Plugin Security

Plugin Licensing & Security

How Drecha protects plugin downloads, matches licenses to websites, and responds when a license is revoked.

Last updated October 10, 2026
Support

1. License validation

A validation request must match the license key, plugin, activated website domain, and installation identifier stored by Drecha. A valid key used from a different domain or installation is rejected.

2. Periodic checks

Drecha plugins are expected to validate on activation and periodically while installed. This lets the plugin receive current license status after a refund, chargeback, manual revocation, or activation change. The server stops confirming a revoked license immediately; an installation learns that status on its next check.

3. Protected downloads and updates

Plugin packages are not public files. Downloads use short-lived, limited-use tokens connected to an active license. Update packages are issued only after a successful license and website validation.

4. Data minimization

License checks are designed around licensing metadata, not WordPress content. We do not need post content, product data, event data, or customer order contents to validate a license.

Functional cookies only

Saaso only uses functional cookies for sign-in, security, and core product flows. By continuing to use the site, you agree to that use.