[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feKXjMJOT3lbedpR8fbHA3gyCDhe7MStMG1aFPW7MHbw":3,"$fORKl36t7Yp52acau1hh1EohvljFoUtHsDLS4Bra9PKo":127,"$fQFIEfEwgmbmV3HDNuoNIAi7zfbdwEeH1bP7mkC7JIwA":132},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":39,"analysis":27,"fingerprints":27},"sticklight","Sticklight","1.1.0","Elementor","https:\u002F\u002Fprofiles.wordpress.org\u002Felemntor\u002F","\u003Cp>Sticklight Connector provides a structured way to use the WordPress user system in external or React-based applications.\u003C\u002Fp>\n\u003Cp>The plugin extends the WordPress REST API with additional endpoints that allow authenticated clients to retrieve user context and interact with WordPress data, while fully respecting core authentication methods, roles, and capability checks.\u003C\u002Fp>\n\u003Cp>Sticklight does not replace WordPress authentication. It relies on \u003Ccode>wp_authenticate\u003C\u002Fcode> for credential validation and WordPress Application Passwords for API access, and follows standard permission checks (\u003Ccode>current_user_can\u003C\u002Fcode>) for all requests.\u003C\u002Fp>\n\u003Ch4>Typical use cases\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>React applications connected to a WordPress site\u003C\u002Fli>\n\u003Cli>Headless or hybrid WordPress setups\u003C\u002Fli>\n\u003Cli>Admin or user dashboards built outside wp-admin\u003C\u002Fli>\n\u003Cli>External tools that require authenticated access to WordPress data\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Authenticates via \u003Ccode>wp_authenticate\u003C\u002Fcode> and issues Application Passwords for API access\u003C\u002Fli>\n\u003Cli>Adds REST endpoints for login, logout, and retrieving current user context\u003C\u002Fli>\n\u003Cli>Enforces WordPress capability checks on all requests\u003C\u002Fli>\n\u003Cli>Supports cross-origin headless setups\u003C\u002Fli>\n\u003Cli>Extensible via WordPress hooks and filters\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Ch4>Login\u003C\u002Fh4>\n\u003Cp>Authenticate with username (or email) and password:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>POST \u002Fwp-json\u002Fsticklight\u002Fv1\u002Fauth\u002Flogin\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>On success the response includes an Application Password for subsequent API requests and the authenticated user:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>{\n  \"app_password\": \"XXXX XXXX XXXX XXXX XXXX XXXX\",\n  \"user\": {\n    \"user_id\": 1,\n    \"username\": \"admin\",\n    \"display_name\": \"Admin\",\n    \"email\": \"admin@example.com\",\n    \"roles\": [\"administrator\"]\n  }\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Use the returned \u003Ccode>app_password\u003C\u002Fcode> with HTTP Basic Authentication for all further requests.\u003C\u002Fp>\n\u003Ch4>Current user\u003C\u002Fh4>\n\u003Cp>Retrieve the current authenticated user:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>GET \u002Fwp-json\u002Fsticklight\u002Fv1\u002Fauth\u002Fme\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>Logout\u003C\u002Fh4>\n\u003Cp>Revoke the current Application Password session:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>POST \u002Fwp-json\u002Fsticklight\u002Fv1\u002Fauth\u002Flogout\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch4>User registration\u003C\u002Fh4>\n\u003Cp>User creation is handled through the built-in WordPress REST API (\u003Ccode>POST \u002Fwp-json\u002Fwp\u002Fv2\u002Fusers\u003C\u002Fcode>) and requires administrator authentication.\u003C\u002Fp>\n\u003Ch4>Accessing protected data\u003C\u002Fh4>\n\u003Cp>Requests to any endpoint must pass standard WordPress permission checks. Sticklight does not bypass or override these checks.\u003C\u002Fp>\n\u003Ch3>Security\u003C\u002Fh3>\n\u003Cp>Sticklight follows WordPress security practices:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Authenticates via \u003Ccode>wp_authenticate\u003C\u002Fcode>, which respects all security plugin hooks (rate limiting, two-factor authentication, brute-force protection)\u003C\u002Fli>\n\u003Cli>Issues Application Passwords scoped to individual sessions\u003C\u002Fli>\n\u003Cli>Does not provide user registration — accounts must be created by an administrator\u003C\u002Fli>\n\u003Cli>Applies capability checks (\u003Ccode>current_user_can\u003C\u002Fcode>) on all endpoints\u003C\u002Fli>\n\u003Cli>Does not expose private data without proper permissions\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For external applications, it is recommended to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Use HTTPS\u003C\u002Fli>\n\u003Cli>Restrict allowed origins\u003C\u002Fli>\n\u003Cli>Avoid exposing sensitive endpoints unnecessarily\u003C\u002Fli>\n\u003C\u002Ful>\n","Use WordPress authentication and permissions in external React applications via secure REST API endpoints.",200,685,0,"2026-06-03T08:07:00.000Z","7.0.2","6.8","7.4",[19,20,21,22,23],"api","authentication","headless","react","rest-api","https:\u002F\u002Fsticklight.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsticklight.1.1.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":34,"avg_security_score":35,"avg_patch_time_days":36,"trust_score":37,"computed_at":38},"elemntor",17,13364200,95,616,76,"2026-08-28T17:41:41.399Z",[40,62,81,96,112],{"slug":41,"name":42,"version":43,"author":44,"author_profile":45,"description":46,"short_description":47,"active_installs":48,"downloaded":49,"rating":50,"num_ratings":51,"last_updated":52,"tested_up_to":15,"requires_at_least":53,"requires_php":17,"tags":54,"homepage":57,"download_link":58,"security_score":59,"vuln_count":60,"unpatched_count":13,"last_vuln_date":61,"fetched_at":28},"wp-graphql","WPGraphQL","2.17.0","Jason Bahl","https:\u002F\u002Fprofiles.wordpress.org\u002Fjasonbahl\u002F","\u003Cp>WPGraphQL is a free, open-source WordPress plugin that provides an extendable GraphQL schema and API for any WordPress site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Get Started\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Install WPGraphQL: \u003Ccode>wp plugin install wp-graphql --activate\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Try it out: \u003Ca href=\"https:\u002F\u002Frepl.wpgraphql.com\" rel=\"nofollow ugc\">Live Demo\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Read the \u003Ca href=\"https:\u002F\u002Fwpgraphql.com\u002Fdocs\u002Fquick-start\" rel=\"nofollow ugc\">Quick Start Guide\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Join the \u003Ca href=\"https:\u002F\u002Fdiscord.gg\u002FAGVBqqyaUY\" rel=\"nofollow ugc\">Community on Discord\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-graphql\u002Fwp-graphql\" rel=\"nofollow ugc\">Star the Repo\u003C\u002Fa>!\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Key Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Flexible API\u003C\u002Fstrong>: Query posts, pages, custom post types, taxonomies, users, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Extendable Schema\u003C\u002Fstrong>: Easily add functionality with WPGraphQL’s API, enabling custom integrations.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compatible with Modern Frameworks\u003C\u002Fstrong>: Works seamlessly with \u003Ca href=\"https:\u002F\u002Fvercel.com\u002Fguides\u002Fwordpress-with-vercel\" rel=\"nofollow ugc\">Next.js\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fdocs.astro.build\u002Fen\u002Fguides\u002Fcms\u002Fwordpress\u002F\" rel=\"nofollow ugc\">Astro\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwww.okupter.com\u002Fblog\u002Fheadless-wordpress-graphql-sveltekit\" rel=\"nofollow ugc\">SvelteKit\u003C\u002Fa>, and more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Optimized Performance\u003C\u002Fstrong>: Fetch exactly the data you need in a single query. Boost performance with \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-graphql\u002Fwp-graphql\u002Ftree\u002Fmain\u002Fplugins\u002Fwp-graphql-smart-cache\" rel=\"nofollow ugc\">WPGraphQL Smart Cache\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>WPGraphQL is becoming a \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fnews\u002F2024\u002F10\u002Fwpgraphql\u002F\" rel=\"ugc\">Canonical Plugin\u003C\u002Fa> on WordPress.org, ensuring long-term support and a growing community of users and contributors.\u003C\u002Fp>\n\u003Ch4>Upgrading\u003C\u002Fh4>\n\u003Cp>It is recommended that anytime you want to update WPGraphQL that you get familiar with what’s changed in the release.\u003C\u002Fp>\n\u003Cp>WPGraphQL publishes \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fwp-graphql\u002Fwp-graphql\u002Freleases\" rel=\"nofollow ugc\">release notes on Github\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>WPGraphQL has been following Semver practices for a few years. We will continue to follow Semver and let version numbers communicate meaning. The summary of Semver versioning is as follows:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cem>MAJOR\u003C\u002Fem> version when you make incompatible API changes,\u003C\u002Fli>\n\u003Cli>\u003Cem>MINOR\u003C\u002Fem> version when you add functionality in a backwards compatible manner, and\u003C\u002Fli>\n\u003Cli>\u003Cem>PATCH\u003C\u002Fem> version when you make backwards compatible bug fixes.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>You can read more about the details of Semver at semver.org\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>WPGraphQL uses \u003Ca href=\"https:\u002F\u002Fappsero.com\" rel=\"nofollow ugc\">Appsero\u003C\u002Fa> SDK to collect some telemetry data upon user’s confirmation. This helps us to troubleshoot problems faster and make product improvements.\u003C\u002Fp>\n\u003Cp>Appsero SDK \u003Cstrong>does not gather any data by default.\u003C\u002Fstrong> The SDK starts gathering basic telemetry data \u003Cstrong>only when a user allows it via the admin notice\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>When you opt in, each telemetry request is sent to Appsero and a duplicate is sent in a non-blocking request to WPGraphQL-operated infrastructure at https:\u002F\u002Ftelemetry.wpgraphql.com (the same categories of data as described for Appsero below).\u003C\u002Fp>\n\u003Cp>Learn more about how \u003Ca href=\"https:\u002F\u002Fappsero.com\u002Fprivacy-policy\u002F\" rel=\"nofollow ugc\">Appsero collects and uses this data\u003C\u002Fa>.\u003C\u002Fp>\n","WPGraphQL adds a flexible and powerful GraphQL API to WordPress, enabling efficient querying and interaction with your site's data.",30000,1570697,98,48,"2026-06-24T22:21:00.000Z","6.0",[55,56,21,22,23],"decoupled","graphql","https:\u002F\u002Fgithub.com\u002Fwp-graphql\u002Fwp-graphql","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-graphql.2.17.0.zip",80,9,"2026-05-07 00:00:00",{"slug":63,"name":64,"version":65,"author":66,"author_profile":67,"description":68,"short_description":69,"active_installs":70,"downloaded":71,"rating":26,"num_ratings":72,"last_updated":73,"tested_up_to":74,"requires_at_least":75,"requires_php":17,"tags":76,"homepage":79,"download_link":80,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"headless-rest-api-security","Headless REST API Security","2.2","Md. Rakib Ullah","https:\u002F\u002Fprofiles.wordpress.org\u002Frakib417\u002F","\u003Cp>Running a Headless WordPress site often involves exposing the REST API. Headless REST API Security provides tools for administrators to control which endpoints are accessible to the public or external applications.\u003C\u002Fp>\n\u003Cp>This plugin restricts public access to REST API endpoints by default and offers a settings interface to allow-list only the specific routes required by a frontend application (such as Next.js, Gatsby, or mobile apps).\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Access Control:\u003C\u002Fstrong> Restrict default public access to REST API endpoints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Route Allow-Listing:\u003C\u002Fstrong> Specific API routes (e.g., \u003Ccode>\u002Fwp\u002Fv2\u002Fposts\u003C\u002Fcode>) can be enabled while others remain restricted.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>API Key Authentication:\u003C\u002Fstrong> Supports an \u003Ccode>X-API-KEY\u003C\u002Fcode> header for server-to-server or frontend requests.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Headless Redirect:\u003C\u002Fstrong> Option to redirect users accessing the backend API URL to a specified frontend domain.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Access:\u003C\u002Fstrong> Logged-in Administrators and Editors retain access to the API to support the Block Editor (Gutenberg) functionality.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugin Support:\u003C\u002Fstrong> Detects routes registered by third-party plugins for configuration.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Navigate to \u003Cstrong>Settings > Headless Security\u003C\u002Fstrong> in the WordPress dashboard.\u003C\u002Fli>\n\u003Cli>Enable the \u003Cstrong>Master Switch\u003C\u002Fstrong> to activate the access restrictions.\u003C\u002Fli>\n\u003Cli>Review the list of REST API routes and check the \u003Cstrong>Allow\u003C\u002Fstrong> box for endpoints the application requires.\u003C\u002Fli>\n\u003Cli>Copy the generated \u003Cstrong>API Key\u003C\u002Fstrong> for use in application headers.\u003C\u002Fli>\n\u003Cli>(Optional) Enter a \u003Cstrong>Headless Frontend URL\u003C\u002Fstrong> to configure redirects for visitors.\u003C\u002Fli>\n\u003C\u002Fol>\n","Manage access to the WordPress REST API by restricting public endpoints, enabling specific route allow-listing, and handling API key authentication.",30,929,2,"2026-02-22T18:49:00.000Z","6.9.5","5.8",[77,20,21,78,23],"access-control","permissions","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fheadless-rest-api-security\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fheadless-rest-api-security.2.3.zip",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":70,"downloaded":89,"rating":13,"num_ratings":13,"last_updated":90,"tested_up_to":15,"requires_at_least":75,"requires_php":17,"tags":91,"homepage":94,"download_link":95,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"overedge-connector","Overedge Connector","1.3.0","timothyolu","https:\u002F\u002Fprofiles.wordpress.org\u002Ftimothyolu\u002F","\u003Cp>\u003Cstrong>Overedge Connector\u003C\u002Fstrong> is the bridge between your WordPress content and your React frontend.\u003C\u002Fp>\n\u003Cp>Whether you built your site with Lovable, Vite, Next.js, or plain React — Overedge Connector turns your WordPress installation into a fully configured headless CMS that your React app can fetch from instantly.\u003C\u002Fp>\n\u003Ch4>External Services\u003C\u002Fh4>\n\u003Cp>This plugin optionally connects to the Overedge platform (https:\u002F\u002Foveredge.dev) to automate the connection setup between your React frontend and WordPress. This connection is initiated manually by the site administrator and can be used without the platform entirely.\u003C\u002Fp>\n\u003Cp>The Overedge platform stores only site URLs and plugin health status. No content or personal data is transmitted.\u003C\u002Fp>\n\u003Cp>Privacy policy: https:\u002F\u002Foveredge.dev\u002Fprivacy\u003Cbr \u002F>\nTerms of service: https:\u002F\u002Foveredge.dev\u003C\u002Fp>\n\u003Ch4>What It Does\u003C\u002Fh4>\n\u003Cp>Once activated, Overedge Connector automatically:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Registers \u003Cstrong>custom post types\u003C\u002Fstrong> — Testimonials, Team Members, and FAQs — all exposed via the REST API\u003C\u002Fli>\n\u003Cli>Configures \u003Cstrong>Advanced Custom Fields\u003C\u002Fstrong> field groups for each post type\u003C\u002Fli>\n\u003Cli>Enables and configures the \u003Cstrong>WordPress REST API\u003C\u002Fstrong> for headless use\u003C\u002Fli>\n\u003Cli>Handles \u003Cstrong>CORS headers\u003C\u002Fstrong> so your React frontend can fetch content cross-origin\u003C\u002Fli>\n\u003Cli>Creates a \u003Cstrong>site-wide options panel\u003C\u002Fstrong> for managing global settings (hero text, stats, CTAs, contact details)\u003C\u002Fli>\n\u003Cli>Exposes a \u003Cstrong>health endpoint\u003C\u002Fstrong> at \u003Ccode>\u002Fwp-json\u002Foveredge\u002Fv1\u002Fhealth\u003C\u002Fcode> so your frontend can monitor the connection\u003C\u002Fli>\n\u003Cli>Generates a \u003Cstrong>secret key\u003C\u002Fstrong> for secure webhook verification\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Is It For?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Vibe coders\u003C\u002Fstrong> building client sites on Lovable who need their clients to manage content independently\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Freelance developers\u003C\u002Fstrong> tired of rewriting WordPress REST API integrations on every project\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agencies\u003C\u002Fstrong> delivering consistent, client-friendly handovers at scale\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Works With Any React Frontend\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Lovable subdomain (e.g. yoursite.lovable.app)\u003C\u002Fli>\n\u003Cli>Custom domain (e.g. yoursite.com)\u003C\u002Fli>\n\u003Cli>Next.js, Vite, Create React App — anything React\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Works With Any WordPress Setup\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Subdomain (e.g. cms.yoursite.com)\u003C\u002Fli>\n\u003Cli>Main domain (e.g. yoursite.com)\u003C\u002Fli>\n\u003Cli>Subfolder (e.g. yoursite.com\u002Fcms)\u003C\u002Fli>\n\u003Cli>Shared hosting, VPS, managed WordPress — all supported\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Overedge Platform\u003C\u002Fh4>\n\u003Cp>This plugin works standalone, but connects seamlessly with the \u003Cstrong>Overedge platform\u003C\u002Fstrong> (overedge.dev) which provides:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Browser-based connection wizard — no terminal, no VS Code\u003C\u002Fli>\n\u003Cli>Auto-generated React integration files (wordpress.ts, useWordPress.ts, cmsData.ts)\u003C\u002Fli>\n\u003Cli>Dashboard to manage all connected sites\u003C\u002Fli>\n\u003Cli>Health monitoring across all your client sites\u003C\u002Fli>\n\u003Cli>Phase 2: Visual customisation — clients control colours, layout, and components from wp-admin\u003C\u002Fli>\n\u003Cli>Phase 2: Shortcode \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> React props mapping — \u003Ccode>[overedge_hero headline=\"...\"]\u003C\u002Fcode> updates your React component automatically\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>REST API Endpoints Added\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>GET \u002Fwp-json\u002Foveredge\u002Fv1\u002Fhealth\u003C\u002Fcode> — Plugin health and site status\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fwp-json\u002Foveredge\u002Fv1\u002Fconfigure\u003C\u002Fcode> — Update CORS allowed origin\u003C\u002Fli>\n\u003Cli>\u003Ccode>GET \u002Fwp-json\u002Foveredge\u002Fv1\u002Fsettings\u003C\u002Fcode> — Site-wide CMS settings\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Custom Post Types Registered\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>overedge_testimonial\u003C\u002Fcode> — with fields: quote, author_name, author_country, destination, avatar\u003C\u002Fli>\n\u003Cli>\u003Ccode>overedge_team_member\u003C\u002Fcode> — with fields: full_name, job_title, bio, photo, destination_focus, linkedin_url\u003C\u002Fli>\n\u003Cli>\u003Ccode>overedge_faqs\u003C\u002Fcode> — with fields: answer, destination, order\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>All custom post types are exposed via the WordPress REST API and include ACF field support.\u003C\u002Fp>\n\u003Ch4>Privacy\u003C\u002Fh4>\n\u003Cp>This plugin does not collect or transmit any personal data. The optional Overedge platform connection only stores site URLs and connection status — never content or user data.\u003C\u002Fp>\n","Connect your WordPress site to any React or Lovable-built frontend as a headless CMS — in minutes.",529,"2026-06-12T06:21:00.000Z",[21,92,22,23,93],"lovable","vite","https:\u002F\u002Foveredge.dev\u002Fconnector","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Foveredge-connector.1.3.0.zip",{"slug":97,"name":98,"version":99,"author":100,"author_profile":101,"description":102,"short_description":103,"active_installs":13,"downloaded":104,"rating":13,"num_ratings":13,"last_updated":105,"tested_up_to":15,"requires_at_least":53,"requires_php":106,"tags":107,"homepage":110,"download_link":111,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"dk-headless-api","DK Headless API","1.0.1","digitized kosmos","https:\u002F\u002Fprofiles.wordpress.org\u002Fdigitizedkosmos\u002F","\u003Cp>DK API transforms WordPress into a clean, controlled API backend by disabling the frontend theme layer entirely, selectively removing default WP REST API routes, and registering a clean, versioned custom REST namespace.\u003C\u002Fp>\n\u003Ch4>Core Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Fully disables the WordPress frontend.\u003C\u002Fli>\n\u003Cli>Preserves Gutenberg compatibility while removing unnecessary endpoints.\u003C\u002Fli>\n\u003Cli>Exposes clean endpoints for Posts, Pages, Categories, Taxonomies, and Menus.\u003C\u002Fli>\n\u003Cli>Built-in structured block parsing for WordPress 7.0 readiness.\u003C\u002Fli>\n\u003Cli>Resolves Advanced Custom Fields (ACF) natively in API responses.\u003C\u002Fli>\n\u003C\u002Ful>\n","Turns WordPress into a controlled Headless CMS with custom REST routes, rate limiting, and caching.",108,"2026-06-30T19:48:00.000Z","8.0",[108,21,109,22,23],"cms","nextjs","https:\u002F\u002Fdigitizedkosmos.com\u002Fproducts\u002Fdk-headless-api","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdk-headless-api.1.0.1.zip",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":13,"downloaded":120,"rating":13,"num_ratings":13,"last_updated":121,"tested_up_to":15,"requires_at_least":122,"requires_php":123,"tags":124,"homepage":125,"download_link":126,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"gallop","Gallop","0.1.1","gallopsoftware","https:\u002F\u002Fprofiles.wordpress.org\u002Fgallopsoftware\u002F","\u003Cp>Gallop is the headless WordPress REST API for Next.js that’s FAST and SIMPLE. Keep the WordPress you write in, lose the theme that slows you down — and ship your whole page from one request.\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>The WordPress editing experience your team already knows, with the speed of a fully decoupled Next.js front end. One endpoint, one response, done.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgallop.software\u002Fheadless-wordpress\" rel=\"nofollow ugc\">Visit the Gallop homepage & documentation \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Most headless setups make you stitch together a waterfall of core WordPress REST calls per page — \u003Ccode>\u002Fwp\u002Fv2\u002Fposts\u003C\u002Fcode>, \u003Ccode>\u002Fwp\u002Fv2\u002Fmedia\u003C\u002Fcode>, meta, and taxonomy — then bolt on a JWT layer and an auth service just to log a user in. Gallop replaces all of that.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>One request. The whole page.\u003C\u002Fstrong> Hand Gallop a URI and it returns the post body, an SEO block, and your global site data — already joined, already resolved, ready to render. \u003Cstrong>The API is the point:\u003C\u002Fstrong> a dedicated, Next.js-shaped REST namespace (\u003Ccode>\u002Fwp-json\u002Fgallop\u002Fv1\u003C\u002Fcode>) so your front-end code stays simple — one fetch, one response, ready to render.\u003C\u002Fp>\n\u003Ch4>Why choose Gallop?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>One round trip instead of five.\u003C\u002Fstrong> Everything a page needs — \u003Ccode>post\u003C\u002Fcode>, \u003Ccode>seo\u003C\u002Fcode>, and \u003Ccode>site\u003C\u002Fcode> — in a single response.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No JWT, no API keys, no separate auth service.\u003C\u002Fstrong> Cookie-based login is built in and wired to WordPress’s own \u003Ccode>wp_signon()\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SEO done for you.\u003C\u002Fstrong> With Yoast active, the \u003Ccode>seo\u003C\u002Fcode> block ships search-ready out of the box.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No-code custom post types.\u003C\u002Fstrong> Register REST-enabled CPTs from the admin — no \u003Ccode>register_post_type()\u003C\u002Fcode> boilerplate.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Instant publishing.\u003C\u002Fstrong> Publish in WordPress and Gallop revalidates the affected Next.js routes automatically — no full redeploy.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Framework-agnostic JSON.\u003C\u002Fstrong> Next.js is the reference target, but any HTTP client can consume the API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Keep your workflow.\u003C\u002Fstrong> Your editors keep the exact WordPress publishing experience they already rely on.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Everything a page needs, in one request\u003C\u002Fh4>\n\u003Cp>Hand Gallop a URI and it returns the whole page in a single response: the full \u003Ccode>post\u003C\u002Fcode>, its \u003Ccode>seo\u003C\u002Fcode> metadata, and your global \u003Ccode>site\u003C\u002Fcode> data, already joined, already resolved, ready to render. \u003Ccode>GET|POST \u002Fgallop\u002Fv1\u002Fpost\u003C\u002Fcode> handles posts and pages, and \u003Ccode>POST \u002Fgallop\u002Fv1\u002Fcategory\u003C\u002Fcode> does the same for taxonomy archives. No waterfall of \u003Ccode>\u002Fwp\u002Fv2\u002Fposts\u003C\u002Fcode>, \u003Ccode>\u002Fwp\u002Fv2\u002Fmedia\u003C\u002Fcode>, meta, and taxonomy calls per page — one round trip instead of five, with no JWT, API keys, or complicated authentication to set up. Your front end stays simple, and your pages load fast.\u003C\u002Fp>\n\u003Cp>The SEO is done for you. With Yoast active, the \u003Ccode>seo\u003C\u002Fcode> block is populated straight from Yoast’s indexables (canonical, meta description, OpenGraph, robots flags, reading time) so every page ships search-ready out of the box. Without Yoast, \u003Ccode>seo\u003C\u002Fcode> comes back as an empty object instead of disappearing, so your front end can check it and fall back to its own defaults.\u003C\u002Fp>\n\u003Ch4>Login, editing, and cache revalidation, already wired up\u003C\u002Fh4>\n\u003Cp>\u003Ciframe loading=\"lazy\" title=\"winx-edit\" src=\"https:\u002F\u002Fplayer.vimeo.com\u002Fvideo\u002F1200535505?dnt=1&app_id=122963\" width=\"750\" height=\"374\" frameborder=\"0\" allow=\"autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\">\u003C\u002Fiframe>\u003C\u002Fp>\n\u003Cp>Moving off a WordPress template usually means rebuilding everything it gave you for free. Gallop ships with it already done. Cookie-based login is wired into the front end through the Gallop plugin, so editors sign in on your Next.js site with their normal WordPress credentials — no JWT layer, no separate auth service to stand up, and no API keys to manage.\u003C\u002Fp>\n\u003Cp>Editing works the way your team already knows. Publish or update a post or page in WordPress and Gallop tells your Next.js site to revalidate the affected routes and clear their cache, so changes and new posts go live instantly with no full redeploy. Login, editing, and cache invalidation are all baked in, so you keep the WordPress workflow your team relies on and still ship a fast Next.js front end.\u003C\u002Fp>\n\u003Ch4>Settings and custom post types, configured from WordPress\u003C\u002Fh4>\n\u003Cp>\u003Ciframe loading=\"lazy\" title=\"GallopWP-v2\" src=\"https:\u002F\u002Fplayer.vimeo.com\u002Fvideo\u002F1196416170?dnt=1&app_id=122963\" width=\"750\" height=\"432\" frameborder=\"0\" allow=\"autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\">\u003C\u002Fiframe>\u003C\u002Fp>\n\u003Cp>Point Gallop at your Next.js production URL and it 301-redirects public WordPress front-end requests to the matching path on your headless host. Admin, REST API, and previews are left untouched.\u003C\u002Fp>\n\u003Cp>Register REST-enabled custom post types from the Post Types tab and they’re immediately available through the Gallop namespace — no \u003Ccode>register_post_type()\u003C\u002Fcode> boilerplate, no developer round trip. Core post types are left alone, and content you create survives a deactivate\u002Funinstall.\u003C\u002Fp>\n\u003Ch4>Trusted on real production sites\u003C\u002Fh4>\n\u003Cp>Gallop isn’t a proof of concept — it powers live production sites today:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>douglasnewby.com\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>cmwelectric.com\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>winx.gallop.software\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Every one edits in WordPress and ships a fast Next.js front end — headless content, real Google rankings and structured data, no theme holding it back, and the same WordPress publishing experience your team already knows.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgallop.software\u002Fheadless-wordpress\" rel=\"nofollow ugc\">See how Gallop powers headless WordPress \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>REST endpoints\u003C\u002Fh4>\n\u003Cp>All endpoints live under the \u003Ccode>gallop\u002Fv1\u003C\u002Fcode> namespace.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>GET|POST \u002Fgallop\u002Fv1\u002Fpost\u003C\u002Fcode> — Resolve a front-end URI to a post and return \u003Ccode>post\u003C\u002Fcode>, \u003Ccode>seo\u003C\u002Fcode>, and \u003Ccode>site\u003C\u002Fcode> payloads. Accepts \u003Ccode>uri\u003C\u002Fcode> as a parameter.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fgallop\u002Fv1\u002Fcategory\u003C\u002Fcode> — Resolve a category URI to a term and return \u003Ccode>category\u003C\u002Fcode>, \u003Ccode>seo\u003C\u002Fcode>, and \u003Ccode>site\u003C\u002Fcode> payloads.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fgallop\u002Fv1\u002Fauth\u002Flogin\u003C\u002Fcode> — Cookie-based login for a headless front end. Accepts \u003Ccode>username\u003C\u002Fcode>, \u003Ccode>password\u003C\u002Fcode>, and optional \u003Ccode>remember\u003C\u002Fcode>. Rate-limited per username\u002FIP.\u003C\u002Fli>\n\u003Cli>\u003Ccode>POST \u002Fgallop\u002Fv1\u002Fauth\u002Flogout\u003C\u002Fcode> — Log out the current user.\u003C\u002Fli>\n\u003Cli>\u003Ccode>GET  \u002Fgallop\u002Fv1\u002Fauth\u002Fsession\u003C\u002Fcode> — Return the current user payload, or \u003Ccode>{ \"user\": null }\u003C\u002Fcode> when not logged in.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Login support\u003C\u002Fh4>\n\u003Cp>Gallop ships with everything a Next.js site needs to authenticate users against WordPress — no extra plugin, no JWT layer to wire up:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Cookie-based login\u003C\u002Fstrong> via \u003Ccode>POST \u002Fgallop\u002Fv1\u002Fauth\u002Flogin\u003C\u002Fcode>, which calls WordPress’s built-in \u003Ccode>wp_signon()\u003C\u002Fcode> and sets the standard auth cookies. A Next.js front end on the same registered domain can then make authenticated requests with credentials included.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Session checks\u003C\u002Fstrong> via \u003Ccode>GET \u002Fgallop\u002Fv1\u002Fauth\u002Fsession\u003C\u002Fcode>, so your front end can tell whether a visitor is logged in and render accordingly.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Logout\u003C\u002Fstrong> via \u003Ccode>POST \u002Fgallop\u002Fv1\u002Fauth\u002Flogout\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Brute-force protection\u003C\u002Fstrong> out of the box: five failed attempts per username + client IP within fifteen minutes return HTTP 429 until the window expires, with optional reverse-proxy IP awareness for sites behind Cloudflare or a load balancer.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SEO integration\u003C\u002Fh4>\n\u003Cp>When the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwordpress-seo\u002F\" rel=\"ugc\">Yoast SEO\u003C\u002Fa> plugin is active, the \u003Ccode>seo\u003C\u002Fcode> block in the post and category responses is populated from Yoast’s indexable data (canonical, meta description, OpenGraph fields, robots flags, reading time, etc.). Without Yoast, \u003Ccode>seo\u003C\u002Fcode> is returned as an empty object so clients can branch safely.\u003C\u002Fp>\n\u003Ch4>Action hooks\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>gallop_auth_login_success\u003C\u002Fcode> — fires after a successful REST login. Args: \u003Ccode>WP_User $user\u003C\u002Fcode>, \u003Ccode>WP_REST_Request $request\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Ccode>gallop_auth_login_failed\u003C\u002Fcode> — fires after a failed REST login. Args: \u003Ccode>string $username\u003C\u002Fcode>, \u003Ccode>WP_REST_Request $request\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Ccode>gallop_auth_logout\u003C\u002Fcode> — fires after a REST logout. Args: \u003Ccode>WP_User $user\u003C\u002Fcode>, \u003Ccode>WP_REST_Request $request\u003C\u002Fcode>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Filter hooks\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>gallop_trust_forwarded_ip\u003C\u002Fcode> — filter the boolean controlling whether reverse-proxy IP headers (\u003Ccode>CF-Connecting-IP\u003C\u002Fcode>, \u003Ccode>X-Forwarded-For\u003C\u002Fcode>) are trusted when rate-limiting REST auth. Defaults to the “Trust proxy IP headers” setting. Only enable behind a trusted proxy that overwrites these headers, otherwise the per-IP rate limit can be bypassed by spoofing them.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Data stored\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ccode>gallop_post_types\u003C\u002Fcode> (option) — your custom post type definitions.\u003C\u002Fli>\n\u003Cli>\u003Ccode>gallop_nextjs_production_url\u003C\u002Fcode> (option) — the redirect target, if configured.\u003C\u002Fli>\n\u003Cli>\u003Ccode>gallop_trust_forwarded_ip\u003C\u002Fcode> (option) — whether to trust reverse-proxy IP headers when rate-limiting auth (default off).\u003C\u002Fli>\n\u003Cli>\u003Ccode>gallop_auth_*\u003C\u002Fcode> (transients) — short-lived login rate-limit counters.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy\u003C\u002Fh3>\n\u003Cp>Gallop does not send any data to external services. All data stays on your WordPress site.\u003C\u002Fp>\n\u003Cp>The \u003Ccode>\u002Fgallop\u002Fv1\u002Fauth\u002Flogin\u003C\u002Fcode> endpoint authenticates users with WordPress’s built-in \u003Ccode>wp_signon()\u003C\u002Fcode> and sets the standard WordPress auth cookies. To mitigate brute-force attacks, Gallop temporarily stores failed-login counters in WordPress transients keyed by username and by the requesting IP address. These counters expire automatically (typically within 15 minutes) and are removed on plugin uninstall.\u003C\u002Fp>\n\u003Cp>No personal data is shared with third parties. No tracking, analytics, or telemetry is performed.\u003C\u002Fp>\n","A REST API for headless Next.js sites: a page's post, SEO, and site data in one request, plus cookie login for authenticated front ends.",88,"2026-06-22T20:09:00.000Z","6.4","8.1",[20,55,21,109,23],"https:\u002F\u002Fgallop.software\u002Fheadless-wordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgallop.0.1.1.zip",{"error":128,"url":129,"statusCode":130,"statusMessage":131,"message":131},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fsticklight\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":72,"versions":133},[134,140],{"version":6,"download_url":25,"svn_tag_url":135,"released_at":27,"has_diff":136,"diff_files_changed":137,"diff_lines":27,"trac_diff_url":138,"vulnerabilities":139,"is_current":128},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsticklight\u002Ftags\u002F1.1.0\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsticklight%2Ftags%2F1.0.0&new_path=%2Fsticklight%2Ftags%2F1.1.0",[],{"version":141,"download_url":142,"svn_tag_url":143,"released_at":27,"has_diff":136,"diff_files_changed":144,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":145,"is_current":136},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsticklight.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsticklight\u002Ftags\u002F1.0.0\u002F",[],[]]