{"id":357090,"date":"2026-09-17T18:19:13","date_gmt":"2026-09-17T18:19:13","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/master-toolkit-pro\/"},"modified":"2026-09-18T17:57:49","modified_gmt":"2026-09-18T17:57:49","slug":"omninox-site-toolkit","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/omninox-site-toolkit\/","author":23546790,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.9","stable_tag":"1.0.9","tested":"7.1.1","requires":"5.8","requires_php":"7.2","requires_plugins":null,"header_name":"Omninox Site Toolkit","header_author":"Net Innovix","header_description":"All-in-one performance, backup & restore, security, SEO, database cleanup and site health tools for WordPress maintenance and diagnostics.","assets_banners_color":"","last_updated":"2026-09-18 17:57:49","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/netinnovix.com\/plugins\/omninox-site-toolkit","header_author_uri":"https:\/\/netinnovix.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":79,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.7":{"tag":"1.0.7","author":"sobhitjadoun","date":"2026-09-17 18:57:02","revision":3700829},"1.0.8":{"tag":"1.0.8","author":"sobhitjadoun","date":"2026-09-17 19:53:21","revision":3700908},"1.0.9":{"tag":"1.0.9","author":"sobhitjadoun","date":"2026-09-18 17:57:49","revision":3702516}},"upgrade_notice":{"1.0.9":"<p>Progress bar indeterminate animation and UX enhancements, enhanced download nonce verification with fallback, and updated Pro integration support.<\/p>","1.0.8":"<p>UI\/UX redesign with premium light theme, updated brand identity, and WordPress 6.7+ early translation compatibility.<\/p>","1.0.7":"<p>WordPress.org review security fixes: safe title escaping for the_title filter, origin nonce verification on direct file downloads, and token user-binding checks.<\/p>","1.0.6":"<p>Major backup &amp; restore engine hardening: prevents destination WordPress crashes, protects recovery plugin activation across database replacement, prevents overwriting destination themes, adds atomic mutex locking, crash-safe DB\/file checkpointing, immutable rollback snapshots, and zip bomb safety checks.<\/p>","1.0.5":"<p>Backup engine refactoring, Free Level 1 Pro Gate integration, and packaging cleanups.<\/p>","1.0.4":"<p>Security hardening, WordPress.org compliance fixes, and asset enqueue optimization.<\/p>"},"ratings":[],"assets_icons":{"icon.svg":{"filename":"icon.svg","revision":3700841,"resolution":false,"location":"assets","locale":false}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.7","1.0.8","1.0.9"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Dashboard with site health score, module scores and quick actions.","2":"Website Health checks grouped by server, WordPress, PHP and filesystem.","3":"Security Center with hardening checks and audit details.","4":"Media Manager with conversion and compression status.","5":"Reports and recent activity history."}},"plugin_section":[],"plugin_tags":[151,4155,247,600,186],"plugin_category":[54,55,59],"plugin_contributors":[281340],"plugin_business_model":[],"class_list":["post-357090","plugin","type-plugin","status-publish","hentry","plugin_tags-backup","plugin_tags-migration","plugin_tags-performance","plugin_tags-security","plugin_tags-seo","plugin_category-security-and-spam-protection","plugin_category-seo-and-marketing","plugin_category-utilities-and-tools","plugin_contributors-sobhitjadoun","plugin_committers-sobhitjadoun"],"banners":[],"icons":{"svg":"https:\/\/ps.w.org\/omninox-site-toolkit\/assets\/icon.svg?rev=3700841","icon":"https:\/\/ps.w.org\/omninox-site-toolkit\/assets\/icon.svg?rev=3700841","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Omninox Site Toolkit is an all-in-one WordPress performance, backup &amp; restore, migration, security, SEO and maintenance plugin. It replaces a stack of single-purpose plugins with one modular toolkit for site health checks, database cleanup, diagnostics, optimization and reporting. Every module answers the same question in the same shape: what is wrong, how bad is it, and what happens if you click fix.<\/p>\n\n<p>Modules included:<\/p>\n\n<ul>\n<li>Complete Backup \u2014 Database export (.sql dump) and backup readiness diagnostics<\/li>\n<li>Website Health \u2014 WordPress environment, server limits, permissions and caching layers<\/li>\n<li>Performance Analyzer \u2014 TTFB, render-blocking assets, compression, CDN and plugin asset footprint<\/li>\n<li>Conflict Detector \u2014 duplicate plugin families and documented incompatible pairs<\/li>\n<li>Database Optimizer \u2014 revisions, transients, spam comments, and database cleanup<\/li>\n<li>Media Manager \u2014 unattached media audit, oversize scan, and 100 free WebP image conversions<\/li>\n<li>SEO Auditor \u2014 titles, meta descriptions, headings, canonicals, XML sitemap validator<\/li>\n<li>Accessibility Scanner \u2014 WCAG checks on rendered markup, contrast and alt tag diagnostics<\/li>\n<li>Security Center \u2014 core hardening checks, exposure checks, user enumeration protection<\/li>\n<li>Error Log Center \u2014 PHP error log viewer with de-duplication and severity filters<\/li>\n<li>Developer Tools \u2014 hooks, rewrite rules flush, transients purge, autoloaded options inventory<\/li>\n<li>Reports \u2014 On-demand HTML and CSV site audit exports<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin can connect to external 3rd-party services under specific conditions:<\/p>\n\n<ol>\n<li><strong>Net Innovix Licensing and Pricing Service<\/strong><\/li>\n<\/ol>\n\n<p>* <strong>Service Description:<\/strong> Net Innovix provides optional license activation, deactivation, periodic license status validation, and live pricing catalog retrieval for Omninox Pro upgrades.\n* <strong>When data is sent:<\/strong>\n  - When an administrator visits the License or Upgrade settings screen, the plugin fetches current Pro pricing plans via <code>GET \/api\/plugins\/catalog<\/code> (no personal or site data is transmitted).\n  - When an administrator enters and activates a Pro license key, the plugin connects to <code>POST \/api\/activate<\/code> and sends the submitted license key, site URL (<code>home_url()<\/code>), plugin slug, and plugin version.\n  - When an administrator deactivates a license key, the plugin connects to <code>POST \/api\/deactivate<\/code> and sends the license key, site URL, and plugin slug.\n  - Once daily via WP-Cron (or upon manual refresh), if a license key is active, the plugin connects to <code>POST \/api\/validate<\/code> and sends the license key, site URL, and plugin slug to verify active license status.\n* <strong>Service Provider &amp; Hosting:<\/strong> Provided by Net Innovix, hosted at <code>https:\/\/netinnovix.com\/api<\/code>.\n* <strong>Terms of Service:<\/strong> <a href=\"https:\/\/netinnovix.com\/terms\">Net Innovix Terms of Service<\/a>\n* <strong>Privacy Policy:<\/strong> <a href=\"https:\/\/netinnovix.com\/privacy\">Net Innovix Privacy Policy<\/a>\n* <strong>Optionality:<\/strong> 100% optional. The core Free plugin, all diagnostic modules, database cleanups, and export tools function fully without connecting to this service.<\/p>\n\n<ol>\n<li><strong>Administrator Webhook Notifications (Slack, Discord, Telegram)<\/strong><\/li>\n<\/ol>\n\n<p>* <strong>Service Description:<\/strong> Allows administrators to optionally route automated site health and security alert summaries to their private communication channels.\n* <strong>When data is sent:<\/strong> Sent only when an administrator explicitly enters a webhook endpoint URL in settings and an automated scheduled scan identifies health\/security issues or an admin triggers a test notification. Transmits the generated audit summary text to the configured URL.\n* <strong>Service Providers:<\/strong>\n  - Slack: <a href=\"https:\/\/slack.com\/terms-of-service\">Slack Terms<\/a> | <a href=\"https:\/\/slack.com\/privacy-policy\">Slack Privacy Policy<\/a>\n  - Discord: <a href=\"https:\/\/discord.com\/terms\">Discord Terms<\/a> | <a href=\"https:\/\/discord.com\/privacy\">Discord Privacy Policy<\/a>\n  - Telegram: <a href=\"https:\/\/telegram.org\/tos\">Telegram Terms<\/a> | <a href=\"https:\/\/telegram.org\/privacy\">Telegram Privacy Policy<\/a>\n* <strong>Optionality:<\/strong> 100% optional and disabled by default.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>omninox-site-toolkit\/<\/code> directory to <code>\/wp-content\/plugins\/<\/code> (or install via zip).<\/li>\n<li>Activate the plugin through the Plugins screen.<\/li>\n<li>Open Omninox Site Toolkit in the admin menu and run a full audit.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20the%20fixes%20touch%20my%20files%3F\"><h3>Do the fixes touch my files?<\/h3><\/dt>\n<dd><p>Some do. Image compression keeps a backup in the plugin storage directory within uploads before optimizing, and WebP conversion never replaces the source image in the free version. Always download a database backup before running database cleanups.<\/p><\/dd>\n<dt id=\"does%20it%20work%20without%20a%20licence%20key%3F\"><h3>Does it work without a licence key?<\/h3><\/dt>\n<dd><p>Yes. All core Free features, diagnostic modules, database cleanups, and HTML\/CSV exports are completely free and standalone under GPLv2+. No license key, trial period, or account registration is required to use the free plugin.<\/p><\/dd>\n<dt id=\"how%20many%20images%20can%20i%20convert%20for%20free%3F\"><h3>How many images can I convert for free?<\/h3><\/dt>\n<dd><p>The free plugin includes 100 free WebP image conversions. For unlimited WebP and AVIF conversions, in-place replacements, and database restoration, you can optionally install the separate Omninox Site Toolkit Pro add-on.<\/p><\/dd>\n<dt id=\"why%20did%20webp%20conversion%20report%20zero%20files%3F\"><h3>Why did WebP conversion report zero files?<\/h3><\/dt>\n<dd><p>Check the Image conversion support row at the top of the Media module. If it says \"No WebP support\", the server has neither Imagick nor a GD build with WebP, and conversion cannot run until the host enables one. Every other failure reports the specific reason in the result message rather than silently counting zero.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>Enhancement: Redesigned progress bar component with indeterminate state support, percentage counters, and improved status feedback.<\/li>\n<li>Fix: Enhanced download verification to support URL-encoded nonce queries and fallback authentication in decoupled environments.<\/li>\n<li>Compatibility: Improved Pro plugin path detection supporting custom folder structures and strict licensing validation.<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Feature: Complete UI\/UX redesign featuring a clean, responsive layout with updated SVG brand identity.<\/li>\n<li>Compatibility: Full WordPress 6.7+ early translation compatibility, deferring textdomain load to init hook and preventing doing_it_wrong notices.<\/li>\n<li>Enhancement: Optimized admin CSS footprint and streamlined theme variables.<\/li>\n<li>Fix: Added standalone printable audit report stylesheet (<code>report.css<\/code>).<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Security: Escaped post title output in the_title filter callback (<code>Highlighter::highlight_title<\/code>) using <code>esc_html()<\/code>, with search term highlighting applied strictly to escaped plain text and entity skipping (<code>&amp;[#a-zA-Z0-9]+;(*SKIP)(*FAIL)<\/code>).<\/li>\n<li>Security: Added origin nonce verification (<code>wp_verify_nonce( $nonce, 'omninox_download' )<\/code>) and capability authorization gates in <code>admin_post_download()<\/code>.<\/li>\n<li>Security: Added user ownership\/binding validation in <code>Security::redeem_token()<\/code> to prevent token cross-redemption.<\/li>\n<li>Feature: Added standardized <code>Security::generate_download_url()<\/code> helper to build nonce-protected download URLs.<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>Fix: Prevented destination site crashes during or immediately following database and file restoration.<\/li>\n<li>Fix: Preserved OmniNox Free and Pro recovery engine active in <code>active_plugins<\/code> across database replacement.<\/li>\n<li>Fix: Preserved destination theme throughout restore; deferred third-party source plugin and theme activation until post-restore validation.<\/li>\n<li>Fix: Protected OmniNox Free and Pro plugin directories from being overwritten or hot-swapped during active file deployment.<\/li>\n<li>Fix: Implemented atomic ownership-based restore mutex locking with periodic heartbeat lease renewal.<\/li>\n<li>Fix: Implemented crash-safe database statement checkpointing with exact byte offset boundaries.<\/li>\n<li>Fix: Implemented immutable file rollback copies ensuring resume operations never overwrite original pre-restore files.<\/li>\n<li>Fix: Implemented complete filesystem rollback with transaction replay for newly added and replaced files.<\/li>\n<li>Fix: Added preflight ZIP bomb and decompression safety limits (entry count, single entry ceiling, compression ratio, disk space margin).<\/li>\n<li>Fix: Guaranteed destination URL persistence (<code>siteurl<\/code> and <code>home<\/code>) across cross-site migrations.<\/li>\n<li>Fix: Added server-side active restore discovery REST endpoint (<code>\/restore\/active<\/code>) for recovery without relying solely on browser session storage.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Feature: Refactored Backup module architecture with clean Free Level 1 Pro Gate.<\/li>\n<li>Chore: Packaging cleanups and release zip distribution isolation.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Fix: Security hardening and asset enqueue optimization.<\/li>\n<li>Fix: WordPress.org directory compliance guidelines adherence.<\/li>\n<\/ul>","raw_excerpt":"All-in-one performance, backup &amp; restore, migration, security, SEO, database cleanup and site health tools for WordPress maintenance and diagnosti &hellip;","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/357090","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=357090"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sobhitjadoun"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=357090"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=357090"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=357090"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=357090"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=357090"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=357090"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}