{"id":378847,"date":"2026-10-01T08:22:18","date_gmt":"2026-10-01T08:22:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/tugracyber\/"},"modified":"2026-10-01T08:21:49","modified_gmt":"2026-10-01T08:21:49","slug":"tugracyber","status":"publish","type":"plugin","link":"https:\/\/pan.wordpress.org\/plugins\/tugracyber\/","author":23576719,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.0","stable_tag":"0.1.0","tested":"7.1.2","requires":"5.8","requires_php":"7.2","requires_plugins":null,"header_name":"TugraCyber","header_author":"TugraCyber","header_description":"Monitors third-party scripts on your WooCommerce checkout page, alerts on unauthorized changes and produces a PCI DSS 4.0.1 (6.4.3 \/ 11.6.1) compliance report.","assets_banners_color":"060606","last_updated":"2026-10-01 08:21:49","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/tugracyber.com","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":45,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.0":{"tag":"0.1.0","author":"skromets","date":"2026-10-01 08:21:49","revision":3722656}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3722655,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3722655,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3722655,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3722655,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[3148,245444,265161,600,286],"plugin_category":[45,54],"plugin_contributors":[283843],"plugin_business_model":[],"class_list":["post-378847","plugin","type-plugin","status-publish","hentry","plugin_tags-checkout","plugin_tags-magecart","plugin_tags-pci-dss","plugin_tags-security","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-skromets","plugin_committers-skromets"],"banners":{"banner":"https:\/\/ps.w.org\/tugracyber\/assets\/banner-772x250.png?rev=3722655","banner_2x":"https:\/\/ps.w.org\/tugracyber\/assets\/banner-1544x500.png?rev=3722655","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/tugracyber\/assets\/icon-128x128.png?rev=3722655","icon_2x":"https:\/\/ps.w.org\/tugracyber\/assets\/icon-256x256.png?rev=3722655","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>TugraCyber keeps an inventory of every script running on your checkout page and alerts you when a script's content changes silently, which is the signature of Magecart-style card skimming attacks.<\/p>\n\n<ul>\n<li><strong>Runs only on the checkout page.<\/strong> This is exactly the scope of PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1.<\/li>\n<li><strong>Script inventory.<\/strong> A SHA-256 hash of each script's content is recorded, so silent changes are caught immediately.<\/li>\n<li><strong>Removed and returning script detection.<\/strong> You get an alert when a known script disappears from the page, or reappears after being marked as removed.<\/li>\n<li><strong>PCI DSS 6.4.3\/11.6.1 report.<\/strong> Available from the dashboard in your TugraCyber account.<\/li>\n<\/ul>\n\n<p>This plugin only adds the monitoring agent to your checkout page. The dashboard, alerts and reports live in your <a href=\"https:\/\/tugracyber.com\">TugraCyber<\/a> account. Setup requires an account and a collector address.<\/p>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WooCommerce must be active (monitoring runs only on the WooCommerce checkout page).<\/li>\n<li>A TugraCyber account and a collector address.<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>Through the monitoring script (agent) it places on your checkout page, this plugin sends data to the <strong>Collector Endpoint<\/strong> address you enter on the settings page. This address is empty by default: the plugin can be installed, but no data is sent anywhere until you enter an address.<\/p>\n\n<p>For each script loaded on the checkout page, the data sent is:<\/p>\n\n<ul>\n<li>the script's URL (src),<\/li>\n<li>the SHA-256 hash of the script's content (not the content itself; the hash is an irreversible digest),<\/li>\n<li>the script type (inline or external) and your site ID.<\/li>\n<\/ul>\n\n<p>Page content, customer data, payment information and card numbers are <strong>never<\/strong> collected or sent.<\/p>\n\n<p>If you enter the TugraCyber hosted service at https:\/\/tugracyber.com as the Collector Endpoint, data is sent to that service and the following apply:<\/p>\n\n<ul>\n<li>Terms of Service: https:\/\/tugracyber.com\/terms<\/li>\n<li>Privacy Policy: https:\/\/tugracyber.com\/privacy<\/li>\n<\/ul>\n\n<p>Alternatively, you can enter the address of a TugraCyber collector instance running on your own server. In that case data goes only to a server under your control and nothing is sent to any third party.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload and activate the plugin.<\/li>\n<li>Go to Settings &gt; TugraCyber.<\/li>\n<li>Enter the collector endpoint of your TugraCyber account and save.<\/li>\n<li>Visit your checkout page once. The first script inventory is sent automatically.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"which%20pages%20does%20this%20plugin%20run%20on%3F\"><h3>Which pages does this plugin run on?<\/h3><\/dt>\n<dd><p>Only the WooCommerce checkout page. It does nothing on other pages.<\/p><\/dd>\n<dt id=\"i%20don%27t%20have%20a%20tugracyber%20account.%20can%20i%20still%20install%20it%3F\"><h3>I don't have a TugraCyber account. Can I still install it?<\/h3><\/dt>\n<dd><p>Yes, but monitoring does not start until a collector address is entered.<\/p><\/dd>\n<dt id=\"what%20data%20does%20the%20plugin%20send%3F\"><h3>What data does the plugin send?<\/h3><\/dt>\n<dd><p>Only the URL and SHA-256 content hash of the scripts on the checkout page. See the \"External Services\" section above. Page content and customer or payment data are never sent.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release: agent injection on the checkout page, settings page, automatic site ID and write key generation.<\/li>\n<\/ul>","raw_excerpt":"Monitors third-party scripts on your WooCommerce checkout, detects tampering and produces a PCI DSS 6.4.3\/11.6.1 report.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/378847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=378847"}],"author":[{"embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/skromets"}],"wp:attachment":[{"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=378847"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=378847"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=378847"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=378847"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=378847"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pan.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=378847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}