NullSquare connects your WordPress site to the NullSquare external security service. It helps verify control of the site’s domain, keeps the connected-site status synchronized, and can display an optional public trust badge after verification.
The plugin does not scan the WordPress installation, inspect post content, or monitor individual visitors. Security assessments are performed by the separate NullSquare service only for targets the account owner is authorized to test.
Features include:
A NullSquare account and an internet connection are required to connect and verify a site. Service availability, account eligibility, and any plan limits are governed by NullSquare’s Terms of Service.
This plugin connects to the NullSquare service at api.nullsquare.net and app.nullsquare.net. The service is required for account authorization, domain verification, connection-status synchronization, the public verified-site profile, and badge configuration synchronization.
The plugin does not contact NullSquare until a WordPress administrator explicitly starts a connection. Once connected, it communicates with NullSquare when completing the connection, during scheduled heartbeats, when an administrator visits WordPress admin after the synchronization interval, when settings are saved, and when the administrator disconnects the site.
Depending on the action, the plugin may send:
The public verification endpoint can return the requested challenge, normalized domain, site URL, a challenge signature, and WordPress/plugin versions. It does not expose the connection code or site-specific secret.
NullSquare may use the public site name, icon, logo, domain, and verification status on the site’s public verified profile after the administrator connects the site. The optional badge links to that public profile only after the administrator enables the badge.
The plugin does not send WordPress posts, pages, comments, user passwords, or individual visitor identities to NullSquare.