{"id":359870,"date":"2026-08-28T07:04:19","date_gmt":"2026-08-28T07:04:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/luketom-site-guard\/"},"modified":"2026-08-28T07:04:04","modified_gmt":"2026-08-28T07:04:04","slug":"luketom-compromise-review","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/luketom-compromise-review\/","author":11850598,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.18.3","stable_tag":"1.18.3","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Luketom Compromise Review","header_author":"LukeTom","header_description":"Reviews WordPress compromise indicators and permits changes only after confirmation. Includes verified quarantine restore, reversible inactive-theme removal and restorable .htaccess repair.","assets_banners_color":"453838","last_updated":"2026-08-28 07:04:04","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.luketom.com\/","rating":0,"author_block_rating":0,"active_installs":10,"downloads":52,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"1.18.3":{"tag":"1.18.3","author":"lukehutton","date":"2026-08-28 07:04:04","revision":3669937}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3669955,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3669955,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3669955,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3669955,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.18.3"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[278011,1184,193334,6464,600],"plugin_category":[54],"plugin_contributors":[278012],"plugin_business_model":[],"class_list":["post-359870","plugin","type-plugin","status-publish","hentry","plugin_tags-incident-response","plugin_tags-malware","plugin_tags-quarantine","plugin_tags-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-lukehutton","plugin_committers-lukehutton"],"banners":{"banner":"https:\/\/ps.w.org\/luketom-compromise-review\/assets\/banner-772x250.png?rev=3669955","banner_2x":"https:\/\/ps.w.org\/luketom-compromise-review\/assets\/banner-1544x500.png?rev=3669955","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/luketom-compromise-review\/assets\/icon-128x128.png?rev=3669955","icon_2x":"https:\/\/ps.w.org\/luketom-compromise-review\/assets\/icon-256x256.png?rev=3669955","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Luketom Compromise Review detects the known August 2026 incident filenames and the contact-page gambling redirect pattern, plus PHP in uploads, multi-signal webshell code, gambling content in posts and administrators outside an explicit allowlist.<\/p>\n\n<p>Features:<\/p>\n\n<ul>\n<li>One clearly labelled full manual security scan with safe 50,000-file continuation batches until every eligible file has been checked.<\/li>\n<li>Daily scheduled quick scan with optional, administrator-enabled email alerts.<\/li>\n<li>Lightweight four-hour monitoring for changes to .htaccess, wp-config.php and key WordPress bootstrap files.<\/li>\n<li>Protected, fingerprinted recovery copy of the last explicitly approved .htaccess, with a verified pre-restore rollback copy.<\/li>\n<li>Evidence-preserving quarantine only after independent confirmation and a fresh matching fingerprint.<\/li>\n<li>One-click verified restore for current and legacy quarantine records, with overwrite protection.<\/li>\n<li>Targeted .htaccess repair with a verified restorable backup and protection against overwriting newer rules.<\/li>\n<li>Reversible removal of individually selected or bulk-selected inactive themes after a fresh eligibility check.<\/li>\n<li>Administrator allowlist and WordPress file-editor capability blocking.<\/li>\n<li>Configurable same-site URL\/path for the page where a known injection was observed and must be verified after cleanup.<\/li>\n<li>No automatic administrator deletion and no automatic removal of ambiguous files. A protected, manually confirmed action is available for suspicious administrators.<\/li>\n<\/ul>\n\n<p>This plugin cannot protect against a compromised hosting control panel, SFTP account or server-level attacker. Rotate credentials and use hosting-level monitoring as well.<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>Compromise Review does not send telemetry and does not contact luketom or any other third-party service. Important-file monitoring and malware scans run locally. Live-page verification requests only the same-site URL selected by the administrator. Email alerts are disabled on a fresh installation until an administrator enables them and controls the recipient list.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload and activate the plugin.<\/li>\n<li>Open Compromise Review in WordPress admin.<\/li>\n<li>Save the approved administrator list.<\/li>\n<li>Run the full security scan and review every finding.<\/li>\n<li>Use repair or quarantine only for confirmed high-confidence findings.<\/li>\n<\/ol>\n\n<!--section=changelog-->\n<h4>1.18.3<\/h4>\n\n<ul>\n<li>Distinguish verified LiteSpeed-managed .htaccess changes from unexplained important-file changes.<\/li>\n<li>Show expected LiteSpeed-only changes as calm informational notices instead of red security warnings.<\/li>\n<li>Require the approved non-LiteSpeed rules to remain byte-for-byte unchanged and reject suspicious cache-block directives before applying the informational classification.<\/li>\n<li>Keep administrator approval explicit and suppress urgent change emails only for verified expected LiteSpeed changes.<\/li>\n<\/ul>\n\n<h4>1.18.2<\/h4>\n\n<ul>\n<li>Document the intentional use of LiteSpeed Cache and WP Super Cache third-party purge hooks for WordPress coding-standard checks.<\/li>\n<\/ul>\n\n<h4>1.18.1<\/h4>\n\n<ul>\n<li>Rename the plugin and directory slug to Luketom Compromise Review to provide a distinctive WordPress.org identity.<\/li>\n<li>Replace short global, option, cron, nonce and asset prefixes with the unique luketom_cr prefix.<\/li>\n<li>Migrate existing Site Guard settings, scan history, approved administrators, integrity records and learned decisions without deleting rollback data.<\/li>\n<li>Retain verified restoration support for quarantine records and inactive themes created by versions up to 1.18.0.<\/li>\n<li>Correct the WordPress.org contributor username.<\/li>\n<\/ul>\n\n<h4>1.18.0<\/h4>\n\n<ul>\n<li>Keep exact rewrite evidence actionable after its confirmed gambling payload has already been quarantined, including existing 1.17.1 records.<\/li>\n<li>Detect the Babeltoto payload variant shown in the Mifsuds incident.<\/li>\n<li>Store a protected, fingerprinted recovery copy only after an administrator explicitly approves .htaccess or Compromise Review verifies a repair.<\/li>\n<li>Add an explicit one-click recovery action that first preserves the current .htaccess as a separate verified rollback copy.<\/li>\n<\/ul>\n\n<h4>1.17.2<\/h4>\n\n<ul>\n<li>Preserve exact rewrite evidence when a confirmed gambling payload is quarantined.<\/li>\n<li>Revalidate the fingerprinted protected copy so its matching .htaccess rule remains a confirmed, repairable finding after the live payload file has been moved.<\/li>\n<li>Support existing 1.17.1 quarantine records by verifying their target path, stored fingerprint and payload contents before permitting repair.<\/li>\n<li>Detect the Babeltoto variant shown in the Mifsuds incident.<\/li>\n<\/ul>\n\n<h4>1.17.1<\/h4>\n\n<ul>\n<li>Restore individual and bulk inactive-theme removal.<\/li>\n<li>Revalidate every selected theme immediately before removal and keep active, parent, child and multisite themes protected.<\/li>\n<li>Store every removed theme as a fingerprinted, non-executable restore copy instead of permanently deleting it.<\/li>\n<li>Add one-click verified theme restoration without activating the restored theme or overwriting an existing directory.<\/li>\n<\/ul>\n\n<h4>1.17.0<\/h4>\n\n<ul>\n<li>Require independent evidence and a fresh exact fingerprint before quarantine or .htaccess repair.<\/li>\n<li>Treat incident-associated filenames and generic code signatures as review-only, never as automatic removal evidence.<\/li>\n<li>Add verified one-click restore for new and existing quarantine records and restorable .htaccess repair backups.<\/li>\n<li>Refuse restores that would overwrite an existing file or .htaccess rules changed after repair.<\/li>\n<li>Disable permanent theme deletion and bulk malicious classification inside Compromise Review.<\/li>\n<li>Keep a 50-entry repair, quarantine and restore action history.<\/li>\n<\/ul>\n\n<h4>1.16.5<\/h4>\n\n<ul>\n<li>Allow the strict clean tick when an optional affected page returns an HTTP error such as 404.<\/li>\n<li>Continue displaying the affected-page error for configuration review without treating it as evidence of infection.<\/li>\n<li>Withhold the clean tick only when live-page verification actually detects the known malicious payload.<\/li>\n<\/ul>\n\n<h4>1.16.4<\/h4>\n\n<ul>\n<li>Replace the number 5 in the green Remember step with a tick only when every strict clean condition is satisfied.<\/li>\n<li>Keep the numbered 5 whenever scan batches, warnings, unapproved administrators, monitored files or important-file alerts remain.<\/li>\n<li>Use the journey marker itself as the clean affirmation instead of adding a separate completion panel.<\/li>\n<\/ul>\n\n<h4>1.16.3<\/h4>\n\n<ul>\n<li>Display a clear files-and-database backup requirement beside the full security scan.<\/li>\n<li>Require an explicit backup confirmation before the full scan begins.<\/li>\n<li>Explain that scanning is read-only while later repair, quarantine and removal controls can change the site.<\/li>\n<\/ul>\n\n<h4>1.16.2<\/h4>\n\n<ul>\n<li>Add a prominent green tick confirmation only when a full scan has completed with no unresolved security findings.<\/li>\n<li>Require all administrators to be approved, all scan batches to be complete, no uncertain monitored files and no outstanding important-file alerts.<\/li>\n<li>Suppress clean confirmation when the most recent affected-page check reported infection or an HTTP error.<\/li>\n<\/ul>\n\n<h4>1.16.1<\/h4>\n\n<ul>\n<li>Base the five-step journey indicator only on unfinished scan batches and unresolved security findings.<\/li>\n<li>Stop protected themes and monitored files from incorrectly holding the interface on Step 3.<\/li>\n<li>Keep Step 2 current while additional 50,000-file batches remain, then mark the completed clean journey correctly.<\/li>\n<\/ul>\n\n<h4>1.16.0<\/h4>\n\n<ul>\n<li>Count eligible files beyond the first 50,000 and display the exact number not yet scanned.<\/li>\n<li>Add Scan next 50,000 files so large sites can progress through the full file set in controlled batches.<\/li>\n<li>Retain and combine findings from completed batches until the full scan is finished.<\/li>\n<li>Restore the WordPress administrator checker as a visible Step 1 panel with account and approval counts.<\/li>\n<li>Keep unapproved administrators in Step 3 with separate approve and delete controls.<\/li>\n<\/ul>\n\n<h4>1.15.1<\/h4>\n\n<ul>\n<li>Detect installed child themes and protect them from individual and bulk automatic removal, even when inactive.<\/li>\n<li>Recheck child-theme status on the server so removal cannot be triggered from an older scan result.<\/li>\n<li>Correct stored older findings while rendering so child-theme removal controls disappear immediately after updating.<\/li>\n<\/ul>\n\n<h4>1.15.0<\/h4>\n\n<ul>\n<li>Replace the overlapping first and fuller scan choices with one clearly labelled Full security scan.<\/li>\n<li>Distinguish full-scan and quick-check coverage, show the actual safety limit and stop scheduled checks from overwriting the latest manual scan.<\/li>\n<li>Fix file counting at the 12,000 and 50,000 safety limits.<\/li>\n<li>Make the action indicator a fixed, immediately painted progress panel that remains visible from any step.<\/li>\n<li>Stop cache clearing from starting an unrelated filesystem scan and report which available cache layers were cleared.<\/li>\n<li>Make the affected-page setting optional and remove site-specific example paths and default URLs.<\/li>\n<li>Simplify Step 4 to one confirmed-incident bulk repair and show affected-page rechecking only when a page is configured.<\/li>\n<li>Rename stale cleanup and learning labels so each result describes the action that actually ran.<\/li>\n<\/ul>\n\n<h4>1.14.2<\/h4>\n\n<ul>\n<li>Return administrators to the same findings area after approvals, deletions, repairs and other actions reload the page.<\/li>\n<li>Prefer the exact finding row when it still exists and fall back to the previous scroll position when an item was removed.<\/li>\n<\/ul>\n\n<h4>1.14.1<\/h4>\n\n<ul>\n<li>Use the WordPress filesystem API for repairs, evidence backups and quarantine operations.<\/li>\n<li>Store new quarantine evidence in the WordPress uploads area instead of the content root.<\/li>\n<li>Tighten submitted-value sanitisation and escaped output for WordPress.org review.<\/li>\n<li>Run automated Plugin Check against the production plugin files only.<\/li>\n<\/ul>\n\n<h4>1.14.0<\/h4>\n\n<ul>\n<li>Default alerts on fresh installations to the WordPress site administrator email.<\/li>\n<li>Let site owners explicitly control every alert recipient.<\/li>\n<li>Keep email delivery disabled on fresh installations until an administrator opts in.<\/li>\n<li>Preserve existing alert-recipient settings when upgrading managed sites.<\/li>\n<li>Add GitHub release packaging and an approval-gated WordPress.org deployment workflow.<\/li>\n<li>Declare compatibility through WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.13.0<\/h4>\n\n<ul>\n<li>Add lightweight monitoring for .htaccess, wp-config.php, wp-load.php, wp-settings.php, wp-blog-header.php, index.php and .user.ini.<\/li>\n<li>Check every four hours on the next WordPress request and send one email per distinct file change.<\/li>\n<li>Keep important-file warnings visible until an administrator recognises the change and approves the new trusted baseline.<\/li>\n<li>Never overwrite, repair or delete a changed important file automatically.<\/li>\n<\/ul>\n\n<h4>1.12.0<\/h4>\n\n<ul>\n<li>Stop treating generic signature matches inside recognised installed plugins as confirmed quarantineable malware.<\/li>\n<li>Show the exact risky signature categories plus the installed plugin name and version.<\/li>\n<li>Keep known backdoors, gambling payloads and confirmed malicious fingerprints at critical\/high severity.<\/li>\n<\/ul>\n\n<h4>1.11.1<\/h4>\n\n<ul>\n<li>Prevent temporary 503 resource exhaustion by removing the synchronous 12,000-file scan from redirect repairs.<\/li>\n<li>Verify the exact .htaccess change immediately and clear only the repaired finding.<\/li>\n<li>Leave full filesystem scans as a separate deliberate action.<\/li>\n<\/ul>\n\n<h4>1.11.0<\/h4>\n\n<ul>\n<li>Fingerprint each suspicious theme HTML rewrite rule found in .htaccess.<\/li>\n<li>Back up and remove only the selected exact rule, then verify and rescan.<\/li>\n<li>Replace misleading broad repair buttons on older scan results with a required refresh action.<\/li>\n<li>Report explicitly when a repair changed nothing instead of appearing to succeed silently.<\/li>\n<\/ul>\n\n<h4>1.10.0<\/h4>\n\n<ul>\n<li>Add a confirmed delete action for unapproved administrator accounts.<\/li>\n<li>Reassign deleted-account content to the administrator performing the cleanup, then rescan.<\/li>\n<li>Block deletion of the current administrator, the last administrator and multisite super-administrators.<\/li>\n<\/ul>\n\n<h4>1.9.1<\/h4>\n\n<ul>\n<li>Preserve valid dots in theme directory names during individual and bulk removal.<\/li>\n<li>Continue rejecting slashes and unsafe path characters before server-side eligibility checks.<\/li>\n<\/ul>\n\n<h4>1.9.0<\/h4>\n\n<ul>\n<li>Display the active child theme and required parent as green protected rows.<\/li>\n<li>Add checkboxes, Select all and one confirmed bulk-removal action for inactive themes.<\/li>\n<li>Revalidate every selected theme on the server and rescan once after removal.<\/li>\n<\/ul>\n\n<h4>1.8.0<\/h4>\n\n<ul>\n<li>Detect every inactive installed theme as a security-hygiene finding.<\/li>\n<li>Add a confirmed WordPress-native removal action followed by a fresh scan.<\/li>\n<li>Protect the active theme and its required parent from removal.<\/li>\n<li>Disable direct theme deletion on multisite and direct administrators to Network Admin.<\/li>\n<\/ul>\n\n<h4>1.7.1<\/h4>\n\n<ul>\n<li>Move accepted Monitor decisions out of unresolved medium warnings into a blue informational state.<\/li>\n<li>Exclude monitored files from the Needs review count and email warning threshold.<\/li>\n<li>Continue reassessing monitored fingerprints whenever their file contents change.<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>Add per-row and Select all checkboxes for eligible medium fingerprint findings.<\/li>\n<li>Apply Safe, Monitor or Malicious decisions to multiple selected findings with one confirmation.<\/li>\n<li>Restrict bulk decisions to non-actionable medium findings so confirmed threats cannot be bulk-approved accidentally.<\/li>\n<li>Identify clean placeholders belonging to absent import\/export plugins as orphaned data rather than malware.<\/li>\n<\/ul>\n\n<h4>1.6.2<\/h4>\n\n<ul>\n<li>Cross-check clean upload placeholders against WordPress's installed-plugin registry.<\/li>\n<li>Suppress WP All Export, WP All Import and WP Import Export Lite placeholders only when the matching plugin is installed.<\/li>\n<li>Keep orphaned or unexplained upload folders visible for review.<\/li>\n<\/ul>\n\n<h4>1.6.1<\/h4>\n\n<ul>\n<li>Recognise the actual WP All Export uploads directory name, wpallexport, and suppress clean index placeholders.<\/li>\n<li>Add a clear recommended action for uncertain findings and make Keep monitoring the safe default.<\/li>\n<li>Clarify that Safe and Malicious decisions require human verification.<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>Add a fifth Threat Intelligence step with explicit Safe, Confirmed malicious and Keep monitoring decisions.<\/li>\n<li>Learn exact SHA-256 file fingerprints without self-modifying the plugin.<\/li>\n<li>Suppress approved-safe fingerprints, escalate approved-malicious fingerprints and reassess files whenever their contents change.<\/li>\n<li>Add an auditable learned-rule table with the ability to forget decisions.<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Redesign the admin screen as a clear Configure, Scan, Review, Fix and verify journey.<\/li>\n<li>Add recommended next actions, novice-friendly explanations and safer action labels.<\/li>\n<li>Move advanced notifications and administrator controls into expandable sections.<\/li>\n<li>Clearly distinguish confirmed fixable threats from manual-review findings.<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Stop classifying known WP All Import\/Export index placeholders as high-risk malware when no malicious signature is present.<\/li>\n<li>Downgrade other unsigned PHP-in-uploads files to non-actionable manual review.<\/li>\n<li>Reserve quarantine controls for confirmed payloads and high-risk code signatures.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Add Scan &amp; check known URL and Fix chosen URL controls.<\/li>\n<li>Safely remove a matching same-site theme HTML rewrite for the configured URL with evidence backup.<\/li>\n<li>Quarantine confirmed gambling payload files, purge caches and verify the configured URL after repair.<\/li>\n<li>Add one-click administrator approval from the findings table and suppress future warnings for approved accounts.<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Display the full Luketom Compromise Review name in the WordPress admin sidebar.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Standardise future branding as Luketom Compromise Review.<\/li>\n<li>Add a Known injection URL setting for the affected same-site page or path.<\/li>\n<li>Use the configured URL for uncached front-end verification after cleanup and cache purges.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Refresh administrator findings immediately after saving the administrator allowlist.<\/li>\n<li>Remove approved administrators from Needs review without requiring another filesystem scan.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Purge WordPress, LiteSpeed, WP Super Cache, WP Rocket and W3 Total Cache after cleanup actions.<\/li>\n<li>Add a cache-purge and uncached front-end contact-page verification action.<\/li>\n<li>Record the live verification result in the cleanup audit panel.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Add an animated activity bar and stage messages during scans, repairs, quarantine and settings saves.<\/li>\n<li>Add a clear security summary with finding counts, files checked and scan coverage.<\/li>\n<li>Preserve a visible last-cleanup audit record showing repairs, quarantined paths and verification coverage.<\/li>\n<li>Explain partial scan coverage and the deep-scan limit.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Add a one-click, evidence-preserving fix for confirmed incident redirects and payload files.<\/li>\n<li>Add direct Repair and Quarantine &amp; rescan actions beside eligible findings.<\/li>\n<li>Remove noisy single-signature warnings that matched legitimate WordPress and plugin files.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Send compromise alerts to both luke@luketom.com and tom@luketom.com.<\/li>\n<li>Support additional alert recipients and include medium-severity compromise indicators.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial incident-response release.<\/li>\n<\/ul>","raw_excerpt":"Incident-focused safeguards for a multi-site WordPress estate.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/359870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=359870"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/lukehutton"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=359870"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=359870"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=359870"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=359870"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=359870"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=359870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}