{"id":349670,"date":"2026-08-15T13:18:48","date_gmt":"2026-08-15T13:18:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/impact-sentinel-addon-monitor-risk-scanner\/"},"modified":"2026-08-15T13:18:27","modified_gmt":"2026-08-15T13:18:27","slug":"slb-impact-sentinel","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/slb-impact-sentinel\/","author":23530275,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.2.5","stable_tag":"2.2.5","tested":"7.0.4","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"SLB-Impact Sentinel - Addon Monitor & Risk Scanner","header_author":"Spartan Logic Builders","header_description":"Monitor WordPress plugins and themes for version changes, scan changelogs for risk, and use Claude AI to assess impact on your custom plugins.","assets_banners_color":"05020c","last_updated":"2026-08-15 13:18:27","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/spartanlogicbuilders.com\/product\/impact-sentinel-pro\/","header_author_uri":"https:\/\/spartanlogicbuilders.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":20,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.2.5":{"tag":"2.2.5","author":"spartanlogicbuilders","date":"2026-08-15 13:18:27"}},"upgrade_notice":{"2.2.0":"<p>Adds a consent card for external requests and fixes database migration stability. Safe to update.<\/p>","1.9.2":"<p>Adds the Schedule tab in Settings. No database changes. Safe to update.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3648633,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3648633,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3648633,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3648633,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.2.5"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3648633,"resolution":"1","location":"assets","locale":"","width":2172,"height":836},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3648633,"resolution":"2","location":"assets","locale":"","width":2180,"height":870},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3648633,"resolution":"3","location":"assets","locale":"","width":2128,"height":1140},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3648633,"resolution":"4","location":"assets","locale":"","width":1460,"height":704},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3648633,"resolution":"5","location":"assets","locale":"","width":2134,"height":978}},"screenshots":{"1":"Configuration \u2014 onboarding wizard with Quick Start and Guided Setup options","2":"Dashboard \u2014 active high-urgency alert, recent activity panel, and pending updates","3":"Discovery \u2014 plugin inventory with tier and ownership classification","4":"Settings \u2014 schedule overview with scan frequency and timing configuration","5":"Alerts \u2014 alert card with full AI impact assessment and keyword highlighting"}},"plugin_section":[],"plugin_tags":[1110,13434,265442,600,2550],"plugin_category":[54],"plugin_contributors":[273127],"plugin_business_model":[],"class_list":["post-349670","plugin","type-plugin","status-publish","hentry","plugin_tags-alerts","plugin_tags-changelog","plugin_tags-plugin-monitor","plugin_tags-security","plugin_tags-updates","plugin_category-security-and-spam-protection","plugin_contributors-spartanlogicbuilders","plugin_committers-spartanlogicbuilders"],"banners":{"banner":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/banner-772x250.png?rev=3648633","banner_2x":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/banner-1544x500.png?rev=3648633","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/icon-128x128.png?rev=3648633","icon_2x":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/icon-256x256.png?rev=3648633","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/screenshot-1.png?rev=3648633","caption":"Configuration \u2014 onboarding wizard with Quick Start and Guided Setup options"},{"src":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/screenshot-2.png?rev=3648633","caption":"Dashboard \u2014 active high-urgency alert, recent activity panel, and pending updates"},{"src":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/screenshot-3.png?rev=3648633","caption":"Discovery \u2014 plugin inventory with tier and ownership classification"},{"src":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/screenshot-4.png?rev=3648633","caption":"Settings \u2014 schedule overview with scan frequency and timing configuration"},{"src":"https:\/\/ps.w.org\/slb-impact-sentinel\/assets\/screenshot-5.png?rev=3648633","caption":"Alerts \u2014 alert card with full AI impact assessment and keyword highlighting"}],"raw_content":"<!--section=description-->\n<p>Impact Sentinel keeps watch over your WordPress plugins so you do not have to. When a plugin updates, it fetches the changelog, scores it against a risk keyword list, and sends you an email alert \u2014 before you decide whether to apply or roll back the update.<\/p>\n\n<p><strong>Know what changed before it breaks anything.<\/strong><\/p>\n\n<p>Most WordPress sites apply plugin updates without reading what changed. Impact Sentinel reads the changelog for you, flags risky updates (breaking changes, deprecated APIs, security patches), and gives you the information to make an informed decision \u2014 not just a blind click on \"Update All.\"<\/p>\n\n<p><strong>How it works<\/strong><\/p>\n\n<ol>\n<li>Impact Sentinel runs a scan on your installed plugins \u2014 either triggered manually from the dashboard or automatically on a schedule (Pro).<\/li>\n<li>When a version change is detected, it fetches the changelog from the plugin's readme, the WP.org API, or a configured URL.<\/li>\n<li>The changelog is scored against a tiered risk keyword list \u2014 security terms, breaking change indicators, deprecations, and more.<\/li>\n<li>If the risk score meets your configured threshold, an email alert is sent to your team.<\/li>\n<\/ol>\n\n<p>No AI required. No external account required. Changelog scanning and email alerts work out of the box.<\/p>\n\n<h4>Plugin Discovery &amp; Inventory<\/h4>\n\n<p>On first run, Impact Sentinel scans all installed plugins and builds a persistent inventory. Classify each plugin by tier \u2014 Self-Managed (your code), WP.org (community), or Premium (paid third-party) \u2014 and mark which ones you own or actively maintain. Classification context appears on every alert so your team knows what they are looking at.<\/p>\n\n<p>Plugins can declare their dependencies using the standard WordPress Requires Plugins header. Impact Sentinel reads these declarations automatically and seeds the dependency map without any manual input.<\/p>\n\n<h4>Changelog Scanning<\/h4>\n\n<p>Impact Sentinel resolves changelogs through six sources in priority order:<\/p>\n\n<ul>\n<li>Manual paste \u2014 for plugins behind member portals or login walls, paste the changelog text directly into the alert card<\/li>\n<li>Local readme.txt or CHANGELOG.md \u2014 reads the file on disk before making any network request<\/li>\n<li>WP.org API \u2014 the structured changelog endpoint, not a scrape<\/li>\n<li>Saved URL \u2014 a specific changelog URL you have configured for that plugin<\/li>\n<li>URL probe \u2014 automatic HEAD requests to common changelog paths (\/changelog\/, \/release-notes\/)<\/li>\n<li>Fallback label \u2014 when no text is available, the alert is created with a note to check manually<\/li>\n<\/ul>\n\n<h4>Risk Keyword Scoring<\/h4>\n\n<p>Changelogs are scored against a tiered keyword list. The high tier includes security-focused terms: CVE, XSS, SQL injection, RCE, authentication bypass, privilege escalation, unauthenticated, vulnerability, and more. Medium and low tiers cover breaking changes, deprecations, and general notices.<\/p>\n\n<p>The keyword list is fully customizable in Settings \u2014 add your own global terms, or set per-plugin overrides with Impact Sentinel Pro.<\/p>\n\n<h4>Email Alerts<\/h4>\n\n<p>When a scan finds a version change and the changelog scores above your configured threshold, an alert is sent to your recipient list. Set the threshold to Critical only, High and above, Medium and above (recommended), or All. Alerts include the plugin name, version arrow, matched keywords, and a changelog excerpt.<\/p>\n\n<h4>Relationship Map &amp; Dependency Matrix<\/h4>\n\n<p>Map which plugins your custom code depends on. The dependency matrix shows which of your owned plugins would be affected if a given third-party plugin introduced a breaking change. Auto-detection scans your plugin source files and proposes likely dependencies. All relationships can be confirmed, dismissed, or added manually.<\/p>\n\n<h4>Work Queue<\/h4>\n\n<p>When an alert is created, a corresponding work queue item is added for your team. Resolve items with notes, set a default assignee, and track what was done about each update.<\/p>\n\n<h4>Pending Updates Panel<\/h4>\n\n<p>The dashboard shows all WordPress-tracked pending updates for your monitored plugins before they are applied \u2014 with version arrows and classification badges so you know which updates need a closer look before you click Update.<\/p>\n\n<h4>Pro Features<\/h4>\n\n<p>Impact Sentinel Pro adds automated nightly scanning, Stage 1 and Stage 2 Claude AI impact analysis, Code Graph (maps which of your functions call into updated dependencies), Conflict Scanner, WP Core monitoring, file integrity monitoring, WPScan CVE vulnerability feed, weekly digest emails, queue history, per-plugin keyword overrides, AI model selection, config export \/ import, and Safe Update pre-update risk analysis (a risk verdict badge on the Plugins page, with the option to block or warn before auto-updates apply).<\/p>\n\n<p>Learn more at spartanlogicbuilders.com\/impact-sentinel\/<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li>Plugin discovery and inventory \u2014 classify all installed plugins by tier and ownership<\/li>\n<li>Version change detection with configurable minimum bump threshold<\/li>\n<li>Changelog fetch from six sources including local files and WP.org API<\/li>\n<li>Risk keyword scoring \u2014 high \/ medium \/ low tiers, fully customizable<\/li>\n<li>Email alerts with configurable threshold and multiple recipients<\/li>\n<li>Manual changelog paste-in for premium plugins behind member portals<\/li>\n<li>Relationship map and dependency matrix<\/li>\n<li>Work queue \u2014 resolve and track alert action items<\/li>\n<li>Pending updates panel on the dashboard<\/li>\n<li>Scan history with type badges, duration, alert count, and site health check<\/li>\n<li>Manual scan trigger from the dashboard<\/li>\n<li>API key via wp-config.php constant or plugin settings UI (AES-256-GCM encrypted)<\/li>\n<\/ul>\n\n<h4>Requirements<\/h4>\n\n<p>No external account or API key is required to use Impact Sentinel.<\/p>\n\n<p>Email alerts use WordPress's built-in wp_mail function \u2014 delivered through whatever mail configuration your site already has.<\/p>\n\n<p>AI features (Stage 1 and Stage 2 Claude impact analysis) require an Anthropic API key and are available in Impact Sentinel Pro only.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to the following external services:<\/p>\n\n<p><strong>WordPress.org Plugin API<\/strong> (Free)\nFetches structured changelog text for plugins listed on WordPress.org.\nURL: https:\/\/api.wordpress.org\/plugins\/info\/1.0\/{slug}.json\nData sent: Plugin slug only. No visitor or site owner data is transmitted.\nPrivacy policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<p><strong>Anthropic API<\/strong> (optional \u2014 requires API key)\nUsed for AI-powered changelog impact analysis (Stage 1 and Stage 2).\nURL: https:\/\/api.anthropic.com\/v1\/messages\nData sent: Changelog text and plugin source file excerpts. No visitor data is transmitted.\nPrivacy policy: https:\/\/www.anthropic.com\/privacy<\/p>\n\n<p><strong>WPScan API<\/strong> (optional \u2014 requires API key)\nChecks installed plugins against known CVE vulnerability records.\nURL: https:\/\/wpscan.com\/api\/v3\/\nData sent: Plugin slugs and version numbers. No visitor or site owner data is transmitted.\nPrivacy policy: https:\/\/automattic.com\/privacy\/<\/p>\n\n<h3>Privacy<\/h3>\n\n<p><strong>No data leaves your site by default.<\/strong><\/p>\n\n<p>All plugin data, scan results, alerts, and queue items are stored locally in your WordPress database. Impact Sentinel does not transmit analytics, telemetry, or usage data to Spartan Logic Builders or any third party.<\/p>\n\n<p><strong>Changelog fetching (optional network requests):<\/strong><\/p>\n\n<p>When Impact Sentinel fetches a changelog, it makes an outbound HTTPS request to:\n* api.wordpress.org \u2014 the WordPress.org plugin info API (only for plugins with a WP.org listing)\n* A URL you have configured for a specific plugin\n* A probe of common changelog paths on the plugin's declared Plugin URI<\/p>\n\n<p>These requests are made by the server, not the visitor's browser. No visitor data is transmitted.<\/p>\n\n<p><strong>If you enable AI features (optional):<\/strong><\/p>\n\n<p>AI analysis transmits changelog text and plugin source file excerpts to the Anthropic API (api.anthropic.com) over HTTPS. No visitor data is ever transmitted. Refer to Anthropic's privacy policy at https:\/\/www.anthropic.com\/privacy for details.<\/p>\n\n<p><strong>WPScan vulnerability feed (optional):<\/strong><\/p>\n\n<p>Requires a WPScan API key. Plugin slugs and version numbers are transmitted to wpscan.com to check for known CVEs. No visitor or site owner data is transmitted. WPScan is operated by Automattic \u2014 refer to their privacy policy at https:\/\/automattic.com\/privacy\/ for details.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/slb-impact-sentinel\/<\/code>, or install through the WordPress Plugins screen directly.<\/li>\n<li>Activate the plugin through the Plugins screen.<\/li>\n<li>Navigate to Impact Sentinel in your WordPress admin sidebar.<\/li>\n<li>Complete Required Setup \u2014 set your timezone, email recipients, and alert threshold.<\/li>\n<li>Run Discovery to build your plugin inventory.<\/li>\n<li>Classify your plugins by tier and mark the ones you own or maintain.<\/li>\n<li>Run your first scan manually from the Dashboard.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20api%20key%20or%20external%20account%3F\"><h3>Do I need an API key or external account?<\/h3><\/dt>\n<dd><p>No. Plugin discovery, changelog scanning, keyword scoring, email alerts, and the relationship map all work with no external account or API key required.<\/p>\n\n<p>An Anthropic API key is only needed for the AI-powered impact analysis features, which are part of Impact Sentinel Pro.<\/p><\/dd>\n<dt id=\"how%20does%20it%20fetch%20changelogs%20for%20premium%20plugins%3F\"><h3>How does it fetch changelogs for premium plugins?<\/h3><\/dt>\n<dd><p>For plugins not on WP.org, Impact Sentinel attempts a URL probe against common changelog paths and lets you save a direct URL per plugin. For plugins whose changelogs are behind a member portal or login wall, you can paste the changelog text directly into the alert card \u2014 it is stored and used for all future analysis of that version.<\/p><\/dd>\n<dt id=\"does%20it%20work%20for%20themes%20as%20well%20as%20plugins%3F\"><h3>Does it work for themes as well as plugins?<\/h3><\/dt>\n<dd><p>Yes. Discovery includes installed themes. Version change detection, changelog fetching, and alerts work for themes the same way they do for plugins.<\/p><\/dd>\n<dt id=\"what%20does%20the%20risk%20keyword%20scan%20actually%20do%3F\"><h3>What does the risk keyword scan actually do?<\/h3><\/dt>\n<dd><p>It reads the changelog text for the updated version and looks for words and phrases in a tiered list. High-tier matches (CVE, authentication bypass, remote code execution, etc.) generate a high-urgency alert. Medium-tier matches (breaking change, deprecated, removed) generate medium-urgency. Low-tier matches (performance, updated, minor) generate low-urgency. You configure which threshold triggers an email.<\/p><\/dd>\n<dt id=\"how%20is%20the%20dependency%20map%20built%3F\"><h3>How is the dependency map built?<\/h3><\/dt>\n<dd><p>You can add dependencies manually on the Relationships tab, use the auto-detect tool to scan your plugin source files for likely dependencies, or let Impact Sentinel read the standard Requires Plugins header if the plugin declares its dependencies there.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20wordpress%20site%3F\"><h3>Will it slow down my WordPress site?<\/h3><\/dt>\n<dd><p>No. All scanning happens in the background via WP-Cron (scheduled) or on demand (manual trigger). No code runs on the front end of your site.<\/p><\/dd>\n<dt id=\"is%20there%20a%20pro%20version%3F\"><h3>Is there a Pro version?<\/h3><\/dt>\n<dd><p>Yes. Impact Sentinel Pro adds automated nightly scheduling, Claude AI impact analysis, Code Graph, Conflict Scanner, WP Core monitoring, file integrity monitoring, WPScan CVE feed, weekly digest, and more. Available at spartanlogicbuilders.com\/impact-sentinel\/<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.2.5<\/h4>\n\n<ul>\n<li>Removed the last locked\/restricted-functionality signal flagged under Guideline 5 (trialware): the full AI model list and saved-model lookup were still present as dead code in the Free build's Claude analyzer class, even though the active code path already hardcoded Claude Haiku and the Settings UI already presented model choice as a Pro feature. That support code (and the equivalent OpenAI\/Gemini provider-key and model-list code) is now excluded from the Free build entirely.<\/li>\n<li>Removed an unreachable Pro upgrade-installer method left as a dead stub in the Free build (its AJAX hook was already excluded from Free, but the method itself, including the string \"Pro feature\", still shipped)<\/li>\n<li>Removed a Pro-only admin view (owned-plugin file access, used only for Code Graph) that shipped in the Free build as an inert single-line stub file, invisible to normal navigation but still present on disk \u2014 a gap in the Free build's automated orphan-file removal that only caught the more common two-line boilerplate pattern; the build script's check is now more robust<\/li>\n<li>Corrected the readme.txt privacy disclosures to remove a data-collection entry describing a Pro-only upgrade flow that has no functioning code path in this Free build<\/li>\n<\/ul>\n\n<h4>2.2.4<\/h4>\n\n<ul>\n<li>Removed the Safe Update pre-update analyzer and plugins.php risk badge from the Free build entirely \u2014 this Pro-only feature previously shipped as two unbootstrapped class files with no way to run, which is itself a locked\/restricted-functionality signal under Guideline 5; corrected the readme changelog and in-app Free vs Pro comparison to consistently describe it as a Pro feature<\/li>\n<li>Replaced remaining direct fopen()\/fread()\/file_get_contents() calls on local files with the WP_Filesystem API across Discovery, changelog fetching, and dependency auto-detection, including one instance still flagged after the 2.2.3 fopen()\/fread() swap<\/li>\n<li>Fixed a PHP fatal parse error in the Settings screen license tab (Pro build only; not present in the Free build, which strips the affected code) caused by a stray else with no matching if<\/li>\n<\/ul>\n\n<h4>2.2.3<\/h4>\n\n<ul>\n<li>Removed remaining locked\/restricted-functionality signals flagged under Guideline 5 (trialware): the AI model\/provider selection form fields are now correctly stripped from the Free build's save handler (previously reachable even though the Settings UI already hid them), and 14 Pro-only class\/view files that shipped as unbootstrapped stubs are now excluded from the Free package entirely<\/li>\n<li>Reworded Free-tier AI model messaging to describe what Impact Sentinel Pro adds as a separate product, rather than describing Free functionality as \"locked\"<\/li>\n<li>Replaced direct file_get_contents() calls on local plugin files with fopen()\/fread() across Discovery, changelog fetching, and dependency auto-detection<\/li>\n<li>Corrected an invalid WPScan privacy policy URL in this readme (wpscan.com\/privacy returns 404; WPScan is Automattic-owned, now points to automattic.com\/privacy)<\/li>\n<li>Activation-triggered background source\/changelog resolution now correctly respects the external-requests consent setting before making any outbound request<\/li>\n<li>Version number synchronized across plugin header, version constant, and this readme (previously drifted out of sync between releases)<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Added consent card \u2014 all external network requests (WP.org API, changelog URL probes, AI analysis) are now gated behind a one-time admin consent prompt on first use<\/li>\n<li>Extracted all inline scripts and styles to enqueued asset files for improved Content Security Policy compatibility<\/li>\n<li>Fixed database migration stability \u2014 corrected option read and value serialization in upgrade routines<\/li>\n<li>Plugin renamed to SLB-Impact Sentinel for WordPress.org submission; text domain updated to slb-impact-sentinel<\/li>\n<\/ul>\n\n<h4>2.1.6<\/h4>\n\n<ul>\n<li>Renamed database columns <code>claude_summary<\/code> and <code>claude_stage<\/code> to <code>ai_summary<\/code> and <code>ai_stage<\/code> (provider-agnostic names; migration runs automatically)<\/li>\n<li>Fixed Google Fonts external import in Help &amp; About page (replaced with system font stack)<\/li>\n<li>Fixed bare function names to use <code>imsn_<\/code> prefix throughout<\/li>\n<\/ul>\n\n<h4>2.1.5<\/h4>\n\n<ul>\n<li>Fixed update badge JavaScript selector \u2014 badge now reliably appears on the WordPress plugins page<\/li>\n<\/ul>\n\n<h4>2.1.4<\/h4>\n\n<ul>\n<li>Fixed fatal error on plugins.php when WordPress passes null to auto-update filter<\/li>\n<li>Fixed all Settings form fields not saving after v2.1.1 prefix rename<\/li>\n<li>AI analysis tab restructured \u2014 provider selector now first, LLM-agnostic labels, updated model lists<\/li>\n<\/ul>\n\n<h4>2.1.3<\/h4>\n\n<ul>\n<li>Fixed tab navigation broken across all admin views after v2.1.1 prefix rename<\/li>\n<\/ul>\n\n<h4>2.1.2<\/h4>\n\n<ul>\n<li>Fixed API key not saving after v2.1.1 prefix rename (JS\/PHP field name mismatch)<\/li>\n<\/ul>\n\n<h4>2.1.1<\/h4>\n\n<ul>\n<li>Internal prefix rename for WordPress.org compliance \u2014 no functional changes<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Added Safe Update: Pre-Update Intelligence \u2014 risk verdict badge on plugins.php, blocks or warns before auto-updates based on changelog analysis (Pro)<\/li>\n<li>Multi-provider AI support \u2014 Anthropic, OpenAI GPT-4o, Google Gemini selectable in Settings (Pro)<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Visual Dependency Map \u2014 SVG force-directed graph of plugin relationships (Pro)<\/li>\n<li>WordPress Admin Dashboard Widget \u2014 last scan, open alerts, pending updates<\/li>\n<li>Conflict Scanner \u2014 detects hook collisions and namespace conflicts between any two plugins (Pro)<\/li>\n<li>Code Graph split into Impact Analysis and Conflict Scanner sub-tabs<\/li>\n<\/ul>\n\n<h4>1.9.2<\/h4>\n\n<ul>\n<li>Added Schedule tab in Settings \u2014 consolidated run time, scan frequency, and a live overview of all seven background jobs and their next scheduled run<\/li>\n<li>Completed Free\/Pro tagging pass across all PHP classes, templates, and JavaScript<\/li>\n<\/ul>\n\n<h4>1.9.1<\/h4>\n\n<ul>\n<li>Security hardening: path traversal fix in plugin access verification, status allowlist on alert update, uncast ID echoes corrected in queue view, unguarded wp_kses corrected in scan history<\/li>\n<li>Fixed wrong API key constant reference (LF_ \u2192 PS_) in settings template<\/li>\n<li>Applied Free\/Pro build markers across admin views, cron class, notifier, alert engine, data port, and main plugin file<\/li>\n<\/ul>\n\n<h4>1.9.0<\/h4>\n\n<p>Initial public release.<\/p>\n\n<ul>\n<li>Plugin discovery and inventory with tier and ownership classification<\/li>\n<li>Version change detection with configurable bump threshold<\/li>\n<li>Six-source changelog pipeline including Update Interceptor for zip installs<\/li>\n<li>Tiered risk keyword scoring with security-focused defaults<\/li>\n<li>Email alerts with configurable threshold and recipients<\/li>\n<li>Manual changelog paste-in for member-portal plugins<\/li>\n<li>Relationship map, dependency matrix, and auto-detection<\/li>\n<li>Work queue with resolve, dismiss, and default assignee<\/li>\n<li>Pending updates panel on dashboard<\/li>\n<li>Scan history with site health check column<\/li>\n<li>Manual scan trigger<\/li>\n<li>WP event hooks \u2014 scan fires automatically on plugin update, activation, auto-update, and recovery mode<\/li>\n<\/ul>","raw_excerpt":"Monitor WordPress plugins for updates, scan changelogs for risk keywords, and get email alerts before a bad update affects your site.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/349670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=349670"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/spartanlogicbuilders"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=349670"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=349670"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=349670"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=349670"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=349670"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=349670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}