Security & Privacy
API keys, license keys, permissions, nonces and log redaction.
Administrator permissions
Instant Languages admin pages use the WordPress manage_options capability. Administrative POST/AJAX actions use WordPress nonces and capability checks.
Provider secrets
Provider keys are used server-side. Saved secret fields are not printed back into Settings HTML. Frontend visitors do not receive the DeepL or Google API key.
Log redaction
Diagnostic context is sanitized/redacted before storage for common secret categories including API keys, authorization headers, tokens, passwords, cookies and nonces.
Visual Editor
Visual Editor parameters include an explicit content ID, target language and nonce. It opens the original permalink rather than embedding the site in an iframe.
Shortcode scanning
Executing third-party shortcodes during a scan can have side effects if a badly designed shortcode performs actions instead of rendering content. Use the ist_scan_shortcode filter to exclude known unsafe shortcodes.
Uninstall
The plugin can optionally delete all plugin tables/data when uninstalled. Keep this option disabled unless permanent deletion is intended.
Commercial license data
License keys are used only in server-side WordPress requests to the Stardetha licensing store. The admin License screen displays a masked key after activation. License keys are not sent to the public frontend language-switcher JavaScript. Remote checks use HTTPS with SSL verification enabled. A temporary connectivity failure can use the last successful entitlement for the configured 14-day grace period.