{"id":378319,"date":"2026-10-07T00:41:18","date_gmt":"2026-10-07T00:41:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/tendrix-connector\/"},"modified":"2026-10-07T00:40:45","modified_gmt":"2026-10-07T00:40:45","slug":"tendrix-connector","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/tendrix-connector\/","author":23570592,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.26.1","stable_tag":"0.26.1","tested":"7.1.3","requires":"6.4","requires_php":"8.1","requires_plugins":null,"header_name":"Tendrix Connector","header_author":"Tendrix Platform","header_description":"Connects this site to a Tendrix Hub you control: heartbeat, technical inventory and audits on demand. It never executes remote code.","assets_banners_color":"f6f8f1","last_updated":"2026-10-07 00:40:45","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/tendrix.cloud\/plataforma\/","header_author_uri":"https:\/\/tendrix.cloud","rating":0,"author_block_rating":0,"active_installs":0,"downloads":128,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.26.1":{"tag":"0.26.1","author":"tendrixplatform","date":"2026-10-07 00:40:45","revision":3731709}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3731709,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3731709,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3731709,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3731709,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.26.1"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[5590,8533,732,5603,151481],"plugin_category":[52,54],"plugin_contributors":[284784],"plugin_business_model":[],"class_list":["post-378319","plugin","type-plugin","status-publish","hentry","plugin_tags-agency","plugin_tags-audit","plugin_tags-maintenance","plugin_tags-monitoring","plugin_tags-site-health","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_contributors-tendrixplatform","plugin_committers-tendrixplatform"],"banners":{"banner":"https:\/\/ps.w.org\/tendrix-connector\/assets\/banner-772x250.png?rev=3731709","banner_2x":"https:\/\/ps.w.org\/tendrix-connector\/assets\/banner-1544x500.png?rev=3731709","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/tendrix-connector\/assets\/icon-128x128.png?rev=3731709","icon_2x":"https:\/\/ps.w.org\/tendrix-connector\/assets\/icon-256x256.png?rev=3731709","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Tendrix Connector is the client side of a two-plugin system. It is installed on a site that\nsomebody maintains for you, or that you maintain for a client, and it reports to an\n<strong>Tendrix Hub<\/strong> running on a WordPress site that you or your agency owns.<\/p>\n\n<p>There is no third-party service. This plugin talks to one Hub and only to the Hub you paired\nit with, whose address is pinned at pairing time and cannot be changed by a request.<\/p>\n\n<p><strong>What it does<\/strong><\/p>\n\n<ul>\n<li>Sends a heartbeat every five minutes, with the site's technical inventory when something changed.<\/li>\n<li>Runs local audits when the Hub asks: security, pending updates, health, SEO, broken links, accessibility and file integrity.<\/li>\n<li>Executes commands from a closed list, and refuses anything else without interpreting it. The list covers audits, inventory, image optimisation and alt text, cache purging, database cleanup and backups: content, data and cache, never site administration. With the free Tendrix Hub the connector only runs audits and sends its inventory; the other commands are sent only by the Tendrix Hub Pro add-on.<\/li>\n<li>Records fatal errors and outgoing mail failures so they can be diagnosed from the Hub.<\/li>\n<li>Recompresses and resizes the images the Hub selects, keeping a copy of each original.<\/li>\n<li>Carries the daily counts of Tendrix Chat and Tendrix Consent, when they are installed. Anything that is not a whole number is dropped before sending, so no plugin can use this channel for personal data.<\/li>\n<\/ul>\n\n<p><strong>What it never does<\/strong><\/p>\n\n<ul>\n<li>It does not execute code sent by the Hub. The Hub sends the name of a command from a fixed list, never code, never a file path and never SQL.<\/li>\n<li>It does not send your users' names, e-mail addresses or content. People are reported as counts per role. Mail diagnostics mask the recipient (<code>m***@gmail.com<\/code>).<\/li>\n<li>It does not install, update, activate or delete plugins, themes or WordPress core. The Hub shows which updates are pending; an administrator of this site applies them from its own dashboard.<\/li>\n<li>It does not open sessions on this site, create users or change their roles.<\/li>\n<li>It does not change site settings, permalinks, robots.txt, security settings or plugin databases, and it does not delete files from the site. Those are changed by an administrator of this site from its own dashboard.<\/li>\n<li>It does not accept instructions on its public endpoint. The one inbound route only wakes the plugin up, carries no orders, and requires the same signature as everything else.<\/li>\n<\/ul>\n\n<p><strong>File integrity<\/strong><\/p>\n\n<p>When the Hub asks for it, the connector hashes the WordPress core files and the files of\nplugins that come from the wordpress.org directory, compares them against the official\nchecksums published by wordpress.org, and looks for executable PHP inside the uploads folder.<\/p>\n\n<p>This is an integrity canary, not an antivirus. It proves that a file is not the one that was\ndistributed. It says nothing about a malicious plugin whose files are intact, and it never\ndeletes or quarantines anything: it reports, and a person decides.<\/p>\n\n<p><strong>Communication and security<\/strong><\/p>\n\n<p>The connector always initiates the connection outwards. The single inbound route,\n    \/tendrix-conector\/v1\/wake, does not carry orders: it tells the plugin to run its cycle\nnow, and the plugin then asks the Hub for work over its usual signed outbound channel. If\nyour host blocks incoming requests, nothing is lost: the five minute cycle picks the work up\nanyway.<\/p>\n\n<p>Every request is signed with HMAC-SHA256 over the method, path, timestamp, nonce and a hash\nof the body, compared in constant time, with a five minute clock window and single-use\nnonces. The shared secret is created at pairing time and is deleted from this site when you\nunpair.<\/p>\n\n<h3>External services<\/h3>\n\n<p><strong>The Tendrix Hub you paired it with<\/strong><\/p>\n\n<p>Its address is entered by an administrator of this site during pairing, is stored, and cannot\nbe changed by an incoming request. Sending data to it is the entire purpose of the plugin.<\/p>\n\n<p>What is sent: WordPress, PHP and server versions and settings; the list of installed plugins\nand themes with their versions; database size and table statistics; counts of posts, pages,\ncomments, media and users per role; security and SEO configuration; audit findings; fatal\nerror messages with the file, line and URL where they happened, with server paths trimmed;\nand the recipient domain, subject and status of recent outgoing mail.<\/p>\n\n<p>What is never sent: post or page content, passwords, user names or user e-mail addresses.<\/p>\n\n<p><strong>api.wordpress.org<\/strong><\/p>\n\n<p>Used only during a file integrity audit, to fetch the official checksums for the WordPress\nversion this site runs. What is sent: the WordPress version and the site language. This is\nthe same request WordPress itself makes through its own <code>get_core_checksums()<\/code> function.\nProvided by the WordPress Foundation. Terms and privacy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<p><strong>downloads.wordpress.org<\/strong><\/p>\n\n<p>Used only during a file integrity audit, to fetch the published checksums of installed\nplugins. What is sent: the slug and version of a plugin, in the URL. Nothing about this site\nis included, and the answer is cached for a week. Provided by the WordPress Foundation.\nTerms and privacy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<p>No data is sent to the author of this plugin, and there is no telemetry.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Ask whoever runs your Tendrix Hub for the Hub URL and a pairing code.<\/li>\n<li>Install and activate this plugin.<\/li>\n<li>Go to <strong>Settings \u2192 Tendrix Connector<\/strong>, enter the Hub URL and the pairing code, and press <strong>Pair site<\/strong>.<\/li>\n<\/ol>\n\n<p>That is all that is done here. Audits and actions are launched from the Hub.<\/p>\n\n<p>To disconnect, press <strong>Unpair and delete secret<\/strong> on the same screen. The credential stops\nworking immediately and the secret is removed from this site.<\/p>\n\n<p>Multisite is not supported and is refused at pairing time.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"who%20can%20send%20commands%20to%20this%20site%3F\"><h3>Who can send commands to this site?<\/h3><\/dt>\n<dd><p>Only the Hub you paired with, and only commands from a fixed list. Every request must carry\na valid signature made with a secret that exists on both ends and nowhere else.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20my%20host%20blocks%20incoming%20requests%3F\"><h3>What happens if my host blocks incoming requests?<\/h3><\/dt>\n<dd><p>Nothing breaks. The inbound route is only a shortcut that says \"run now\". The plugin's own\nfive minute cycle picks up any pending work regardless.<\/p><\/dd>\n<dt id=\"how%20do%20i%20stop%20it%20completely%3F\"><h3>How do I stop it completely?<\/h3><\/dt>\n<dd><p>Unpair it on its settings screen, or deactivate the plugin. Unpairing deletes the shared\nsecret from this site.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20my%20site%20down%3F\"><h3>Does it slow my site down?<\/h3><\/dt>\n<dd><p>The full inventory is only sent when its hash changed, not on every heartbeat. Audits run\nwhen the Hub asks for them, not on visitor requests.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.26.1<\/h4>\n\n<ul>\n<li>Fix: audits never collected internal links (the pattern that finds them was malformed, so PHP discarded it with a warning).<\/li>\n<\/ul>\n\n<h4>0.26.0<\/h4>\n\n<ul>\n<li>Removed: remote configuration changes (WordPress settings, indexing, permalinks, robots.txt, security hardening, deleting exposed files and plugin database updates). The Hub reports them as findings; an administrator of the site applies them.<\/li>\n<li>No longer deactivates the old Tendrix Agent plugin by itself. Its settings are still moved over, and a notice suggests deactivating it.<\/li>\n<li>Transient names now use the plugin prefix.<\/li>\n<\/ul>\n\n<h4>0.25.0<\/h4>\n\n<ul>\n<li>Removed: installing, updating, activating and deleting plugins and themes, updating WordPress core, restoring a full backup, managing users, opening the dashboard from the Hub and renaming this plugin in the plugin list. The connector now reports and applies configuration fixes only; updates are applied by an administrator of the site.<\/li>\n<li>Security hardening toggles are applied by the connector itself with filters instead of writing a must-use plugin. The file left by earlier versions is removed the next time a toggle changes, or on uninstall.<\/li>\n<\/ul>\n\n<h4>0.24.4<\/h4>\n\n<ul>\n<li>Fixed: a one-off fatal from replacing the plugin ZIP kept showing as a critical finding. Updating clears the connector's own fatals, and fatals older than 7 days are no longer reported.<\/li>\n<\/ul>\n\n<h4>0.24.3<\/h4>\n\n<ul>\n<li>Settings \u2192 Tendrix Connector has a Test connection now button: it checks pairing, the five-minute cycle, the heartbeat (HTTP status, response and clock difference with the Hub), the inventory, the Chat and Consent report and the job queue, and shows the result step by step.<\/li>\n<li>A PHP fatal error in the middle of a cycle is now recorded as the last error, with file and line.<\/li>\n<\/ul>\n\n<h4>0.24.2<\/h4>\n\n<ul>\n<li>Fixed: after moving from the old tendrix-conector folder to tendrix-connector, deactivating the old copy removed the five-minute cycle of the new one. The heartbeat stopped without logging any error and the site showed as offline while audits still worked. The cycle is now rescheduled automatically whenever it is missing.<\/li>\n<\/ul>\n\n<h4>0.24.1<\/h4>\n\n<ul>\n<li>Fixed: a site could stay offline forever. The heartbeat carried the full inventory, so when sending the inventory failed (a hosting firewall, a size limit, a timeout) the heartbeat failed too, the inventory stayed pending for the next one and the connector ended up paused. The heartbeat is now sent on its own first and the inventory goes separately.<\/li>\n<li>A connector paused after repeated failures retries once an hour and resumes by itself when the Hub answers. A revoked credential still stops it.<\/li>\n<li>The last error (step, HTTP status and message) is shown under Settings \u2192 Tendrix Connector and reported to the Hub's activity log.<\/li>\n<\/ul>\n\n<h4>0.24.0<\/h4>\n\n<ul>\n<li>Text domain is now <code>tendrix-connector<\/code>, matching the plugin slug.<\/li>\n<li>Plugins and themes are installed only from the wordpress.org directory. Installing a zip uploaded to the Hub is removed.<\/li>\n<li>The plugin row can no longer be hidden from the plugin list.<\/li>\n<li>Tested with WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>0.23.0<\/h4>\n\n<ul>\n<li><strong>Full backup and restore<\/strong>: wp-content and the database in one zip, kept on the site with web access closed. Restoring backs up the current database first and keeps the connection to the Hub.<\/li>\n<li><strong>Users<\/strong>: create, change role, send a password reset and delete (content goes to the site administrator). The Hub only ever sees masked usernames (<code>a***n<\/code>) and roles.<\/li>\n<li><strong>Plugins uploaded to the Hub<\/strong>: installed only from the paired Hub's address and only if the file matches its hash.<\/li>\n<li><strong>WordPress settings in bulk<\/strong> from a closed list of options, reporting the previous value of each.<\/li>\n<li><strong>Purge cache<\/strong> of the common caching plugins, and <strong>WooCommerce and Elementor database updates<\/strong>.<\/li>\n<li><strong>WooCommerce summary<\/strong>: daily orders and sales in the heartbeat, as counts and totals only.<\/li>\n<li>Reads the last UpdraftPlus backup and open Wordfence issues, and can start either.<\/li>\n<\/ul>\n\n<h4>0.22.0<\/h4>\n\n<ul>\n<li>The heartbeat carries the daily counts of Tendrix Chat and Tendrix Consent. The connector keeps only whole numbers and short keys from them, whatever those plugins send.<\/li>\n<li>Two more commands, only when their plugin is active: chat.configure and consent.configure. The list stays closed: no other name can be added.<\/li>\n<\/ul>\n\n<h4>0.21.0<\/h4>\n\n<ul>\n<li>The Hub can send an image into this site's media library. It never pushes the file: it sends an address on the Hub and the sha256 of what will be found there, this plugin downloads it over its usual outbound channel and checks the hash before touching anything. The address must be on the Hub this site is paired with, the content must really be a JPEG, PNG or WebP, and WordPress does the rest through its own sideload. Undoing it deletes that attachment and only that one.<\/li>\n<li>Optimising raises its own time limit before starting, and batches are of ten: a job that dies halfway leaves files written and the Hub with no answer.<\/li>\n<\/ul>\n\n<h4>0.20.0<\/h4>\n\n<ul>\n<li>Media library: the Hub can ask for it, heaviest first, and recompress and resize the images it picks in place, through the WordPress image editor (Imagick, or GD where Imagick is missing). The original file is copied first, so every optimisation can be undone; file names never change; an image that comes back heavier is put back as it was and reported as already optimal, which is an answer and not a failure. How much each image lost is recorded on this site, so the panel can show it even if the job that did it never reported back.<\/li>\n<\/ul>\n\n<h4>0.19.0<\/h4>\n\n<ul>\n<li>Updates are checked before being kept: four numbers per sampled page, read before and after, and a rollback when a page comes back broken. The Hub is told which pages, not only that something failed.<\/li>\n<li>New file integrity audit: core and plugin files against the official wordpress.org checksums, and executable PHP inside uploads.<\/li>\n<li>A failed job can now carry a short detail alongside its error code, so the Hub can say where it failed and not only what failed.<\/li>\n<\/ul>\n\n<h4>0.18.0<\/h4>\n\n<ul>\n<li>Every disk write now goes through the WordPress filesystem API, so nothing is written behind WordPress's back on hosts where the web process does not own the files.<\/li>\n<li>Browser input goes through one typed helper that unslashes and then sanitises.<\/li>\n<li>English is now the source language, with a Spanish catalogue.<\/li>\n<\/ul>\n\n<h4>0.17.0<\/h4>\n\n<ul>\n<li>Database maintenance: revisions, spam, trash, expired transients, orphaned metadata and table optimisation, in batches so a shared host stays up.<\/li>\n<li>Database backup, written to a temporary name and only renamed when complete.<\/li>\n<li>Single-use link to open this site's dashboard from the Hub, with its own off switch.<\/li>\n<li>Optional renaming of this plugin's row in the plugin list.<\/li>\n<\/ul>\n\n<h4>0.16.1<\/h4>\n\n<ul>\n<li>Fatal error and outgoing mail diagnostics.<\/li>\n<li>Configuration fixes: robots.txt, indexing, permalinks and hardening through a mu-plugin.<\/li>\n<\/ul>","raw_excerpt":"Connects this site to a Tendrix Hub you control: heartbeat, technical inventory and audits on demand. It never executes remote code.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/378319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=378319"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/tendrixplatform"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=378319"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=378319"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=378319"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=378319"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=378319"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=378319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}