Security & privacy
What we record, and what we never touch.
Stated once, properly, so you don’t have to take it on faith from a readme.
The rules
- Your visitors’ content is never read, stored or transmitted. Where a product observes something failing, it records a classified error code and a status number — not the message, not the address, not the payload.
- No product phones home. Our shipped plugins make no external requests. Where a future product genuinely needs an external service, that page will say exactly what is sent and where, before you install it.
- No account required unless a product cannot function without one, and none of them currently do.
- Nothing is added to your front end. No tracking script, no pixel, no third-party asset. Your visitors load exactly what they loaded before.
- Credentials stay server-side. Where a product holds a third-party credential, it is never exposed to viewers or the browser.
How they are enforced
These are tests, not intentions. The rule that a product may not record message content is a test that fails the build if it is broken — which means it cannot be quietly regressed by a later change. Every product also passes Plugin Check, WordPress.org’s own review tool, against a live install.
This site holds to the same rule. It runs no JavaScript, sets no cookies, and loads no third-party assets — the fonts are served from this domain. There is no analytics on this page.
Reporting something
If you believe you have found a security issue in one of our products, email marketplace@unfussyworks.com with the product name and enough detail to reproduce it. We will confirm receipt within two business days and tell you what we intend to do. Please give us a chance to ship a fix before disclosing publicly.