Tendrix Connector is the client side of a two-plugin system. It is installed on a site that
somebody maintains for you, or that you maintain for a client, and it reports to an
Tendrix Hub running on a WordPress site that you or your agency owns.
There is no third-party service. This plugin talks to one Hub and only to the Hub you paired
it with, whose address is pinned at pairing time and cannot be changed by a request.
What it does
What it never does
m***@gmail.com).File integrity
When the Hub asks for it, the connector hashes the WordPress core files and the files of
plugins that come from the wordpress.org directory, compares them against the official
checksums published by wordpress.org, and looks for executable PHP inside the uploads folder.
This is an integrity canary, not an antivirus. It proves that a file is not the one that was
distributed. It says nothing about a malicious plugin whose files are intact, and it never
deletes or quarantines anything: it reports, and a person decides.
Communication and security
The connector always initiates the connection outwards. The single inbound route,
/tendrix-conector/v1/wake, does not carry orders: it tells the plugin to run its cycle
now, and the plugin then asks the Hub for work over its usual signed outbound channel. If
your host blocks incoming requests, nothing is lost: the five minute cycle picks the work up
anyway.
Every request is signed with HMAC-SHA256 over the method, path, timestamp, nonce and a hash
of the body, compared in constant time, with a five minute clock window and single-use
nonces. The shared secret is created at pairing time and is deleted from this site when you
unpair.
The Tendrix Hub you paired it with
Its address is entered by an administrator of this site during pairing, is stored, and cannot
be changed by an incoming request. Sending data to it is the entire purpose of the plugin.
What is sent: WordPress, PHP and server versions and settings; the list of installed plugins
and themes with their versions; database size and table statistics; counts of posts, pages,
comments, media and users per role; security and SEO configuration; audit findings; fatal
error messages with the file, line and URL where they happened, with server paths trimmed;
and the recipient domain, subject and status of recent outgoing mail.
What is never sent: post or page content, passwords, user names or user e-mail addresses.
api.wordpress.org
Used only during a file integrity audit, to fetch the official checksums for the WordPress
version this site runs. What is sent: the WordPress version and the site language. This is
the same request WordPress itself makes through its own get_core_checksums() function.
Provided by the WordPress Foundation. Terms and privacy: https://wordpress.org/about/privacy/
downloads.wordpress.org
Used only during a file integrity audit, to fetch the published checksums of installed
plugins. What is sent: the slug and version of a plugin, in the URL. Nothing about this site
is included, and the answer is cached for a week. Provided by the WordPress Foundation.
Terms and privacy: https://wordpress.org/about/privacy/
No data is sent to the author of this plugin, and there is no telemetry.