Security & Trust

How Ingestics keeps your credentials and content safe

Ingestics runs entirely inside your WordPress install and handles API keys, tokens, and imported content with encryption, request validation, and review-first controls at every stage. This page explains what happens in plain language, with code-level detail available in the documentation.

Credential handling

Every secret is encrypted before it touches the database

API keys, tokens, license keys, and Basic-auth usernames are never stored as plain text.

AES-256-CBC encryption

Provider secrets, license keys, Basic-auth usernames, and any custom header flagged as secret are encrypted at rest using AES-256-CBC.

HMAC-SHA256 verification

An encrypt-then-MAC scheme (HMAC-SHA256) protects stored secrets from tampering, not just exposure.

Credential redaction

Diagnostic URLs and admin API responses mask credential parameters and common signature/secret/password fields, so plaintext secrets never appear in logs or previews.

Nonce-protected admin actions

The admin AJAX surface is guarded by nonce and capability checks throughout, so requests must originate from an authenticated, authorized session.

Outbound request safety

Requests are validated before they run

Every outbound connection Ingestics makes passes through a security gate first.

Scheme allowlist restricts outbound requests to HTTP and HTTPS only — no other protocol can be targeted.

Host safety validation and DNS resolution caching block SSRF-style attacks that try to reach internal or unintended hosts.

Response-size budgets cap payload size on every outbound request path — API, RSS, licensing, AI, translation, OAuth, and more.

Review-first publishing

Nothing has to publish automatically

Ingestics is built so imported content passes through a checkpoint before it goes live, not around one.

Planned and last-call previews

Preview what will be imported and published before it happens, on every plan including Free.

Publish, Draft, or Pending modes

Choose whether imported items go live immediately or wait in Draft or Pending review status.

Filters and quality gates

Duplicate detection and content filters run before publishing, reducing unwanted or repeat content reaching your site.

Structurally tier-gated features

Paid-tier feature code is physically absent from the free-distribution files, not just flagged off — a stronger guarantee than a typical license check.

Import & file handling

File imports are validated before they’re trusted

Spreadsheet (XLSX) imports go through bounded archive validation — entry count limits, decompressed size limits, and compression-ratio bomb protection.

Imported files are stored outside the web root where possible; if a fallback location must be used, it must pass a randomized loopback-denial probe or the import fails closed.

Inbound webhook triggers are rate-limited with single-shot, lock-protected consumption to prevent replay abuse.

Data on deactivation

Deactivating the plugin doesn’t delete your work

Deactivation and uninstall cleanup explicitly preserves your providers, credentials, settings, logs, import sources, and every post already published. Only operational schedules, locks, and queues are cleared.

Read the technical implementation details

The summary above covers what Ingestics does and why. For request-level and configuration-level detail, see the documentation.