{"id":332331,"date":"2026-07-31T18:12:18","date_gmt":"2026-07-31T18:12:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sentio-license-manager\/"},"modified":"2026-07-31T19:23:54","modified_gmt":"2026-07-31T19:23:54","slug":"sentio-license-manager","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/sentio-license-manager\/","author":15604965,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.8.5","stable_tag":"1.8.5","tested":"7.0.2","requires":"6.2","requires_php":"8.0","requires_plugins":null,"header_name":"Sentio License Manager \u2013 Sell Digital Products with WooCommerce","header_author":"Sentio Addons","header_description":"License key management for WooCommerce. Issue and validate license keys for your plugins and themes, manage per-site activations, and provide a REST API for license validation. Includes migration tools for License Manager for WooCommerce and Digital License Manager.","assets_banners_color":"150f26","last_updated":"2026-07-31 19:23:54","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/sentioaddons.com\/sentio-woocommerce-license-and-subscriptions\/","header_author_uri":"https:\/\/sentioaddons.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":36,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.8.5":{"tag":"1.8.5","author":"jtconnelly1","date":"2026-07-31 19:23:54"}},"upgrade_notice":{"1.8.5":"<p>Telemetry is now opt-in with the consent box unchecked by default, and the plugin&#039;s identifier prefix is lengthened to avoid conflicts with other plugins. Stored settings reset to defaults on upgrade.<\/p>","1.8.4":"<p>Security hardening: nonce-verified preference persistence, inline capability + nonce checks in every admin handler; bundled example code replaced by hosted documentation.<\/p>","1.8.3":"<p>Security and code-standards hardening for WordPress.org review: enqueued admin assets, stricter input sanitization and output escaping, write-permission enforcement on compat-API mutations, and authenticated telemetry opt-out.<\/p>","1.8.2":"<p>Update-delivery feature removed; this is now a license-management-only plugin per WordPress.org guidelines.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3630423,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3630423,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3630423,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3630423,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3630423,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.8.5"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[146554,242119,58362,26437,286],"plugin_category":[45],"plugin_contributors":[266733],"plugin_business_model":[],"class_list":["post-332331","plugin","type-plugin","status-publish","hentry","plugin_tags-license-manager","plugin_tags-plugin-license","plugin_tags-serial-key","plugin_tags-software-license","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-jtconnelly1","plugin_committers-jtconnelly1"],"banners":{"banner":"https:\/\/ps.w.org\/sentio-license-manager\/assets\/banner-772x250.png?rev=3630423","banner_2x":"https:\/\/ps.w.org\/sentio-license-manager\/assets\/banner-1544x500.png?rev=3630423","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/sentio-license-manager\/assets\/icon.svg?rev=3630423","icon":"https:\/\/ps.w.org\/sentio-license-manager\/assets\/icon.svg?rev=3630423","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Sentio License Manager turns your WooCommerce store into a software licensing server. Sell licenses for your plugins, themes, or apps and let customers activate their purchase by signing in with their store account \u2014 no license keys to email, copy, or paste, and no separate dashboard to learn.<\/p>\n\n<p>When a customer completes an order for a licensed product, Sentio License Manager issues a license automatically and ties it to their account. The customer installs your software, opens its license screen, signs in with their store email and password, and activation happens in one step \u2014 on every site they own, up to the plan's seat limit.<\/p>\n\n<h4>Login-Based Activation \u2014 No Keys Required<\/h4>\n\n<p>Instead of emailing keys and fielding \"it says invalid\" support tickets, Sentio License Manager authenticates against your store credentials. Customers never see or handle a license key.<\/p>\n\n<h4>A Full REST API for Your Client Plugins<\/h4>\n\n<p>Sentio License Manager exposes a Bearer-token REST API that your distributed plugin or theme talks to: authenticate, activate a site, verify a license, and deactivate a seat. The built-in Integration Guide documents every endpoint with copy-pasteable code, and a complete working example client is available in the hosted developer documentation \u2014 copy one file, set four constants, and your software is license-aware.<\/p>\n\n<h4>Migrate From LMFWC or Digital License Manager<\/h4>\n\n<p>Already using License Manager for WooCommerce (LMFWC) or Digital License Manager (DLM)? Sentio License Manager imports your existing licenses with a guided, dry-run-first migration tool. It also ships REST API compatibility shims that return LMFWC- and DLM-shaped responses, so the client integrations you have already deployed keep working without code changes while you transition.<\/p>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li>Login-based activation \u2014 customers activate with their store account, never a key<\/li>\n<li>Automatic license generation when a WooCommerce order completes<\/li>\n<li>Per-domain activation management with configurable seat limits per plan<\/li>\n<li>Single-site, multi-site, and unlimited activation tiers<\/li>\n<li>Full REST API with Bearer-token authentication for client plugins<\/li>\n<li>Built-in Integration Guide with copy-pasteable code, linked to full hosted developer documentation<\/li>\n<li>One-click migration from License Manager for WooCommerce (LMFWC) and Digital License Manager (DLM)<\/li>\n<li>REST API compatibility shims so existing LMFWC\/DLM client integrations keep working<\/li>\n<li>Optional, consent-gated anonymous usage telemetry (off unless you opt in)<\/li>\n<li>HPOS (High-Performance Order Storage) compatible<\/li>\n<\/ul>\n\n<h4>How It Works<\/h4>\n\n<ol>\n<li>Install Sentio License Manager on your WooCommerce store, create a product, and link it to a license plan from the Products screen \u2014 a couple of minutes with the built-in panel.<\/li>\n<li>A customer purchases through your store and receives an order confirmation automatically.<\/li>\n<li>The customer installs your plugin or theme, opens its license screen, and signs in with their store credentials \u2014 the license activates immediately, no key required.<\/li>\n<\/ol>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 6.2 or higher<\/li>\n<li>WooCommerce 9.0 or higher<\/li>\n<li>PHP 8.0 or higher<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to one external service. The connection is described below with what data is sent, when it occurs, and links to the vendor's terms of service and privacy policy.<\/p>\n\n<h4>sentioaddons.com \u2014 telemetry (consent-gated, opt-in)<\/h4>\n\n<p>This plugin includes an opt-in anonymous-usage telemetry feature so we can understand how Sentio License Manager is used \u2014 license and product volumes, WordPress and PHP versions, and which migration paths people take \u2014 to prioritize bug fixes and decide what to build next. <strong>No data is sent before you grant consent.<\/strong><\/p>\n\n<p>On first activation, the plugin redirects you to a welcome screen at <strong>Sentio &rarr; Welcome<\/strong>. The welcome screen presents a clear consent toggle (default checked, but you can uncheck it before saving) and an optional email field. Two buttons close the welcome screen: clicking <strong>Allow &amp; Start Building<\/strong> respects the checkbox state; clicking <strong>Skip<\/strong> forces consent to off regardless of the checkbox.<\/p>\n\n<p>If you grant consent, a daily WordPress cron job (<code>sentiolm_telemetry_ping<\/code>) POSTs to <code>https:\/\/sentioaddons.com\/wp-json\/sentio-lm\/v1\/telemetry<\/code>. The cron runs once per 24-hour window from the time of consent.<\/p>\n\n<p>The data fields the plugin sends are:<\/p>\n\n<ul>\n<li>Plugin version<\/li>\n<li>WordPress version<\/li>\n<li>PHP version<\/li>\n<li>WooCommerce version (if WooCommerce is active)<\/li>\n<li>Aggregate license counts \u2014 total, plus active \/ expired \/ revoked status breakdown (counts only; no license keys, no customer data)<\/li>\n<li>Aggregate product count<\/li>\n<li>Migration usage \u2014 counts of licenses imported from License Manager for WooCommerce (LMFWC) and Digital License Manager (DLM)<\/li>\n<li>Number of REST-compatibility keys configured<\/li>\n<li>Site locale<\/li>\n<li>SHA-256 hash of the site URL (one-way; not reversible to the original URL \u2014 used only to deduplicate pings from the same site)<\/li>\n<li>Optional email address \u2014 only if you provided one in the welcome screen<\/li>\n<\/ul>\n\n<p>The site's IP address is <strong>not<\/strong> sent by the plugin. If country-level data is needed for analytics, it is enriched server-side from the Cloudflare <code>CF-IPCountry<\/code> HTTP header at the moment of the request, never persisted. License keys, customer emails, order details, post\/page content, and visitor analytics are never collected.<\/p>\n\n<p>You can opt out at any time from <strong>Sentio &rarr; Settings &rarr; Anonymous Usage Data<\/strong>. Opting out fires a DELETE request to <code>https:\/\/sentioaddons.com\/wp-json\/sentio-lm\/v1\/telemetry\/site<\/code> to remove your site's data row from our servers, and unschedules the daily cron. Opt-out is one click and does not require a confirmation step. The deletion is authenticated: each daily ping returns a random deletion token (stored only on your site; the server keeps only a hash), and the opt-out request presents that token so no third party can delete or spoof your site's row.<\/p>\n\n<ul>\n<li>Privacy Policy: <a href=\"https:\/\/sentioaddons.com\/privacy-policy\/\">https:\/\/sentioaddons.com\/privacy-policy\/<\/a><\/li>\n<\/ul>\n\n<h4>Cloudflare IP ranges (no connection made)<\/h4>\n\n<p>This plugin includes a one-click preset that fills the trusted-proxy setting with Cloudflare's publicly published IP ranges, for sites served through Cloudflare. The ranges are bundled as a static list inside the plugin (last verified 2026-04-18). The plugin never connects to Cloudflare, never loads anything from Cloudflare, and sends no data to Cloudflare \u2014 the preset is optional and only writes the bundled list into your own site's settings when you click it. Cloudflare's terms: <a href=\"https:\/\/www.cloudflare.com\/terms\/\">https:\/\/www.cloudflare.com\/terms\/<\/a> \u2014 privacy: <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">https:\/\/www.cloudflare.com\/privacypolicy\/<\/a><\/p>\n\n<h3>Credits<\/h3>\n\n<p>This plugin bundles one third-party library:<\/p>\n\n<ul>\n<li><strong>defuse\/php-encryption<\/strong> (MIT license) \u2014 used only to decrypt your existing license keys when migrating from License Manager for WooCommerce (LMFWC) or Digital License Manager (DLM). It performs local cryptography only and makes no network connections. Source: <a href=\"https:\/\/github.com\/defuse\/php-encryption\">https:\/\/github.com\/defuse\/php-encryption<\/a><\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>sentio-license-manager<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install it from your WordPress admin under <strong>Plugins &rarr; Add New<\/strong>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Ensure <strong>WooCommerce<\/strong> is installed and active.<\/li>\n<li>Go to <strong>License Manager &rarr; Products<\/strong> to create your first product plan.<\/li>\n<li>Link the plan to a WooCommerce product or variation.<\/li>\n<li>See <strong>License Manager &rarr; Integration Guide<\/strong> for client plugin setup instructions; a complete example client lives in the hosted developer documentation linked from the guide.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20require%20woocommerce%3F\"><h3>Does this require WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. WooCommerce must be installed and active \u2014 Sentio License Manager generates licenses from completed WooCommerce orders.<\/p><\/dd>\n<dt id=\"how%20do%20customers%20activate%20their%20license%3F\"><h3>How do customers activate their license?<\/h3><\/dt>\n<dd><p>They install your plugin or theme, open its license screen, and sign in with their WooCommerce store account email and password. No license key is copied or pasted.<\/p><\/dd>\n<dt id=\"can%20i%20migrate%20from%20another%20license%20plugin%3F\"><h3>Can I migrate from another license plugin?<\/h3><\/dt>\n<dd><p>Yes. Sentio License Manager includes guided importers for License Manager for WooCommerce (LMFWC) and Digital License Manager (DLM). Each migration offers a dry run first so you can preview exactly what will be imported.<\/p><\/dd>\n<dt id=\"will%20my%20existing%20client%20integrations%20break%20after%20migrating%3F\"><h3>Will my existing client integrations break after migrating?<\/h3><\/dt>\n<dd><p>No. Sentio License Manager ships REST API compatibility shims that return LMFWC- and DLM-shaped responses, so the client code you have already shipped to customers keeps working while you transition to Sentio License Manager's native API.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20any%20data%20off-site%3F\"><h3>Does the plugin send any data off-site?<\/h3><\/dt>\n<dd><p>Only if you opt in. On first activation Sentio License Manager shows a welcome screen with an anonymous-usage telemetry toggle (and an optional email). Nothing is sent unless you allow it, and you can opt out anytime from Settings. See the \"External Services\" section above for the exact data and endpoints.<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20hpos%3F\"><h3>Is it compatible with HPOS?<\/h3><\/dt>\n<dd><p>Yes. Sentio License Manager is fully compatible with WooCommerce High-Performance Order Storage (custom order tables).<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.8.5 - 2026-07-28<\/h4>\n\n<ul>\n<li>The anonymous-usage telemetry checkbox on the welcome screen now renders unchecked. Telemetry is strictly opt-in: nothing is transmitted, no email is stored, and no scheduled task is created unless you tick the box and save.<\/li>\n<li>Global identifier prefix lengthened from <code>slm<\/code> to <code>sentiolm<\/code> to prevent conflicts with other plugins, per the directory guidelines. This covers option and user-meta keys, transients, scheduled-task hooks, action and filter names, form and AJAX action names, nonce actions, script and style handles, admin page slugs, and plugin constants. Existing installs carry their schema-tracking data forward automatically; other stored settings reset to defaults on upgrade.<\/li>\n<\/ul>\n\n<h4>1.8.4 - 2026-07-24<\/h4>\n\n<ul>\n<li>The bundled example-integration reference code has been removed from the package in favor of hosted developer documentation (linked from the Integration Guide and overridable via the sentiolm_example_integration_url filter). The guide's inline code snippets are unchanged.<\/li>\n<li>The licenses-table per-page preference is now persisted only on a nonce-verified filter-form submit by a user with manage_options \u2014 plain pagination links can no longer write the stored preference.<\/li>\n<li>Every admin action handler (admin-post forms, AJAX endpoints, WooCommerce save hooks) now carries an explicit inline capability check followed by its nonce verification as the first statements of the handler, replacing the shared verification helper so the checks are visible at every read site.<\/li>\n<\/ul>\n\n<h4>1.8.3 - 2026-07-20<\/h4>\n\n<ul>\n<li>All admin inline <code>&lt;script&gt;<\/code>\/<code>&lt;style&gt;<\/code> blocks moved into enqueued asset files (Integration Guide, Settings, Products, and the WooCommerce product panel\/variation fields), loaded only on their owning screens via <code>admin_enqueue_scripts<\/code>.<\/li>\n<li>Input-sanitization hardening: the licenses-table pagination now builds its links from an allowlisted, pre-sanitized parameter set instead of the raw request; API credential secrets from HTTP Basic Auth are sanitized at every intake point.<\/li>\n<li>Output-escaping hardening: white-label values interpolated into inline CSS are now type-sanitized (hex colors, font allowlist, tag-stripped custom CSS), and the My Account endpoint title filter escapes the substituted label.<\/li>\n<li>REST security: the LMFWC\/DLM compatibility shims now require a consumer key with write permission for license activation and deactivation (matching create\/update\/delete); telemetry opt-out deletion now requires a per-site deletion token (returned on each ping, stored server-side only as a hash) so third parties cannot delete another site's telemetry row.<\/li>\n<li>Example-integration reference code renamed to a unique sentiolm_example_ prefix throughout.<\/li>\n<li>Admin screens now derive the REST base URL via rest_url(); fixed an unclosed output buffer in the license-update handler.<\/li>\n<li>Exhaustive follow-up audit across every shipped file: remaining inline onclick handlers replaced by a shared enqueued confirm helper, a declared sanitize_callback added to every REST route argument, and uniform unslash-plus-sanitize applied to every remaining request-variable read.<\/li>\n<\/ul>\n\n<h4>1.8.2 - 2026-06-18<\/h4>\n\n<ul>\n<li>First WordPress.org release, revised for the directory. Self-hosted plugin\/theme update-delivery \u2014 which served downloadable packages and fed WordPress native update checks for externally hosted plugins \u2014 has been completely removed: the public REST update endpoint, the \"Plugin Releases\" admin screen, the release-metadata database table, and all supporting code are deleted. This addresses the storefront\/update-delivery classification; the plugin no longer installs, updates, or distributes any code from outside WordPress.org.<\/li>\n<li>Sentio License Manager is now strictly a license-management plugin: it issues and validates license keys for WooCommerce products and tracks per-site activations via a REST API \u2014 the same scope as other licensing plugins in the directory (License Manager for WooCommerce, Digital License Manager). It does not deliver software updates.<\/li>\n<li>Unchanged: license issuance on WooCommerce purchase, per-site activation management, the license-validation REST API (activate\/validate\/deactivate), LMFWC and DLM migration tools, the REST API compatibility shim, and consent-gated anonymous telemetry.<\/li>\n<\/ul>","raw_excerpt":"Sell software licenses through WooCommerce. Customers activate by logging in with their store account \u2014 no license keys to copy or paste.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/332331","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=332331"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/jtconnelly1"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=332331"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=332331"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=332331"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=332331"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=332331"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=332331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}