{"id":360589,"date":"2026-09-11T03:30:18","date_gmt":"2026-09-11T03:30:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/atomic-site-manager\/"},"modified":"2026-09-11T03:30:07","modified_gmt":"2026-09-11T03:30:07","slug":"atomic-site-manager","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/atomic-site-manager\/","author":23498447,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.1","requires":"6.5","requires_php":"8.1","requires_plugins":null,"header_name":"Atomic Site Manager","header_author":"Oyorox","header_description":"Connect this site to your Atomic Site Manager dashboard for remote updates, backups, security, SEO, and site health monitoring.","assets_banners_color":"","last_updated":"2026-09-11 03:30:07","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/atomicsitemanager.com\/","header_author_uri":"https:\/\/oyorox.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":37,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"oyorox","date":"2026-09-11 03:30:07","revision":3690696}},"upgrade_notice":{"1.0.2":"<p>Security and guideline release. Installs are restricted to the WordPress.org directory, backup restores no longer write executable files into uploads, and stored credentials are redacted and protected from remote reads, writes and deletes.<\/p>","1.0.1":"<p>The built-in SEO engine is now off by default and webfonts are bundled locally. If you relied on the SEO engine, enable it from your Atomic Site Manager dashboard.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.jpg":{"filename":"icon-128x128.jpg","revision":3690696,"resolution":"128x128","location":"assets","locale":"","width":512,"height":512},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3690696,"resolution":"256x256","location":"assets","locale":"","width":512,"height":512}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Settings \u2192 Atomic Site Manager: Site Key field, connection status, and the manual heartbeat control."}},"plugin_section":[],"plugin_tags":[151,2156,5603,14512,600],"plugin_category":[54,59],"plugin_contributors":[262955],"plugin_business_model":[],"class_list":["post-360589","plugin","type-plugin","status-publish","hentry","plugin_tags-backup","plugin_tags-management","plugin_tags-monitoring","plugin_tags-remote","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-oyorox","plugin_committers-oyorox"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/atomic-site-manager\/assets\/icon-128x128.jpg?rev=3690696","icon_2x":"https:\/\/ps.w.org\/atomic-site-manager\/assets\/icon-256x256.png?rev=3690696","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Atomic Site Manager is a connector plugin. It links this WordPress site to an Atomic Site Manager account so you can manage the site from one external dashboard instead of logging in to wp-admin for every routine task.<\/p>\n\n<p>The plugin adds no dashboard, charts, or reporting screens to WordPress. Inside WordPress it shows a single settings page where you paste your Site Key and connect. Everything else happens in the Atomic Site Manager web app.<\/p>\n\n<p><strong>The connector requires an Atomic Site Manager account.<\/strong> Without a Site Key from that service the plugin stays idle and does nothing. Create an account and register your site at https:\/\/atomicsitemanager.com\/<\/p>\n\n<h4>What the connector does<\/h4>\n\n<ul>\n<li>Registers this site with your Atomic Site Manager account using a Site Key you paste yourself<\/li>\n<li>Sends a periodic heartbeat with site inventory and health data<\/li>\n<li>Polls for commands you queue in the dashboard and runs them on this site<\/li>\n<li>Reports each command result back to the dashboard<\/li>\n<li>Clears its stored credentials automatically when you disconnect the site from the dashboard<\/li>\n<\/ul>\n\n<h4>What you can run from the dashboard<\/h4>\n\n<ul>\n<li>Install, update, activate, deactivate, and delete plugins and themes. Installs come from the WordPress.org directory by slug; the connector does not install packages from any other source.<\/li>\n<li>Update WordPress core and translations<\/li>\n<li>Create, edit, and delete users and roles<\/li>\n<li>Read and update options, browse database tables, and flush caches<\/li>\n<li>Create, restore, and delete database and uploads backups stored on this server<\/li>\n<li>Take, compare, and restore configuration snapshots<\/li>\n<li>Run reset tools for options, users, roles, sessions, and media<\/li>\n<li>Apply security hardening settings and run performance audits<\/li>\n<li>Manage SEO titles, descriptions, and social metadata<\/li>\n<li>Run static plugin checks against installed plugins<\/li>\n<li>Toggle background updates and traffic-triggered WP-Cron spawning<\/li>\n<li>Open a one-click admin login from the dashboard for users you authorize there<\/li>\n<\/ul>\n\n<h4>Built-in engines<\/h4>\n\n<p>SEO output, reset and snapshot tooling, and static plugin checking are built into the connector, so you do not need separate plugins for them. All three ship switched off: until you turn the SEO engine on from the dashboard, the connector adds no titles, meta tags, schema, feed text, or sitemap URLs to your site. The connector never activates or deactivates a plugin or theme on its own. It only does so when you run that specific command from your dashboard, and it never touches its own activation state.<\/p>\n\n<h4>External services<\/h4>\n\n<p>This plugin relies on two external services. Both are described below, including\nwhat is sent, when it is sent, and the conditions under which it happens.<\/p>\n\n<p><strong>1. Atomic Site Manager (required)<\/strong><\/p>\n\n<p>Atomic Site Manager is a software-as-a-service dashboard for managing WordPress\nsites remotely, operated by Oyorox. This plugin is the connector for that\nservice: it registers the site, reports its state, and carries out the commands\nyou queue in the dashboard. Without it the plugin has nothing to talk to.<\/p>\n\n<ul>\n<li>Service home: https:\/\/atomicsitemanager.com\/<\/li>\n<li>Dashboard you sign in to: https:\/\/atomic-site-manager-web.vercel.app<\/li>\n<li>API endpoint the plugin calls: <code>https:\/\/atomic-site-manager-api.vercel.app\/api\/v1\/connector\/<\/code><\/li>\n<li>Terms of use: https:\/\/atomicsitemanager.com\/terms-of-use.html<\/li>\n<li>Privacy policy: https:\/\/atomicsitemanager.com\/privacy-policy.html<\/li>\n<\/ul>\n\n<p><em>When data is sent<\/em><\/p>\n\n<p>Nothing at all is sent until you paste a Site Key on <strong>Settings \u2192 Atomic Site\nManager<\/strong> and click <strong>Connect<\/strong>. After that:<\/p>\n\n<ul>\n<li>On connect \u2014 once, when you submit your Site Key<\/li>\n<li>On heartbeat \u2014 every 60 seconds by default, via WP-Cron, and whenever you press <strong>Send heartbeat now<\/strong><\/li>\n<li>On command result \u2014 after the dashboard runs a command on this site<\/li>\n<li>On magic login \u2014 once per one-click login, to verify the token you were issued<\/li>\n<li>On disconnect \u2014 once, when you disconnect from the settings page<\/li>\n<\/ul>\n\n<p><em>What is sent<\/em><\/p>\n\n<ul>\n<li>Site name, site URL, home URL, locale, timezone, and whether the install is multisite<\/li>\n<li>WordPress, PHP, MySQL, and web server versions, and whether WP_DEBUG and SSL are on<\/li>\n<li>Installed plugins and themes with names, slugs, versions, authors, and active state<\/li>\n<li>Available core, plugin, theme, and translation updates<\/li>\n<li>Memory usage and limit, disk usage and free space, the uploads directory path, and the active theme<\/li>\n<li>WordPress user accounts and roles, including user login, email address, display name, assigned roles, and registration date, for up to 200 users<\/li>\n<li>Command results and error messages produced by dashboard actions<\/li>\n<li>Your Site Key and the site token issued in exchange for it<\/li>\n<\/ul>\n\n<p>The plugin does not send post content, comments, media files, passwords, or\nvisitor analytics.<\/p>\n\n<p>All requests use HTTPS. Plain HTTP is accepted only for <code>localhost<\/code> and private\nLAN addresses so the plugin can be developed against a local backend.<\/p>\n\n<p><strong>2. IndexNow (optional, off by default)<\/strong><\/p>\n\n<p>IndexNow is a search-engine notification protocol sponsored by Microsoft Bing,\nYandex, Seznam.cz, Naver, and Yep. The plugin can ping it so newly published\ncontent is discovered quickly instead of waiting for the next crawl.<\/p>\n\n<ul>\n<li>Service: https:\/\/www.indexnow.org\/<\/li>\n<li>API endpoint the plugin calls: <code>https:\/\/api.indexnow.org\/indexnow<\/code><\/li>\n<li>Terms and conditions, including how request data is handled: https:\/\/www.indexnow.org\/terms<\/li>\n<\/ul>\n\n<p><em>When data is sent<\/em><\/p>\n\n<p>Only when <strong>all three<\/strong> of the following are true, all of which are off or empty\nuntil you set them from the Atomic Site Manager dashboard: the SEO engine is\nenabled, IndexNow and instant indexing are enabled, and an IndexNow key is set.\nWhen they are, one request is sent each time a post moves into the <em>published<\/em>\nstatus for the first time. Nothing is sent on a default install.<\/p>\n\n<p><em>What is sent<\/em><\/p>\n\n<ul>\n<li>This site's hostname<\/li>\n<li>The permalink of the post that was just published<\/li>\n<li>Your IndexNow key, and the URL of the key verification file on this site<\/li>\n<\/ul>\n\n<p>No personal data, post content, or visitor data is sent to IndexNow.<\/p>\n\n<h4>Bundled third-party assets<\/h4>\n\n<p>The admin settings screen uses three webfonts, all bundled with the plugin and\nserved from this site \u2014 no CDN or external font service is contacted. Each is\nlicensed under the SIL Open Font License 1.1, with the full licence text in\n    assets\/fonts\/:<\/p>\n\n<ul>\n<li>DM Sans \u2014 Copyright 2014 The DM Sans Project Authors<\/li>\n<li>Fraunces \u2014 Copyright 2018 The Fraunces Project Authors<\/li>\n<li>IBM Plex Mono \u2014 Copyright 2017 IBM Corp.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Install the plugin through <strong>Plugins \u2192 Add New<\/strong>, or upload the <code>atomic-site-manager<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate <strong>Atomic Site Manager<\/strong> from the <strong>Plugins<\/strong> screen.<\/li>\n<li>Sign in to the Atomic Site Manager dashboard at https:\/\/atomic-site-manager-web.vercel.app, create a site, and copy its <strong>Site Key<\/strong>.<\/li>\n<li>In WordPress, go to <strong>Settings \u2192 Atomic Site Manager<\/strong>.<\/li>\n<li>Paste the <strong>Site Key<\/strong> and click <strong>Connect<\/strong>.<\/li>\n<\/ol>\n\n<p>The site registers with the service and begins sending heartbeats. Use <strong>Disconnect<\/strong> on the same screen to revoke the connection and clear the stored credentials.<\/p>\n\n<p>To point a staging or local install at a different backend, define the URLs in <code>wp-config.php<\/code> before WordPress loads plugins:<\/p>\n\n<pre><code>define( 'ASMS_SERVER_URL', 'https:\/\/api-staging.example.com' );\ndefine( 'ASMS_DASHBOARD_URL', 'https:\/\/app-staging.example.com' );\n<\/code><\/pre>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20account%20to%20use%20this%20plugin%3F\"><h3>Do I need an account to use this plugin?<\/h3><\/dt>\n<dd><p>Yes. The plugin is a connector for the Atomic Site Manager service at https:\/\/atomic-site-manager-web.vercel.app and does nothing on its own. You need a Site Key from that service before anything is sent or received.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20add%20a%20monitoring%20dashboard%20to%20wordpress%3F\"><h3>Does the plugin add a monitoring dashboard to WordPress?<\/h3><\/dt>\n<dd><p>No. It adds one settings page for connecting and disconnecting. All dashboards, command queues, reports, and history live in the web app at https:\/\/atomic-site-manager-web.vercel.app<\/p><\/dd>\n<dt id=\"what%20data%20leaves%20my%20site%3F\"><h3>What data leaves my site?<\/h3><\/dt>\n<dd><p>Site and server versions, plugin and theme inventory, available updates, memory and disk metrics, WordPress user accounts including email addresses, and the results of commands you run from the dashboard. See <strong>External services<\/strong> in the description for the full list, including the optional IndexNow ping. Post content, comments, media, passwords, and visitor analytics are never sent.<\/p><\/dd>\n<dt id=\"can%20the%20service%20deactivate%20or%20delete%20this%20connector%20remotely%3F\"><h3>Can the service deactivate or delete this connector remotely?<\/h3><\/dt>\n<dd><p>No. Remote deactivate and delete of Atomic Site Manager itself is blocked in the command runner. Other plugins and themes can be managed remotely according to the permissions set in your dashboard account.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20using%20my%20existing%20seo%20plugin%3F\"><h3>Can I keep using my existing SEO plugin?<\/h3><\/dt>\n<dd><p>Yes. Atomic Site Manager does not deactivate, block, or modify any other plugin.<\/p>\n\n<p>The built-in SEO engine is <strong>switched off until you enable it<\/strong> from your Atomic Site Manager dashboard, so installing this plugin alongside Yoast, Rank Math, or All in One SEO changes nothing on its own. If you do enable it while another SEO plugin is running, both will output title, description, and Open Graph tags and search engines will see duplicates \u2014 so turn one of them off. Only one should be generating metadata.<\/p><\/dd>\n<dt id=\"how%20often%20does%20the%20heartbeat%20run%3F\"><h3>How often does the heartbeat run?<\/h3><\/dt>\n<dd><p>Every 60 seconds by default, through WP-Cron, and the service can adjust that interval. You can also send one immediately from the settings page.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20turn%20off%20traffic-triggered%20wp-cron%3F\"><h3>What happens if I turn off traffic-triggered WP-Cron?<\/h3><\/dt>\n<dd><p>Page visits stop spawning WordPress cron, but direct or server-scheduled calls to <code>wp-cron.php<\/code> still run. Set up a real server cron job before turning this off, so scheduled posts, emails, and other plugin tasks keep working.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20work%20over%20plain%20http%3F\"><h3>Does the plugin work over plain HTTP?<\/h3><\/dt>\n<dd><p>Only for <code>localhost<\/code> and private LAN addresses, for local development. Any public backend URL must use HTTPS.<\/p><\/dd>\n<dt id=\"where%20are%20backups%20stored%3F\"><h3>Where are backups stored?<\/h3><\/dt>\n<dd><p>In a <code>wp-content\/asm-backups<\/code> folder on this server. The plugin does not upload backup archives to the service.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Plugin and theme installs now come from the WordPress.org directory only. Package URLs pointing anywhere else are refused instead of downloaded, in remote install commands and in collections alike. Saved collections store a slug and no longer keep a package URL.<\/li>\n<li>Restoring a backup writes only inert media files into the uploads directory. PHP and other executable files, <code>.htaccess<\/code>, <code>web.config<\/code> and dotfiles inside the archive are refused and reported instead of being written.<\/li>\n<li>Stored credentials are never returned to the dashboard. Option reads, option listings, the database browser and option exports redact API keys \u2014 including WordPress core connector and AI provider keys \u2014 tokens, passwords, salts and licence keys.<\/li>\n<li>Remote option writes and deletes now refuse WordPress' structural settings. <code>active_plugins<\/code>, <code>template<\/code> and <code>stylesheet<\/code> are protected, so activating a plugin or switching a theme stays a user action, and keys, salts and other plugins' credentials can no longer be overwritten or removed.<\/li>\n<li>The database tools stay inside this installation's own tables, so a database shared with another WordPress install is no longer reachable.<\/li>\n<li>The plugin-data reset no longer matches option names from short or generic plugin slugs, and skips protected options instead of deleting them.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>The built-in SEO engine now ships switched off. A fresh install no longer alters titles, head markup, image alt text, feed content, robots.txt, or permalinks until you enable the engine from the dashboard.<\/li>\n<li>Bundled the admin screen's webfonts with the plugin instead of loading them from Google Fonts, so no external asset request is made.<\/li>\n<li>Security response headers are now controlled by their own hardening toggle instead of being sent on every request.<\/li>\n<li>Documented the optional IndexNow integration and both external services in full, with terms and privacy links.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Site Key connection, disconnect, and automatic credential clearing when the service revokes a site.<\/li>\n<li>WP-Cron heartbeat with site inventory, update availability, and health metrics.<\/li>\n<li>Remote command runner for plugins, themes, core, translations, users, roles, options, database tables, and caches.<\/li>\n<li>Database and uploads backups, configuration snapshots, and reset tools.<\/li>\n<li>Built-in SEO, reset\/snapshot, and static plugin-check engines, all off until enabled from the dashboard.<\/li>\n<li>Security hardening controls, performance audits, and automation toggles for background updates and WP-Cron spawning.<\/li>\n<li>REST status endpoints under the <code>siteconnector\/v1<\/code> namespace.<\/li>\n<\/ul>","raw_excerpt":"Connect this site to your Atomic Site Manager dashboard for remote updates, backups, security, SEO, and site health monitoring.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/360589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=360589"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/oyorox"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=360589"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=360589"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=360589"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=360589"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=360589"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=360589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}