UpdateProof is a free local tool for safer site maintenance.
The Free/Base release helps developers and maintenance agencies establish an evidence-based update workflow before an update:
The Free/Base plugin does not create a staging site, run synthetic form or WooCommerce tests, schedule updates, automatically roll back a failed update, or provide multi-site/team management. Those are planned Pro/service capabilities.
UpdateProof stores the latest safety snapshot and a one-way hash of the optional site token in the WordPress options table. The free plugin does not send site content, visitor data, or telemetry to ZeroFrik or any third party.
Visual regression is disabled by default. If an administrator enables it, the configured public page URLs are sent to the administrator-provided browser worker, which returns screenshots and pixel-difference data. The plugin stores those images in the site’s uploads directory. Do not configure private, password-protected, or visitor-personalized pages in this Free/Base feature.
If an administrator generates a site token and gives it to an external service, that service can read the site metadata, update inventory, and safety snapshot exposed by the plugin’s authenticated REST API. The token can be revoked at any time from the plugin settings in the WordPress admin.
The optional visual regression feature connects to a browser worker URL entered by the site administrator. There is no default hosted worker and no request is made unless the administrator enables the feature and presses Capture visual baseline or Run visual check. The worker receives the configured public page URL, viewport size, and a site identifier, then returns a Chromium screenshot and pixel-difference result. The plugin stores the returned screenshots in the site’s uploads directory. The worker does not receive WordPress credentials, post content, or visitor data from this plugin. If a third-party worker is used, its operator’s terms and privacy policy apply.
The optional read-only endpoints are available below the site REST URL:
Send the generated token in the X-UpdateProof-Token header. A token is never returned by the API.