{"id":329370,"date":"2026-06-26T08:27:17","date_gmt":"2026-06-26T08:27:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/unifyca-audit-connector\/"},"modified":"2026-09-21T16:13:13","modified_gmt":"2026-09-21T16:13:13","slug":"unifyca-audit-connector","status":"publish","type":"plugin","link":"https:\/\/pl.wordpress.org\/plugins\/unifyca-audit-connector\/","author":23507462,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.9","stable_tag":"2.0.9","tested":"7.0.5","requires":"5.8","requires_php":"7.1","requires_plugins":null,"header_name":"Unifyca Audit Connector","header_author":"Unifyca","header_description":"Connects your WordPress site to Unifyca for security and system auditing.","assets_banners_color":"fbfbfd","last_updated":"2026-09-21 16:13:13","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/unifyca.com","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":205,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.0.4":{"tag":"2.0.4","author":"unifyca","date":"2026-06-26 08:27:22","revision":3586949},"2.0.9":{"tag":"2.0.9","author":"unifyca","date":"2026-09-21 16:13:13","revision":3705922}},"upgrade_notice":{"2.0.9":"<p>Fixes active plugins being left deactivated after an update run from Unifyca, and lets the connector keep itself up to date. Recommended for every connected site.<\/p>","2.0.8":"<p>More accurate identification of WordPress.org plugins and themes versus premium or custom ones. Backward compatible.<\/p>","2.0.7":"<p>Fixes plugins being shown as up to date right after one of them was updated. Backward compatible.<\/p>","2.0.6":"<p>Fixes the Site Health directory sizes (WordPress, uploads, themes, plugins, database, total) showing &quot;Loading\u2026&quot; instead of the real value. Sizes are now computed during the audit. Backward compatible.<\/p>","2.0.5":"<p>Fixes administrator &quot;last login IP&quot; detection on sites behind Cloudflare, reverse proxies or managed hosting, where the server\/proxy IP was stored instead of the real admin IP. Resolution stays fully local (no external lookup). Backward compatible.<\/p>","2.0.4":"<p>WordPress.org compliance: location handling now uses the WordPress API (no <code>WP_CONTENT_URL<\/code> \/ <code>WP_PLUGIN_DIR<\/code> path building, no <code>ABSPATH<\/code> disk-probe fallback), and database backups are stored as a protected ZIP archive only. Backward compatible.<\/p>","2.0.3":"<p>Restores the automatic &quot;disable file editor&quot; fix using a runtime define (no wp-config.php changes, nothing written to disk). WP_DEBUG stays manual. Backward compatible.<\/p>","2.0.2":"<p>Compliance update from the WordPress.org manual review: cURL replaced with the WP HTTP API, no automatic wp-config.php edits (now a manual recommendation), ZIP-only file backups, and no server path disclosure. Backward compatible.<\/p>","2.0.1":"<p>Compliance and security update. Removes external IP lookups and the custom self-updater, hardens backup storage, and locks down REST endpoints with dedicated permission checks. Fully backward compatible \u2014 connected sites keep working without re-pairing.<\/p>","2.0.0":"<p>Major redesign. The plugin now ships a full website audit dashboard inside wp-admin in addition to the existing Unifyca SaaS connector. The REST API, HMAC validation and SaaS sync payload remain fully backward compatible \u2014 existing connected sites continue to work without re-pairing.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3587073,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3587073,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3590387,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.0.4","2.0.9"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"The audit dashboard hero, showing the overall score, per-category scores and severity counters.","2":"The Security tab with a list of issue cards, each with a severity badge, explanation and recommended action.","3":"The Connect to Unifyca tab where administrators can copy the connection token to pair the site with the Unifyca SaaS."}},"plugin_section":[],"plugin_tags":[8642,268971,10710,41933,185881],"plugin_category":[],"plugin_contributors":[268972],"plugin_business_model":[],"class_list":["post-329370","plugin","type-plugin","status-publish","hentry","plugin_tags-security-audit","plugin_tags-website-documentation","plugin_tags-wordpress-backup","plugin_tags-wordpress-management","plugin_tags-wordpress-monitoring","plugin_contributors-unifyca","plugin_committers-unifyca"],"banners":{"banner":"https:\/\/ps.w.org\/unifyca-audit-connector\/assets\/banner-772x250.png?rev=3590387","banner_2x":"https:\/\/ps.w.org\/unifyca-audit-connector\/assets\/banner-1544x500.png?rev=3587073","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/unifyca-audit-connector\/assets\/icon-256x256.png?rev=3587073","icon_2x":"https:\/\/ps.w.org\/unifyca-audit-connector\/assets\/icon-256x256.png?rev=3587073","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>Unifyca Audit Connector<\/strong> is a WordPress audit and monitoring plugin that can optionally connect to Unifyca, a WordPress Website Management and Website Documentation platform for agencies and freelancers.<\/p>\n\n<p>Works locally.\nNo account required.\nConnect to Unifyca only if you want centralized WordPress management and website documentation.<\/p>\n\n<p>The plugin is designed for:<\/p>\n\n<ul>\n<li><strong>Freelancers<\/strong> who maintain WordPress sites for clients and want a fast, repeatable way to review them.<\/li>\n<li><strong>Agencies<\/strong> who need a consistent maintenance and reporting workflow across many WordPress installations.<\/li>\n<li><strong>Site owners<\/strong> who want a clearer picture of the operational health of their site without learning the WordPress internals.<\/li>\n<\/ul>\n\n<p>The audit logic runs entirely on your own server. No site data leaves WordPress unless you explicitly connect the site to the Unifyca SaaS (described below). You can use the plugin for free, locally, without creating an account.<\/p>\n\n<p>Complete documentation, setup guides and screenshots:\n<a href=\"https:\/\/unifyca.com\/en\/docs\/\">View the documentation<\/a><\/p>\n\n<h4>What the local audit checks<\/h4>\n\n<p><strong>Security<\/strong><\/p>\n\n<ul>\n<li>WordPress debug mode (<code>WP_DEBUG<\/code>) running on production<\/li>\n<li>WordPress file editor enabled<\/li>\n<li>XML-RPC endpoint enabled<\/li>\n<li>HTTPS not enabled for the site URL<\/li>\n<li>Directory listing on the site root<\/li>\n<li>PHP execution allowed inside the uploads folder<\/li>\n<li>Sensitive files publicly accessible (e.g. <code>wp-config.php<\/code>, <code>.env<\/code>, <code>.git\/<\/code>)<\/li>\n<li>Default <code>admin<\/code> username with administrator role<\/li>\n<li>New administrator users detected since the last audit<\/li>\n<li><code>debug.log<\/code> file present in <code>wp-content\/<\/code><\/li>\n<\/ul>\n\n<p><strong>Maintenance<\/strong><\/p>\n\n<ul>\n<li>WordPress core version outdated<\/li>\n<li>Plugin updates pending<\/li>\n<li>Active theme update pending<\/li>\n<li>Inactive plugins \/ inactive themes accumulating on disk<\/li>\n<li>PHP runtime older than the version WordPress currently recommends<\/li>\n<li>No backup plugin detected<\/li>\n<li>No caching plugin detected<\/li>\n<li>Maintenance mode currently active<\/li>\n<li>Expired transients accumulated in <code>wp_options<\/code><\/li>\n<\/ul>\n\n<p><strong>SEO<\/strong><\/p>\n\n<ul>\n<li>Search engines discouraged (Settings \u2192 Reading)<\/li>\n<li>Homepage with no H1, multiple H1s or an empty H1<\/li>\n<\/ul>\n\n<p><strong>Privacy &amp; compliance<\/strong><\/p>\n\n<ul>\n<li>Detection of files in the uploads directory that may carry identifying metadata (EXIF \/ GPS in images, author or device data in PDFs) and publicly-accessible backup files. This check is intentionally separate from the standard audit because it can be slower on large installations.<\/li>\n<\/ul>\n\n<h4>What you get for free, locally<\/h4>\n\n<ul>\n<li>On-demand local audit with one click from wp-admin<\/li>\n<li>Overall website health score plus per-category scores (Security \/ Maintenance \/ SEO \/ Privacy)<\/li>\n<li>Severity-aware issue cards with a human explanation, why it matters and the recommended action<\/li>\n<li>Counters by severity (Critical \/ High \/ Warning \/ Info)<\/li>\n<li>Clean, agency-friendly dashboard styling<\/li>\n<li>No account required to use the plugin locally<\/li>\n<\/ul>\n\n<h4>What is Unifyca?<\/h4>\n\n<p>Unifyca is a WordPress Website Management platform.<\/p>\n\n<p>It centralizes:<\/p>\n\n<p>\u2022 WordPress maintenance\n\u2022 Website monitoring\n\u2022 Backups\n\u2022 Website documentation\n\u2022 Hosting &amp; domains\n\u2022 Credentials\n\u2022 Client reports<\/p>\n\n<p>Everything around your websites in one place.<\/p>\n\n<h4>What Unifyca SaaS adds (optional)<\/h4>\n\n<p>Manage multiple WordPress websites from one dashboard.<\/p>\n\n<p>You can connect the site to the Unifyca SaaS at <a href=\"https:\/\/unifyca.com\">unifyca.com<\/a> for centralised WordPress maintenance:<\/p>\n\n<ul>\n<li>Apply safe fixes automatically from one dashboard<\/li>\n<li>Manage every WordPress site you operate from a single screen<\/li>\n<li>Schedule Autopilot fixes inside a configurable maintenance window<\/li>\n<li>Receive uptime alerts when a site goes down<\/li>\n<li>Generate white-label maintenance reports for clients<\/li>\n<li>Keep a complete history of every audit and fix that has been applied<\/li>\n<li>Keep hosting, domains, SSL certificates and credentials documented next to each website<\/li>\n<\/ul>\n\n<p>Connecting is fully optional. The plugin will continue running local audits even if you never create a Unifyca account.<\/p>\n\n<h4>What this plugin is not<\/h4>\n\n<ul>\n<li>It is not a \"set it and forget it\" security shield. It detects and explains issues; it does not patch your site automatically without your action.<\/li>\n<li>It does not guarantee security, GDPR compliance, or freedom from vulnerabilities. The local audit helps you spot common problems and review them \u2014 it does not certify any outcome.<\/li>\n<li>It does not send telemetry. There is no anonymous usage tracking and no analytics.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin can optionally connect to <strong>Unifyca<\/strong>, a Software-as-a-Service (SaaS) platform for WordPress website management and documentation. The connection is <strong>never automatic<\/strong>: it requires an explicit administrator action (pasting the connection token generated by the plugin into the Unifyca dashboard). Until you do that, the plugin runs entirely locally and contacts no external service.<\/p>\n\n<h4>Service and domains<\/h4>\n\n<p>When the site is connected, the plugin communicates with the Unifyca SaaS over these domains:<\/p>\n\n<ul>\n<li><a href=\"https:\/\/unifyca.com\">Unifyca<\/a> \u2014 Website, documentation and account area.<\/li>\n<li><a href=\"https:\/\/app.unifyca.com\">Unifyca App<\/a> \u2014 Application\/API, including the optional disconnect-feedback endpoint described below.<\/li>\n<\/ul>\n\n<h4>What the service does<\/h4>\n\n<p>Unifyca lets agencies and freelancers manage many WordPress sites from one place: it runs remote audits, applies administrator-approved fixes, runs and stores backups, monitors uptime, and keeps maintenance history and documentation. The connector exposes a set of HMAC-authenticated REST endpoints that the Unifyca SaaS calls to provide these features.<\/p>\n\n<h4>What data is sent, and when<\/h4>\n\n<ul>\n<li><strong>Local audits do not transmit any data externally.<\/strong> Running an audit from wp-admin keeps all results on your server.<\/li>\n<li>Data is sent to Unifyca <strong>only after the site is explicitly connected<\/strong>, and only when the SaaS initiates an authenticated (HMAC-SHA256 signed) request \u2014 there is no scheduled or background \"phone home\".<\/li>\n<li>When connected, the data sent is the standard audit payload: WordPress core version, site URL, locale, timezone and multisite flag; installed plugins\/themes metadata (name, slug, version, status, on-disk size, and where WordPress gets their updates from: WordPress.org slug or the host name of a declared Update URI \u2014 never code); server metadata (PHP version, memory limit, HTTPS state, <code>WP_DEBUG<\/code> and XML-RPC state, locally-resolved server IP); the WordPress Site Health diagnostic report (the same information WordPress exposes under Tools \u2192 Site Health \u2192 Info: configuration constants, database charset, directory sizes and file-system writability \u2014 with absolute server paths such as ABSPATH and WP_CONTENT_DIR removed); administrator account metadata (ID, login, email, display name, registration date and a one-way SHA-256 fingerprint of the password hash \u2014 never the hash itself); pending comment counts; and audit findings. Administrator login metadata (timestamp and IP of the last login) may be transmitted only when required for the security-monitoring features.<\/li>\n<li>The plugin never sends database contents, post or page content, user passwords, or hosting\/FTP\/SSH\/database credentials.<\/li>\n<\/ul>\n\n<h4>Optional disconnect feedback<\/h4>\n\n<p>When you disconnect the site, the confirmation dialog offers an <strong>optional<\/strong> \"what made you disconnect?\" reason and comment. Only if you fill one of those fields in and submit, the plugin sends a single non-blocking HTTPS POST to <code>https:\/\/app.unifyca.com\/ajax\/wp-disconnect-feedback.php<\/code> containing the selected reason code, the optional comment (max 500 characters), the site URL, the connection token (so Unifyca can match the entry to the correct account) and the plugin version. Submitting feedback is never required to disconnect, and nothing is sent if you leave the fields empty.<\/p>\n\n<h4>Terms and privacy<\/h4>\n\n<ul>\n<li>Terms of Service: https:\/\/unifyca.com\/en\/terms\/<\/li>\n<li>Privacy Policy: https:\/\/unifyca.com\/en\/privacy\/<\/li>\n<\/ul>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin performs a local WordPress audit. Connecting the site to the Unifyca SaaS at unifyca.com is entirely optional and requires explicit administrator action. Local audits do not contact any external service; external communication only occurs after the administrator explicitly connects the site to Unifyca.<\/p>\n\n<h4>Data the plugin stores locally<\/h4>\n\n<p>The plugin writes a small set of options and user metas inside your WordPress database:<\/p>\n\n<ul>\n<li><code>unifyca_connection_token<\/code>, <code>unifyca_token_status<\/code>, <code>unifyca_shared_secret<\/code>, <code>unifyca_connection_status<\/code>, <code>unifyca_connected_at<\/code> \u2014 connection state, only populated when the site is connected to Unifyca.<\/li>\n<li><code>unifyca_prev_admin_ids<\/code> \u2014 list of administrator user IDs at the time of the last audit; used internally to detect newly added administrators between audits.<\/li>\n<li><code>unifyca_disable_xmlrpc<\/code> \u2014 set to 1 when an administrator chose to disable XML-RPC through a connector fix action.<\/li>\n<li><code>unifyca_last_local_audit_at<\/code> \u2014 ISO timestamp of the last local audit.<\/li>\n<li><code>unifyca_last_privacy_lite_scan<\/code> \u2014 structured result of the last lightweight privacy review (counts and a few sample relative paths, never metadata values).<\/li>\n<li><code>unifyca_last_privacy_lite_scan_at<\/code> \u2014 ISO timestamp of the last lightweight privacy review.<\/li>\n<li><code>unifyca_disconnect_feedback_log<\/code> \u2014 rolling local log of the last 20 disconnect feedback submissions (reason code, optional comment, site URL, connection token at the time, plugin version, ISO timestamp). Only written when the administrator submits the optional disconnect feedback form. Always available for inspection via WP-CLI: <code>wp option get unifyca_disconnect_feedback_log --format=json<\/code>.<\/li>\n<li><code>_unifyca_last_login_at<\/code>, <code>_unifyca_last_login_ip<\/code> (user metadata) \u2014 timestamp and IP of the most recent successful login for administrator users only. Used to flag suspicious administrator activity.<\/li>\n<\/ul>\n\n<p>When the site is connected to Unifyca, this information may be transmitted to the Unifyca service to generate security alerts related to administrator account activity. The information is not used for advertising or profiling purposes.<\/p>\n\n<p>All of the above are removed on plugin uninstall.<\/p>\n\n<h4>Data sent to Unifyca<\/h4>\n\n<p>The plugin does not transmit any data to Unifyca unless an administrator explicitly connects the site.<\/p>\n\n<p>When connected, the plugin sends audit results and connection metadata required for the Unifyca service to operate.<\/p>\n\n<p>The plugin does not send:<\/p>\n\n<ul>\n<li>WordPress user passwords.<\/li>\n<li>Hosting, FTP or SSH passwords.<\/li>\n<li>Database passwords.<\/li>\n<li>WordPress post or page contents.<\/li>\n<li>Uploaded media files.<\/li>\n<li>Backup archives unless the administrator explicitly configures an external backup destination or uses a Unifyca backup feature that requires file transfer.<\/li>\n<\/ul>\n\n<p>Disconnecting the site stops future transmissions. Uninstalling the plugin removes all locally stored data listed above.<\/p>\n\n<h4>Third-party services used by the plugin<\/h4>\n\n<p>The local audit does not contact any third-party service. The plugin no longer performs an external public-IP lookup: the server IP reported in the audit is resolved locally from the web server environment only (<code>SERVER_ADDR<\/code> \/ hostname). When public IP detection is needed, it is handled server-side by Unifyca after the site has been connected.<\/p>\n\n<p>The only external service the plugin can communicate with is the <strong>Unifyca SaaS<\/strong>, available at <a href=\"https:\/\/unifyca.com\">unifyca.com<\/a> and <a href=\"https:\/\/app.unifyca.com\">app.unifyca.com<\/a>, and only after the administrator explicitly connects the site.\nSee the <em>External services<\/em> section above for full details, including the service domains, Terms of Service and Privacy Policy.<\/p>\n\n<p>Plugin and theme updates requested from Unifyca \u2014 including an update of this plugin itself \u2014 are installed through WordPress's own update system, which downloads the package from the WordPress.org plugin directory exactly as wp-admin does. The plugin never downloads code from Unifyca or from any other location.<\/p>\n\n<h4>Optional disconnect feedback<\/h4>\n\n<p>When you disconnect the site from Unifyca through the <strong>Connect to Unifyca<\/strong> tab, the confirmation modal exposes an <em>optional<\/em> \"what made you disconnect?\" reason selector with a short comment field. Submitting it is never required to disconnect.<\/p>\n\n<p><strong>No personal user data is sent automatically.<\/strong> The connected site URL and the optional feedback reason\/comment may be shared with Unifyca <strong>only<\/strong> when you explicitly submit the disconnect feedback form. The site URL is included because, in some setups, it can identify a business or organisation; we are upfront about this so you can decide whether to submit feedback at all.<\/p>\n\n<p>If \u2014 and only if \u2014 you fill in one of those fields, the plugin sends a single non-blocking HTTPS POST to https:\/\/app.unifyca.com\/ajax\/wp-disconnect-feedback.php containing: the selected reason code, the optional comment (up to 500 characters), the site URL, the connection token (so Unifyca can match the entry to the correct tenant), and the plugin version.\nThe connection token is transformed into a non-reversible representation before storage. The connection token is never stored in its original form.<\/p>\n\n<p>The connection token is the only stable identifier the plugin holds for the connected tenant \u2014 the handshake does not store a separate Unifyca tenant\/project\/site ID. The shared secret is deliberately never included in this payload.<\/p>\n\n<p>The request is fire-and-forget: if it fails, the disconnect still completes normally. Nothing else is transmitted at this step.<\/p>\n\n<h4>Data sent to the Unifyca SaaS (only when the site is connected)<\/h4>\n\n<p>If the administrator pastes the connection token into Unifyca, the SaaS gains the ability to call the connector's REST endpoints. From that moment on, the standard audit payload is transmitted to Unifyca when the SaaS triggers a sync. The payload contains:<\/p>\n\n<ul>\n<li>WordPress core version, configured site URL, locale, timezone, multisite flag.<\/li>\n<li>Installed plugins \/ themes (name, slug, version, status, on-disk size, update source \u2014 WordPress.org slug or Update URI host name \u2014 never code).<\/li>\n<li>Server metadata (PHP version, memory limit, HTTPS state, <code>WP_DEBUG<\/code>, XML-RPC enabled state, locally-resolved server IP \u2014 no external IP lookup is performed).<\/li>\n<li>Administrator accounts: ID, login, email, display name, registration date and a SHA-256 fingerprint of the WordPress password hash. The raw password hash is NEVER transmitted \u2014 the fingerprint is one-way and exists only to detect password changes between syncs.<\/li>\n<li>Pending comment counts (counts only; no comment content unless the SaaS specifically requests the moderation queue, which carries plain-text excerpts only).<\/li>\n<li>Audit findings (counts, severity, alert metadata, paths to inactive plugins\/themes when relevant).<\/li>\n<\/ul>\n\n<p>The plugin never sends database contents, post content, page content, user passwords, or commercial data to any third party.<\/p>\n\n<p>If the administrator disconnects the site (from the <strong>Connect to Unifyca<\/strong> tab), the shared secret is wiped and no further data can be sent to the SaaS until a new pairing is performed.<\/p>\n\n<h4>Telemetry and automatic data collection<\/h4>\n\n<p>None. The plugin does not run analytics, fingerprinting, scheduled \"phone home\" calls or any background data collection. Local audits make no outbound requests to external services. Every outgoing request to Unifyca falls into one of two explicit categories:<\/p>\n\n<ul>\n<li>part of the documented SaaS sync, which only happens after the administrator has paired this site with Unifyca and is authenticated by HMAC,<\/li>\n<li>the optional disconnect feedback POST described above, which is sent <strong>only<\/strong> when the administrator explicitly submits the form.<\/li>\n<\/ul>\n\n<p>No personal user data, post content, page content, comment bodies or user passwords are ever transmitted in any of these cases.<\/p>\n\n<h3>Documentation<\/h3>\n\n<p>Complete documentation is available online:<\/p>\n\n<ul>\n<li><a href=\"https:\/\/unifyca.com\/en\/docs\/\">English<\/a><\/li>\n<li><a href=\"https:\/\/unifyca.com\/es\/docs\/\">Espa\u00f1ol<\/a><\/li>\n<li><a href=\"https:\/\/unifyca.com\/ca\/docs\/\">Catal\u00e0<\/a><\/li>\n<\/ul>\n\n<p>The documentation includes setup guides, audit explanations, backup features, privacy details and troubleshooting information.<\/p>\n\n<h3>Source code<\/h3>\n\n<p>This plugin is distributed under the GPL v2 or later. All assets (CSS, JavaScript, SVG) included in the plugin ZIP are the unminified, human-readable source.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install <strong>Unifyca Audit Connector<\/strong> through Plugins \u2192 Add New, or upload the plugin folder to <code>wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to <strong>Unifyca Audit<\/strong> in the wp-admin sidebar.<\/li>\n<li>Click <strong>Run audit<\/strong> to perform the first local audit. Results appear inline.<\/li>\n<li>(Optional) To connect this site to the Unifyca SaaS, open the <strong>Connect to Unifyca<\/strong> tab, copy the connection token and paste it into the corresponding Unifyca dashboard.<\/li>\n<\/ol>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 5.8 or newer<\/li>\n<li>PHP 7.1 or newer<\/li>\n<li>PHP <code>curl<\/code> extension recommended (used to read the homepage HTML when checking SEO heading structure)<\/li>\n<li>PHP ZipArchive extension required for backups.<\/li>\n<\/ul>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20is%20wordpress%20website%20management%3F\"><h3>What is WordPress Website Management?<\/h3><\/dt>\n<dd><p>WordPress Website Management is the practice of centralizing updates, audits, monitoring, backups and the infrastructure around websites.<\/p>\n\n<p>Unifyca combines:<\/p>\n\n<ul>\n<li>Security audits<\/li>\n<li>Monitoring and uptime<\/li>\n<li>Backups<\/li>\n<li>Website documentation<\/li>\n<li>Hosting and domains<\/li>\n<li>Credentials<\/li>\n<li>Client reports<\/li>\n<\/ul>\n\n<p>Everything around your websites in one place.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20modify%20my%20site%20automatically%3F\"><h3>Does the plugin modify my site automatically?<\/h3><\/dt>\n<dd><p>No. Local audits are read-only. No changes are made unless an administrator explicitly performs an action.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20send%20my%20data%20anywhere%3F\"><h3>Does this plugin send my data anywhere?<\/h3><\/dt>\n<dd><p>No, not unless you explicitly connect the site to the Unifyca SaaS through the <strong>Connect to Unifyca<\/strong> tab.<\/p>\n\n<p>When <strong>not connected<\/strong>, the local audit performs no outbound requests to any external service. The only network requests it can make are HTTPS loopback requests to your own site URL (to read the homepage HTML and to check whether files like <code>wp-config.php<\/code> respond publicly).<\/p>\n\n<p>No site contents, no posts, no users, no credentials and no audit results are transmitted anywhere unless the site is explicitly connected. See the <em>External services<\/em> section below for what happens once you connect.<\/p><\/dd>\n<dt id=\"how%20is%20the%20audit%20triggered%3F\"><h3>How is the audit triggered?<\/h3><\/dt>\n<dd><p>Only on explicit action:<\/p>\n\n<ul>\n<li>The wp-admin user clicks <strong>Run audit<\/strong> in the dashboard.<\/li>\n<li>The Unifyca SaaS sends an HMAC-authenticated REST request to <code>\/wp-json\/unifyca\/v1\/audit<\/code> (this happens only when the site is connected).<\/li>\n<\/ul>\n\n<p>There is no scheduled or background audit. There is no telemetry.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20using%20the%20plugin%20without%20creating%20a%20unifyca%20account%3F\"><h3>Can I keep using the plugin without creating a Unifyca account?<\/h3><\/dt>\n<dd><p>Yes. The local audit dashboard works fully without a Unifyca account. The <strong>Connect to Unifyca<\/strong> tab is purely optional.<\/p><\/dd>\n<dt id=\"what%20user%20role%20can%20run%20the%20audit%3F\"><h3>What user role can run the audit?<\/h3><\/dt>\n<dd><p>Only users with the <code>manage_options<\/code> capability (typically administrators). All admin actions and the AJAX endpoint validate this capability and a WordPress nonce on every request.<\/p><\/dd>\n<dt id=\"why%20does%20the%20audit%20take%20a%20few%20seconds%3F\"><h3>Why does the audit take a few seconds?<\/h3><\/dt>\n<dd><p>The audit performs HTTP checks against your own site URL (homepage, sensitive paths) and synchronously calculates Site Health values. These checks are intentionally local and can take a few seconds on larger installations. Run the audit when you want fresh results \u2014 the dashboard does not auto-refresh.<\/p><\/dd>\n<dt id=\"why%20is%20the%20score%20for%20one%20of%20my%20sites%20not%20100%3F\"><h3>Why is the score for one of my sites not 100?<\/h3><\/dt>\n<dd><p>The plugin penalises each detected issue based on severity (Critical, High, Warning, Info) and shows you exactly which checks contributed.<\/p>\n\n<p>When the site is <strong>not connected<\/strong> to Unifyca, the dashboard exposes per-category tabs (Security, Maintenance, SEO, Privacy) with the full local list of findings and explanations.<\/p>\n\n<p>When the site <strong>is connected<\/strong> to Unifyca, the wp-admin dashboard becomes a lightweight companion view and the detailed breakdown, fix history and automation live in the Unifyca dashboard.<\/p><\/dd>\n<dt id=\"can%20i%20uninstall%20the%20plugin%20without%20leaving%20residual%20data%3F\"><h3>Can I uninstall the plugin without leaving residual data?<\/h3><\/dt>\n<dd><p>Yes. When you delete the plugin from wp-admin \u2192 Plugins, the <code>uninstall.php<\/code> script runs and removes every option and user meta value the plugin has stored. No data remains.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20guarantee%20my%20site%20is%20secure%3F\"><h3>Does this plugin guarantee my site is secure?<\/h3><\/dt>\n<dd><p>No. The audit helps detect and explain a number of common operational and security issues, but it cannot guarantee that a site is secure. Treat the findings as a checklist to review and improve \u2014 not as a certification.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.0.9<\/h4>\n\n<ul>\n<li>Fixed active plugins being left deactivated after being updated from Unifyca. The update used a WordPress routine that deactivates a running plugin before replacing its files and does not switch it back on; the plugin now uses the same routine the WordPress Plugins screen uses, which never deactivates anything. As an extra safeguard, any plugin that was active before the update and is not active afterwards is switched back on silently, and the result reports it. Plugins that were inactive stay inactive.<\/li>\n<li>The connector can now update itself when a connected Unifyca account asks it to. The new version is installed through WordPress's own plugin update system from the WordPress.org directory, exactly like pressing \"Update now\" in Plugins; nothing is downloaded from any other location and the request cannot choose which plugin to update \u2014 it is always this one. The connector keeps its activation state, including network activation on multisite, and if it is ever left inactive the result says so instead of failing silently.<\/li>\n<\/ul>\n\n<h4>2.0.8<\/h4>\n\n<ul>\n<li>Fixed plugins being reported as \"WordPress.org plugins\" when WordPress had merely checked them for updates. WordPress lists every installed plugin in its update-check data, so premium and custom plugins were classified the same as plugins from the WordPress.org directory. A plugin (or theme) is now identified as a WordPress.org item only when the WordPress.org update service itself returned it.<\/li>\n<li>The audit now reports, for each plugin and theme, where WordPress gets its updates from: WordPress.org (with its WordPress.org slug), a third-party updater or \"Update URI\" header (only the host name is sent), none, or unknown. This lets Unifyca avoid mistaking a custom plugin for a WordPress.org plugin that happens to use the same folder name. No new data is collected from the site beyond what WordPress core already stores for its own update checks.<\/li>\n<\/ul>\n\n<h4>2.0.7<\/h4>\n\n<ul>\n<li>Fixed plugin (and theme) update availability being reported as \"up to date\" for every plugin on the first audit after updating a plugin. WordPress deletes its cached update data when a plugin is updated; the audit now refreshes that data through WordPress core's own update checks before reading plugin and theme information, instead of afterwards.<\/li>\n<\/ul>\n\n<h4>2.0.6<\/h4>\n\n<ul>\n<li>Fixed the WordPress Site Health directory sizes (\"WordPress directory size\", \"Uploads directory size\", themes, plugins, database and total) being reported as \"Loading\u2026\" instead of the real value. These sizes are computed asynchronously in wp-admin; the connector now computes them synchronously via <code>WP_Debug_Data::get_sizes()<\/code> and uses the resulting values whenever available, instead of relying on the internal <code>loading...<\/code> placeholder marker. On large sites the audit may take a few extra seconds while the sizes are calculated.<\/li>\n<li>Stripped absolute server paths from the Site Health data before it is sent. Every section is scanned \u2014 the core \"WordPress constants\" (ABSPATH, WP_CONTENT_DIR, WP_PLUGIN_DIR \u2026) and \"Directories and Sizes\" (the WordPress, uploads, themes and plugins directory locations) sections, as well as any section added by third-party plugins (for example Redux Framework's \"Data Directory\"). WordPress core exposes these paths locally in Tools \u2192 Site Health \u2192 Info, but they are no longer transmitted to the connected service, consistent with the path-disclosure hardening in 2.0.2 \/ 2.0.4. Non-path diagnostics (versions, memory limits, database charset, directory sizes, writability, etc.) are unchanged.<\/li>\n<li>Fixed WordPress admin notices (theme\/plugin update prompts, etc.) rendering next to the plugin logo instead of in their normal position. Added the standard <code>wp-header-end<\/code> marker so core moves notices below the page header.<\/li>\n<\/ul>\n\n<h4>2.0.5<\/h4>\n\n<ul>\n<li>Fixed administrator login IP detection behind proxies. The recorded \"last login IP\" previously defaulted to REMOTE_ADDR, which on sites served through Cloudflare, a reverse proxy, a load balancer or a managed-hosting front-end is the proxy\/server address rather than the real administrator IP.<\/li>\n<li>IP resolution now trusts forwarded headers only when the request genuinely arrives through a proxy: CF-Connecting-IP is used only when REMOTE_ADDR is a known Cloudflare edge range, and X-Forwarded-For is used only when REMOTE_ADDR is not a public client IP. Private, reserved, loopback and invalid forwarded values are rejected, and REMOTE_ADDR remains the safe fallback.<\/li>\n<li>Resolution stays fully local to the current request's server variables \u2014 no external service or outbound request is used. IPv4 and IPv6 are both supported.<\/li>\n<\/ul>\n\n<h4>2.0.4<\/h4>\n\n<ul>\n<li>Compliance pass following the WordPress.org manual review.<\/li>\n<li>Determine file\/directory locations through the WordPress API instead of internal constants: the audit payload now reports the public content URL via <code>content_url()<\/code>, and other plugins' on-disk size is measured by deriving the plugins root from <code>plugin_dir_path()<\/code> on the main file rather than <code>WP_PLUGIN_DIR<\/code>.<\/li>\n<li>Disk-free-space probing no longer falls back to an absolute server path: if <code>wp_upload_dir()<\/code> cannot be resolved the probe is skipped.<\/li>\n<li>Database backups are now stored as a protected ZIP archive (<code>database.zip<\/code>) only. The raw SQL is streamed to a temporary file (<code>wp_tempnam()<\/code>), added to the ZIP, and deleted immediately in both success and failure paths \u2014 a loose <code>database.sql<\/code> is never left on disk. ZIP support is required; there is no loose-SQL fallback.<\/li>\n<li>Removed the literal <code>ABSPATH<\/code> token from user-facing error messages.<\/li>\n<\/ul>\n\n<h4>2.0.3<\/h4>\n\n<ul>\n<li>Restored the automatic \"disable file editor\" fix using a runtime-only define. When enabled, DISALLOW_FILE_EDIT is set with <code>define()<\/code> on every request from the plugin bootstrap \u2014 wp-config.php is never modified, no file is written to disk and an existing definition is never overridden.<\/li>\n<li>WP_DEBUG remains detection-only with a manual recommendation; it is never changed automatically.<\/li>\n<\/ul>\n\n<h4>2.0.2<\/h4>\n\n<ul>\n<li>Compliance pass following the WordPress.org manual review.<\/li>\n<li>Replaced all plugin cURL calls with the WordPress HTTP API (<code>wp_remote_get<\/code>).<\/li>\n<li>The plugin no longer edits wp-config.php automatically. The WP_DEBUG and file-editor fixes now return a manual recommendation telling the administrator exactly which line to add; the audit still detects the issue.<\/li>\n<li>Pre-modify file backups (e.g. .htaccess, robots.txt) are now stored inside ZIP archives in the protected uploads backup directory \u2014 no loose <code>.bak<\/code> or config files are ever written.<\/li>\n<li>Stopped exposing absolute server paths (ABSPATH, WP_CONTENT_DIR, document root) in the audit payload and error messages.<\/li>\n<li>Added the <code>UNIFYCA_PLUGIN_URL<\/code> constant and tidied file\/directory location handling; writable storage always uses <code>wp_upload_dir()<\/code>.<\/li>\n<\/ul>\n\n<h4>2.0.1<\/h4>\n\n<ul>\n<li>WordPress.org compliance pass following directory pre-review.<\/li>\n<li>Removed the external public-IP lookup (<code>api.ipify.org<\/code>). Local audits now make no outbound requests to any external service; the server IP is resolved locally only.<\/li>\n<li>Removed the connector self-update mechanism. The plugin now relies exclusively on the WordPress.org update infrastructure and no longer writes the <code>update_plugins<\/code> site transient.<\/li>\n<li>Hardened backup storage: backups are stored under <code>wp-content\/uploads\/unifyca-backups\/<\/code> (via <code>wp_upload_dir()<\/code>), always protected with an <code>index.php<\/code> and a deny-all <code>.htaccess<\/code>. Core backups are written as a single ZIP archive \u2014 the plugin never leaves loose, web-accessible PHP files (e.g. <code>wp-config.php<\/code>, <code>wp-settings.php<\/code>) in the backup directory.<\/li>\n<li>Replaced every <code>__return_true<\/code> REST permission callback with dedicated callbacks that verify the connection state, the HMAC signature (timestamp freshness + shared-secret), and, for backup downloads, the short-lived signed token.<\/li>\n<li>Documented all external services and updated the Privacy section.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>New wp-admin dashboard. Replaces the previous connector-only settings page with a full website-health audit experience.<\/li>\n<li>Local audits run without a Unifyca account. The plugin can be used standalone.<\/li>\n<li>New score system (overall + per-category) with consistent severity colours.<\/li>\n<li>Issue cards include human explanations, \"why it matters\" and recommended actions.<\/li>\n<li>New <code>Unifyca_Audit_Engine<\/code> class. Single source of truth for all audit checks.<\/li>\n<li>New <code>Unifyca_Alert_Catalog<\/code> class. Translates raw audit data into UI-friendly issue cards.<\/li>\n<li>New <code>Unifyca_Score<\/code> class. Pure score-calculation layer.<\/li>\n<li>AJAX-driven \"Run audit\" button. No page reload. Nonce + <code>manage_options<\/code> enforced.<\/li>\n<li><code>uninstall.php<\/code> removes every option and user meta the plugin created.<\/li>\n<li>WordPress.org-compliance pass: connector self-update gated behind <code>UNIFYCA_ALLOW_CONNECTOR_SELF_UPDATE<\/code> (off by default).<\/li>\n<\/ul>\n\n<h4>1.0.17<\/h4>\n\n<ul>\n<li>Connector-only release. Token pairing, HMAC validation and SaaS sync.<\/li>\n<\/ul>","raw_excerpt":"Connect your WordPress site to Unifyca for centralized management, audits, backups, monitoring and website documentation.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/329370","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=329370"}],"author":[{"embeddable":true,"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/unifyca"}],"wp:attachment":[{"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=329370"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=329370"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=329370"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=329370"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=329370"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=329370"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}