{"id":360858,"date":"2026-09-07T12:04:49","date_gmt":"2026-09-07T12:04:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sumotori-dash-agent\/"},"modified":"2026-09-07T16:18:22","modified_gmt":"2026-09-07T16:18:22","slug":"sumotori-dash-agent","status":"publish","type":"plugin","link":"https:\/\/li.wordpress.org\/plugins\/sumotori-dash-agent\/","author":16611973,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.5.0","stable_tag":"1.5.0","tested":"7.1","requires":"5.2","requires_php":"7.0","requires_plugins":null,"header_name":"Sumotori Dash Agent","header_author":"Tommy Bordas","header_description":"Connects this site to a monitoring dashboard of your choice: reports sensitive administration events and answers signed, read-only inventory requests.","assets_banners_color":"111b23","last_updated":"2026-09-07 16:18:22","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/tommybds\/wp-dashboard","header_author_uri":"https:\/\/sumotori.fr\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":66,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.3.0":{"tag":"1.3.0","author":"tommybordas","date":"2026-09-07 12:22:21","revision":3684865},"1.4.0":{"tag":"1.4.0","author":"tommybordas","date":"2026-09-07 12:43:43","revision":3684922},"1.5.0":{"tag":"1.5.0","author":"tommybordas","date":"2026-09-07 16:18:22","revision":3685265}},"upgrade_notice":{"1.3.0":"<p>The deactivation-protection option is gone. If you had enabled it in an earlier\nversion, delete <code>wp-content\/mu-plugins\/sumotori-dash-agent.php<\/code> by hand over FTP\nor SSH: that leftover file keeps loading the old code and prevents the updated\nplugin from running.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3684865,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3684865,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3684865,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3684865,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.3.0","1.4.0","1.5.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3684865,"resolution":"1","location":"assets","locale":"","width":1160,"height":451},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3684865,"resolution":"2","location":"assets","locale":"","width":1160,"height":232}},"screenshots":[]},"plugin_section":[],"plugin_tags":[6601,732,2156,5603,441],"plugin_category":[45,52,54],"plugin_contributors":[250689],"plugin_business_model":[],"class_list":["post-360858","plugin","type-plugin","status-publish","hentry","plugin_tags-inventory","plugin_tags-maintenance","plugin_tags-management","plugin_tags-monitoring","plugin_tags-multisite","plugin_category-ecommerce","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_contributors-tommybordas","plugin_committers-tommybordas"],"banners":{"banner":"https:\/\/ps.w.org\/sumotori-dash-agent\/assets\/banner-772x250.png?rev=3684865","banner_2x":"https:\/\/ps.w.org\/sumotori-dash-agent\/assets\/banner-1544x500.png?rev=3684865","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sumotori-dash-agent\/assets\/icon-128x128.png?rev=3684865","icon_2x":"https:\/\/ps.w.org\/sumotori-dash-agent\/assets\/icon-256x256.png?rev=3684865","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/sumotori-dash-agent\/assets\/screenshot-1.png?rev=3684865","caption":""},{"src":"https:\/\/ps.w.org\/sumotori-dash-agent\/assets\/screenshot-2.png?rev=3684865","caption":""}],"raw_content":"<!--section=description-->\n<p>Sumotori Dash Agent is a connector. It links a WordPress site to the monitoring\ndashboard of your choice \u2014 the one you use to keep an eye on the sites you\nmaintain.<\/p>\n\n<p><strong>The plugin ships with no service address.<\/strong> You enter the dashboard URL\nyourself when pairing, and <strong>nothing is transmitted until the site is paired<\/strong>.\nSee the \"External services\" section below for the exhaustive list of the data\nexchanged.<\/p>\n\n<h4>What the agent does<\/h4>\n\n<ul>\n<li><strong>Pairing by code<\/strong>: you paste a short code displayed by your dashboard into\nthe settings screen; the agent then obtains the endpoint and the shared secret\nby itself. No secret has to be copied by hand. The same pairing can be\ntriggered from WP-CLI, or by an administrator through this site's own REST API\n\u2014 useful when the plugin was installed remotely and nobody is going to open\nwp-admin to copy a code.<\/li>\n<li><strong>Administration event reporting<\/strong>: creation or promotion of an administrator\naccount, administrator login, plugin activation or deactivation, completed\nupdate, theme switch, account deletion. Every message is signed (HMAC-SHA256)\nand sent non-blocking: a slow or unreachable dashboard never slows the site\ndown.<\/li>\n<li><strong>Read-only inventory<\/strong>: the agent exposes two REST routes that <em>answer<\/em>\nrequests signed by your dashboard. They only write a response: no option is\nmodified, no task is scheduled, no command is executed.<\/li>\n<li><strong>Multisite<\/strong>: a single link for the whole network, managed from the network\nadministration. The inventory can target any sub-site.<\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>The agent never transmits passwords, password hashes, file contents, post\ncontents, or backup destination credentials (S3 keys, SFTP passwords, Google\nDrive tokens and the like). It does however transmit personal data about your\nadministrator accounts: see \"External services\".<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin communicates with <strong>a third-party monitoring dashboard<\/strong>, separate\nfrom this WordPress site.<\/p>\n\n<p><strong>Which service?<\/strong> There is no default service: no address is hardcoded in the\nplugin. The service contacted is the one whose <strong>URL you enter yourself<\/strong> in the\n\"Settings \u2192 Dash Agent\" screen when pairing (a <code>SUMOTORI_DASH_AGENT_URL<\/code>\nconstant may also be defined in <code>wp-config.php<\/code> to enforce that address). The\nendpoint actually used for subsequent messages is the one that service returns\nin its pairing response. The operator of that service is the person or company\nhosting it, and that operator publishes its own terms of use and privacy policy.<\/p>\n\n<p>The dashboard this plugin was written against is a self-hosted, open-source\napplication; you can run your own instance.<\/p>\n\n<p>Reference implementation: https:\/\/github.com\/tommybds\/wp-dashboard\nTerms of use: https:\/\/github.com\/tommybds\/wp-dashboard\/blob\/master\/TERMS.md\nPrivacy policy: https:\/\/github.com\/tommybds\/wp-dashboard\/blob\/master\/PRIVACY.md<\/p>\n\n<p><strong>No data is transmitted until the site is paired.<\/strong> Before pairing the plugin\nmakes no outbound request whatsoever, and its inventory REST routes answer 403 to\nevery call. The one route that answers before pairing is the pairing route\nitself (<code>\/wp-json\/sumotori-dash\/v1\/pair<\/code>), and only to a logged-in administrator\nof this site: it is how the pairing is started, and it reports no site data \u2014 it\nreturns nothing but the resulting link status.<\/p>\n\n<p>Exchanges happen in exactly three situations.<\/p>\n\n<h4>1. Pairing (one request, manually triggered)<\/h4>\n\n<p>When: only when an administrator submits a pairing code from the settings\nscreen, runs <code>wp dash-agent pair<\/code>, or triggers the pairing through this site's\nown REST API (<code>POST \/wp-json\/sumotori-dash\/v1\/pair<\/code>, reserved to the same\ncapability as the settings screen \u2014 see the FAQ). Whichever of the three routes\nis used, the request below is the very first thing the plugin ever sends: <strong>no\ndata leaves the site before it<\/strong>.\nWhere: <code>POST &lt;dashboard URL&gt;\/api\/pair<\/code>.\nData transmitted:<\/p>\n\n<ul>\n<li>the pairing code you entered;<\/li>\n<li>the URL of this site (<code>home_url()<\/code>, or <code>network_site_url()<\/code> on multisite);<\/li>\n<li>the agent version number;<\/li>\n<li>a boolean telling whether the installation is a multisite.<\/li>\n<\/ul>\n\n<p>In return, the service sends back the event endpoint and a shared secret, which\nare stored in this site's database.<\/p>\n\n<h4>2. Administration events (one request per event)<\/h4>\n\n<p>When: on each event listed below, for as long as the site is paired.\nWhere: <code>POST &lt;endpoint returned at pairing&gt;<\/code>, sent non-blocking, 2-second\ntimeout, signed with the <code>X-Viz-Site<\/code>, <code>X-Viz-Timestamp<\/code> and <code>X-Viz-Signature<\/code>\nheaders.\nEvery message contains the site URL, the event name, a timestamp and, on\nmultisite, the ID and URL of the sub-site concerned. Depending on the event, it\nalso contains:<\/p>\n\n<ul>\n<li><strong>Administrator account created \/ promoted to administrator<\/strong>: numeric ID,\n<strong>login name<\/strong>, <strong>email address<\/strong> and role list of the account concerned.<\/li>\n<li><strong>Administrator login<\/strong>: numeric ID, <strong>login name<\/strong>, <strong>email address<\/strong> and the\n<strong>IP address<\/strong> the login came from.<\/li>\n<li><strong>Promotion to super administrator<\/strong> (multisite): numeric ID, login name and\nemail address.<\/li>\n<li><strong>Plugin activated \/ deactivated<\/strong>: plugin file path and scope (network or\nsite).<\/li>\n<li><strong>Update completed<\/strong>: type (plugin, theme, core), action, and the list of\nupdated items.<\/li>\n<li><strong>Theme switched<\/strong>: new theme name, incoming and outgoing stylesheets.<\/li>\n<li><strong>Account deleted<\/strong>: numeric ID and login name of the deleted account, ID of\nthe reassignment account.<\/li>\n<li><strong>Sub-site created<\/strong> (multisite): ID, URL and name of the sub-site.<\/li>\n<\/ul>\n\n<h4>3. Answers to inventory requests (no outbound request)<\/h4>\n\n<p>When: when the dashboard queries this site at\n    GET \/wp-json\/sumotori-dash\/v1\/inventory or\n    GET \/wp-json\/sumotori-dash\/v1\/sites. These requests must carry a valid HMAC\nsignature, computed with the shared secret and timestamped (300-second window);\nany other request gets a 403. The plugin contacts nobody in this case: it merely\nanswers.\nData transmitted in the response:<\/p>\n\n<ul>\n<li>WordPress version and pending core update where applicable;<\/li>\n<li>site URL and name, PHP version;<\/li>\n<li><strong>inventory of installed plugins<\/strong>: slug, activation state, installed version,\nwhether an update is pending and the target version;<\/li>\n<li><strong>inventory of installed themes<\/strong>: directory slug, display name, state (active,\nparent theme of the active child theme, or inactive), installed version,\nwhether an update is pending and the target version, and the slug of the parent\ntheme for a child theme;<\/li>\n<li>number of themes with a pending update;<\/li>\n<li><strong>administrator accounts<\/strong>: numeric ID, <strong>login name<\/strong>, <strong>email address<\/strong> and\nregistration date;<\/li>\n<li><strong>UpdraftPlus backup settings<\/strong> when it is installed: file and database backup\nfrequency, retention rules (including additional weekly or monthly rules),\n<strong>names<\/strong> of the configured destinations and the timestamp of the last backup;<\/li>\n<li>number of plugins set to auto-update;<\/li>\n<li>if the VizProof Timeline plugin is active on the site: its version, the number\nof pages it watches, a boolean telling whether it is connected to its own\nservice (its API token is never transmitted, only its <em>presence<\/em> is reported),\nand the ID, state and date of its last check;<\/li>\n<li>on multisite: number of sub-sites, network-activated plugins, <strong>super\nadministrators<\/strong> (login name, numeric ID, email address) and the list of\nsub-sites (ID, URL, name).<\/li>\n<\/ul>\n\n<h4>Never transmitted<\/h4>\n\n<p>Passwords, password hashes, file contents, post contents, third-party service\nAPI keys, and backup destination credentials (only the destination <em>names<\/em> are\nreported).<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li>Open \"Settings \u2192 Dash Agent\" (on multisite: \"Settings\" in the network\nadministration).<\/li>\n<li>Enter the https URL of your dashboard and the pairing code it shows you, then\nsubmit.<\/li>\n<li>The site is paired: administration events are reported and the dashboard can\nquery the inventory.<\/li>\n<\/ol>\n\n<p>To unlink the site, return to the same screen and click \"Disconnect this site\":\nno further data is transmitted.<\/p>\n\n<h4>Command-line installation<\/h4>\n\n<pre><code>wp plugin activate sumotori-dash-agent\nwp dash-agent pair --url=https:\/\/your-dashboard.example --code=XXXXXX\nwp dash-agent status\nwp dash-agent disconnect\n<\/code><\/pre>\n\n<h4>Pairing without opening wp-admin<\/h4>\n\n<p>If you have no shell access to the site, an administrator can start the same\npairing over this site's REST API. See \"Can a dashboard pair the site without\nopening wp-admin?\" in the FAQ below.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20send%20anything%20before%20pairing%3F\"><h3>Does the plugin send anything before pairing?<\/h3><\/dt>\n<dd><p>No. As long as the site is not paired, no event hook is even registered and the\ninventory REST routes answer 403. The only thing that starts an exchange is an\nadministrator deliberately pairing the site, from the settings screen, from\nWP-CLI, or through the <code>\/pair<\/code> REST route.<\/p><\/dd>\n<dt id=\"where%20is%20the%20dashboard%20address%20set%3F\"><h3>Where is the dashboard address set?<\/h3><\/dt>\n<dd><p>You enter it when pairing. No address is hardcoded in the plugin. If you manage\na fleet of sites, you can also enforce it in <code>wp-config.php<\/code>:<\/p>\n\n<pre><code>define( 'SUMOTORI_DASH_AGENT_URL', 'https:\/\/your-dashboard.example' );\n<\/code><\/pre>\n\n<p>The settings screen field then displays that value instead of being editable.<\/p><\/dd>\n<dt id=\"what%20is%20left%20in%20the%20database%20after%20uninstalling%3F\"><h3>What is left in the database after uninstalling?<\/h3><\/dt>\n<dd><p>Nothing. Deleting the plugin erases the configuration option: the site option,\nthe network option, and any options left on sub-sites.<\/p><\/dd>\n<dt id=\"can%20a%20dashboard%20pair%20the%20site%20without%20opening%20wp-admin%3F\"><h3>Can a dashboard pair the site without opening wp-admin?<\/h3><\/dt>\n<dd><p>Yes, since version 1.4.0. An administrator of the site \u2014 in practice a dashboard\nauthenticating with an administrator application password the site owner issued\nto it \u2014 can call this site's own REST API:<\/p>\n\n<pre><code>POST \/wp-json\/sumotori-dash\/v1\/pair\n{\"url\": \"https:\/\/your-dashboard.example\", \"code\": \"XXXX-XXXX\"}\n<\/code><\/pre>\n\n<p>The agent then performs exactly the same exchange as the settings form: it calls\n    \/api\/pair and stores the endpoint and secret it gets back. The second\naccepted body registers the link directly, as <code>wp dash-agent connect<\/code> does:<\/p>\n\n<pre><code>POST \/wp-json\/sumotori-dash\/v1\/pair\n{\"endpoint\": \"https:\/\/your-dashboard.example\/api\/ingest\", \"secret\": \"\u2026\"}\n<\/code><\/pre>\n\n<p>Send one form or the other, never both. The endpoint must be an https URL and\nthe secret 16 to 512 printable characters with no space.<\/p>\n\n<p>Both forms require the <code>manage_options<\/code> capability (<code>manage_network_options<\/code> on\na multisite network) \u2014 exactly the capability the settings screen already\nrequires. The route therefore grants its caller nothing they could not already do\nby hand in wp-admin; anyone else gets a 403.<\/p>\n\n<p>A site that is already paired answers 409 and keeps its current link, unless the\nbody also carries <code>\"force\": true<\/code>.<\/p>\n\n<p>The answer to a successful call is:<\/p>\n\n<pre><code>{\"paired\": true, \"endpoint\": \"\u2026\", \"paired_at\": \"\u2026\", \"site_url\": \"\u2026\",\n \"agent_version\": \"\u2026\", \"message\": \"\u2026\"}\n<\/code><\/pre>\n\n<p><strong>The shared secret is never returned<\/strong>, never logged, and never quoted in an\nerror message. An invalid body gives a 400, a dashboard that cannot be reached or\nwhose answer cannot be read gives a 502.<\/p>\n\n<p>Finally, <code>DELETE \/wp-json\/sumotori-dash\/v1\/pair<\/code>, with the same capability,\nclears the link: it is the REST equivalent of the \"Disconnect this site\" button,\nso a dashboard can withdraw cleanly from a site it no longer manages.<\/p><\/dd>\n<dt id=\"can%20the%20inventory%20modify%20my%20site%3F\"><h3>Can the inventory modify my site?<\/h3><\/dt>\n<dd><p>No. Both inventory routes (<code>\/inventory<\/code> and <code>\/sites<\/code>) are read-only: they write\nno option, schedule no task, execute no command, and include no file whose path\nwould come from the request.<\/p>\n\n<p>The only route that writes anything is <code>\/pair<\/code>, and all it ever writes is the\nlink itself \u2014 the dashboard endpoint and the shared secret, the same single\noption the settings screen saves. It is reserved to administrators of the site,\nand it touches nothing else.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20work%20on%20multisite%3F\"><h3>Does the plugin work on multisite?<\/h3><\/dt>\n<dd><p>Yes. The link is unique for the whole network and is configured from the network\nadministration (<code>manage_network_options<\/code> capability). The inventory can target\nany sub-site through the <code>blog_id<\/code> parameter.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>The inventory answer now carries the <strong>list of installed themes<\/strong>, not only a\ncount of the ones awaiting an update: for each theme its directory slug,\ndisplay name, state (active, parent theme of the active child theme, or\ninactive), installed version, whether an update is pending and the target\nversion, and the parent theme of a child theme. A dashboard can therefore\nshow the themes of a site and cross-check them against a public vulnerability\ndatabase, as it already does for plugins. At most 100 themes are listed.<\/li>\n<li>On multisite, the state of each theme is reported for the sub-site being\ninventoried, exactly as the plugin inventory already does.<\/li>\n<li>The existing <code>themes_updates<\/code> count is unchanged, so dashboards written\nagainst an earlier version keep working.<\/li>\n<li>Nothing else moves: the inventory stays strictly read-only, no personal data\nis added \u2014 a theme name and a version number are not personal data \u2014 and no\noutbound request is made.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>The site can now be paired without anyone opening wp-admin, through a new REST\nroute <code>POST \/wp-json\/sumotori-dash\/v1\/pair<\/code>. The body carries either\n  url + <code>code<\/code>, which runs exactly the same exchange as the settings form, or\n  endpoint + <code>secret<\/code>, the equivalent of <code>wp dash-agent connect<\/code>. This closes\nthe last gap for a dashboard that installed the agent remotely and has no shell\naccess to the site: until now a human had to copy a code by hand.<\/li>\n<li>The route requires <code>manage_options<\/code> (<code>manage_network_options<\/code> on multisite) \u2014\nthe very capability the settings screen already requires \u2014 so it grants its\ncaller nothing they could not already do from wp-admin. Every other request\ngets a 403.<\/li>\n<li>An already paired site answers 409 and keeps its link unless the body carries\n  \"force\": true. An invalid body gives a 400, an unreachable or unreadable\ndashboard a 502.<\/li>\n<li>The shared secret is never included in the answer, in an error message, or in\nany log.<\/li>\n<li>New <code>DELETE \/wp-json\/sumotori-dash\/v1\/pair<\/code>, same capability, clearing the\nlink: the REST equivalent of the \"Disconnect this site\" button.<\/li>\n<li>The shared secret is now validated on every path \u2014 settings screen, WP-CLI and\nREST alike: 16 to 512 printable characters, no space and no control character.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Removed the \"Protect the agent against deactivation\" option, which copied the\nagent file into <code>wp-content\/mu-plugins\/<\/code>. Plugins are not meant to write\nexecutable code outside their own directory, so the feature has been dropped\nentirely rather than kept behind a checkbox. The agent is now an ordinary\nplugin that is activated, deactivated and uninstalled like any other.<\/li>\n<li><code>uninstall.php<\/code> no longer touches the <code>mu-plugins<\/code> directory.<\/li>\n<li>Internal version constant realigned with the plugin header.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Plugin URI corrected to a page that actually resolves.<\/li>\n<li>Translation files removed from the package: translations are now handled by\ntranslate.wordpress.org, which generates and delivers them automatically.<\/li>\n<li><code>load_plugin_textdomain()<\/code> removed \u2014 WordPress has loaded translations by\nitself for plugins hosted on WordPress.org since version 4.6.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>The <code>mu-plugins<\/code> copy becomes an explicit option, disabled by default, with a\n\"Remove from mu-plugins\" button. It is no longer performed automatically on\nactivation: the plugin stays normally deactivatable and uninstallable.<\/li>\n<li>The dashboard URL is now entered by the administrator when pairing: no service\naddress is embedded in the plugin any more.<\/li>\n<li>Added <code>uninstall.php<\/code>: uninstalling erases all options and the mu-plugins copy.<\/li>\n<li>All visible strings go through the translation functions (text domain\n  sumotori-dash-agent) and a <code>.pot<\/code> template is provided.<\/li>\n<li>Compliance review: output escaping, input sanitising, nonce and capability\ncheck on every action, unique prefix, removal of error-log writes.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Pairing by code from the settings screen and from WP-CLI.<\/li>\n<li>Multisite support: single network link, network block in the inventory,\n  \/sites route, <code>blog_id<\/code> parameter.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release: administration event reporting and read-only REST inventory.<\/li>\n<\/ul>","raw_excerpt":"Connects this site to a monitoring dashboard you choose: reports administration events and answers signed, read-only inventory requests.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/360858","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=360858"}],"author":[{"embeddable":true,"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/tommybordas"}],"wp:attachment":[{"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=360858"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=360858"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=360858"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=360858"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=360858"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/li.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=360858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}