Plugin Security
Plugin Licensing & Security
How Drecha protects plugin downloads, matches licenses to websites, and responds when a license is revoked.
1. License validation
A validation request must match the license key, plugin, activated website domain, and installation identifier stored by Drecha. A valid key used from a different domain or installation is rejected.
2. Periodic checks
Drecha plugins are expected to validate on activation and periodically while installed. This lets the plugin receive current license status after a refund, chargeback, manual revocation, or activation change. The server stops confirming a revoked license immediately; an installation learns that status on its next check.
3. Protected downloads and updates
Plugin packages are not public files. Downloads use short-lived, limited-use tokens connected to an active license. Update packages are issued only after a successful license and website validation.
4. Data minimization
License checks are designed around licensing metadata, not WordPress content. We do not need post content, product data, event data, or customer order contents to validate a license.