, flags high-risk code patterns, and verifies WordPress core files against official checksums to detect malicious tampering.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Japanese SEO Spam Auto-Fix Engine:\u003C\u002Fstrong> A specialized, deep-scanning engine designed to detect and eradicate the notorious “Japanese Keyword Hack”. Features a one-click Auto-Fix that intelligently restores or quarantines hijacked posts to protect your Google ranking without destroying your original content.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Advanced Security: Defeating the Japanese SEO Keyword Hack\u003C\u002Fh3>\n\u003Cp>The “Japanese Keyword Hack” is a devastating black-hat SEO attack where hackers exploit vulnerabilities in outdated plugins to inject massive amounts of auto-generated Japanese text and malicious links into your database and core files. This causes Google to flag your site as “hacked,” instantly destroying your SEO ranking.\u003C\u002Fp>\n\u003Cp>SPM by Marwan includes a highly specialized engine specifically built to defeat this attack:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Deep Database Scanning:\u003C\u002Fstrong> Actively crawls your \u003Ccode>wp_posts\u003C\u002Fcode> and \u003Ccode>wp_options\u003C\u002Fcode> tables, utilizing advanced Unicode block detection to find injected Japanese Hiragana, Katakana, and Kanji spam hidden within your legitimate content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Intelligent Auto-Fix (No Data Loss):\u003C\u002Fstrong> When you click “Auto-Fix”, the scanner doesn’t just blindly delete your hijacked posts. Instead, it scans the WordPress Revision History for each infected post. It finds the last “clean” version of your post (before the hacker touched it) and seamlessly restores it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Fail-Safe Quarantining:\u003C\u002Fstrong> If a post was created entirely by the hacker (meaning no clean revision exists), or if you have revisions disabled, the engine will safely quarantine the post by setting its status to \u003Cstrong>Draft\u003C\u002Fstrong>. This instantly removes the spam from the public internet—stopping the SEO bleed—while preserving the draft in your admin panel so you don’t lose any data.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Orphaned File Detection:\u003C\u002Fstrong> Scans your entire server structure to locate and quarantine backdoor PHP scripts that hackers leave behind to reinfect your site after you clean it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Core Checksum Verification:\u003C\u002Fstrong> Verifies every single WordPress core file against the official WordPress.org cryptographic checksums to detect hidden cloaking scripts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Trust Verification:\u003C\u002Fstrong> Evaluates code based on developer reputation, update frequency, repository standing, and code integrity. Establishes a trust score to help you make informed decisions about your technology stack.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Historical Analytics:\u003C\u002Fstrong> Maintains a robust ledger of performance and security metrics over time. Visualizes trends to help you understand the long-term impact of specific extensions and updates.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Action Layer (Scan \u002F Safe Mode \u002F Reporting):\u003C\u002Fstrong> Provides immediate remediation tools. Execute targeted scans, isolate problematic extensions using Safe Mode, and generate comprehensive diagnostics reports.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin utilizes the WordPress.org Plugins API (https:\u002F\u002Fapi.wordpress.org) to verify plugin licenses and retrieve information about installed plugins.\u003Cbr \u002F>\n* \u003Cstrong>What data is sent:\u003C\u002Fstrong> The names and slugs of your active plugins are sent in the API request.\u003Cbr \u002F>\n* \u003Cstrong>When it is sent:\u003C\u002Fstrong> Data is sent when the plugin performs a scheduled background scan or when you manually click “Deep Scan” or “Refresh Now” on the dashboard.\u003Cbr \u002F>\n* \u003Cstrong>Why it is used:\u003C\u002Fstrong> To verify that the plugins running on your site are authentic, properly licensed, and available on the official WordPress.org directory, which enhances your site’s security and trust metrics.\u003C\u002Fp>\n\u003Cp>For more information, please refer to the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fabout\u002Fprivacy\u002F\" rel=\"ugc\">WordPress.org Privacy Policy\u003C\u002Fa>.\u003C\u002Fp>\n","Tracks load time and PHP errors for each active extension, storing logs in a custom database table.",322,"2026-06-06T19:28:00.000Z","5.6",[19,22,52,113,23],"profiler","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fspm-by-marwan.1.2.7.zip",{"error":117,"url":118,"statusCode":119,"statusMessage":120,"message":120},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fnpc-maintenance-inspector\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":122,"versions":123},2,[124,130],{"version":6,"download_url":25,"svn_tag_url":125,"released_at":27,"has_diff":126,"diff_files_changed":127,"diff_lines":27,"trac_diff_url":128,"vulnerabilities":129,"is_current":117},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fnpc-maintenance-inspector\u002Ftags\u002F1.0.1\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fnpc-maintenance-inspector%2Ftags%2F1.0.0&new_path=%2Fnpc-maintenance-inspector%2Ftags%2F1.0.1",[],{"version":58,"download_url":131,"svn_tag_url":132,"released_at":27,"has_diff":126,"diff_files_changed":133,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":134,"is_current":126},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnpc-maintenance-inspector.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fnpc-maintenance-inspector\u002Ftags\u002F1.0.0\u002F",[],[]]