Title: Tendrix Connector
Author: tendrixplatform
Published: <strong>October 7, 2026</strong>
Last modified: October 7, 2026

---

Search plugins

![](https://ps.w.org/tendrix-connector/assets/banner-772x250.png?rev=3731709)

![](https://ps.w.org/tendrix-connector/assets/icon-256x256.png?rev=3731709)

# Tendrix Connector

 By [tendrixplatform](https://profiles.wordpress.org/tendrixplatform/)

[Download](https://downloads.wordpress.org/plugin/tendrix-connector.0.26.1.zip)

 * [Details](https://mfe.wordpress.org/plugins/tendrix-connector/#description)
 * [Reviews](https://mfe.wordpress.org/plugins/tendrix-connector/#reviews)
 *  [Installation](https://mfe.wordpress.org/plugins/tendrix-connector/#installation)
 * [Development](https://mfe.wordpress.org/plugins/tendrix-connector/#developers)

 [Support](https://wordpress.org/support/plugin/tendrix-connector/)

## Description

Tendrix Connector is the client side of a two-plugin system. It is installed on 
a site that
 somebody maintains for you, or that you maintain for a client, and 
it reports to an **Tendrix Hub** running on a WordPress site that you or your agency
owns.

There is no third-party service. This plugin talks to one Hub and only to the Hub
you paired
 it with, whose address is pinned at pairing time and cannot be changed
by a request.

**What it does**

 * Sends a heartbeat every five minutes, with the site’s technical inventory when
   something changed.
 * Runs local audits when the Hub asks: security, pending updates, health, SEO, 
   broken links, accessibility and file integrity.
 * Executes commands from a closed list, and refuses anything else without interpreting
   it. The list covers audits, inventory, image optimisation and alt text, cache
   purging, database cleanup and backups: content, data and cache, never site administration.
   With the free Tendrix Hub the connector only runs audits and sends its inventory;
   the other commands are sent only by the Tendrix Hub Pro add-on.
 * Records fatal errors and outgoing mail failures so they can be diagnosed from
   the Hub.
 * Recompresses and resizes the images the Hub selects, keeping a copy of each original.
 * Carries the daily counts of Tendrix Chat and Tendrix Consent, when they are installed.
   Anything that is not a whole number is dropped before sending, so no plugin can
   use this channel for personal data.

**What it never does**

 * It does not execute code sent by the Hub. The Hub sends the name of a command
   from a fixed list, never code, never a file path and never SQL.
 * It does not send your users’ names, e-mail addresses or content. People are reported
   as counts per role. Mail diagnostics mask the recipient (`m***@gmail.com`).
 * It does not install, update, activate or delete plugins, themes or WordPress 
   core. The Hub shows which updates are pending; an administrator of this site 
   applies them from its own dashboard.
 * It does not open sessions on this site, create users or change their roles.
 * It does not change site settings, permalinks, robots.txt, security settings or
   plugin databases, and it does not delete files from the site. Those are changed
   by an administrator of this site from its own dashboard.
 * It does not accept instructions on its public endpoint. The one inbound route
   only wakes the plugin up, carries no orders, and requires the same signature 
   as everything else.

**File integrity**

When the Hub asks for it, the connector hashes the WordPress core files and the 
files of
 plugins that come from the wordpress.org directory, compares them against
the official checksums published by wordpress.org, and looks for executable PHP 
inside the uploads folder.

This is an integrity canary, not an antivirus. It proves that a file is not the 
one that was
 distributed. It says nothing about a malicious plugin whose files 
are intact, and it never deletes or quarantines anything: it reports, and a person
decides.

**Communication and security**

The connector always initiates the connection outwards. The single inbound route,
/
tendrix-conector/v1/wake, does not carry orders: it tells the plugin to run its 
cycle now, and the plugin then asks the Hub for work over its usual signed outbound
channel. If your host blocks incoming requests, nothing is lost: the five minute
cycle picks the work up anyway.

Every request is signed with HMAC-SHA256 over the method, path, timestamp, nonce
and a hash
 of the body, compared in constant time, with a five minute clock window
and single-use nonces. The shared secret is created at pairing time and is deleted
from this site when you unpair.

### External services

**The Tendrix Hub you paired it with**

Its address is entered by an administrator of this site during pairing, is stored,
and cannot
 be changed by an incoming request. Sending data to it is the entire 
purpose of the plugin.

What is sent: WordPress, PHP and server versions and settings; the list of installed
plugins
 and themes with their versions; database size and table statistics; counts
of posts, pages, comments, media and users per role; security and SEO configuration;
audit findings; fatal error messages with the file, line and URL where they happened,
with server paths trimmed; and the recipient domain, subject and status of recent
outgoing mail.

What is never sent: post or page content, passwords, user names or user e-mail addresses.

**api.wordpress.org**

Used only during a file integrity audit, to fetch the official checksums for the
WordPress
 version this site runs. What is sent: the WordPress version and the site
language. This is the same request WordPress itself makes through its own `get_core_checksums()`
function. Provided by the WordPress Foundation. Terms and privacy: https://wordpress.
org/about/privacy/

**downloads.wordpress.org**

Used only during a file integrity audit, to fetch the published checksums of installed

plugins. What is sent: the slug and version of a plugin, in the URL. Nothing about
this site is included, and the answer is cached for a week. Provided by the WordPress
Foundation. Terms and privacy: https://wordpress.org/about/privacy/

No data is sent to the author of this plugin, and there is no telemetry.

## Installation

 1. Ask whoever runs your Tendrix Hub for the Hub URL and a pairing code.
 2. Install and activate this plugin.
 3. Go to **Settings  Tendrix Connector**, enter the Hub URL and the pairing code, 
    and press **Pair site**.

That is all that is done here. Audits and actions are launched from the Hub.

To disconnect, press **Unpair and delete secret** on the same screen. The credential
stops
 working immediately and the secret is removed from this site.

Multisite is not supported and is refused at pairing time.

## FAQ

### Who can send commands to this site?

Only the Hub you paired with, and only commands from a fixed list. Every request
must carry
 a valid signature made with a secret that exists on both ends and nowhere
else.

### What happens if my host blocks incoming requests?

Nothing breaks. The inbound route is only a shortcut that says “run now”. The plugin’s
own
 five minute cycle picks up any pending work regardless.

### How do I stop it completely?

Unpair it on its settings screen, or deactivate the plugin. Unpairing deletes the
shared
 secret from this site.

### Does it slow my site down?

The full inventory is only sent when its hash changed, not on every heartbeat. Audits
run
 when the Hub asks for them, not on visitor requests.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Tendrix Connector” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ tendrixplatform ](https://profiles.wordpress.org/tendrixplatform/)

[Translate “Tendrix Connector” into your language.](https://translate.wordpress.org/projects/wp-plugins/tendrix-connector)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/tendrix-connector/),
check out the [SVN repository](https://plugins.svn.wordpress.org/tendrix-connector/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/tendrix-connector/)
by [RSS](https://plugins.trac.wordpress.org/log/tendrix-connector/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.26.1

 * Fix: audits never collected internal links (the pattern that finds them was malformed,
   so PHP discarded it with a warning).

#### 0.26.0

 * Removed: remote configuration changes (WordPress settings, indexing, permalinks,
   robots.txt, security hardening, deleting exposed files and plugin database updates).
   The Hub reports them as findings; an administrator of the site applies them.
 * No longer deactivates the old Tendrix Agent plugin by itself. Its settings are
   still moved over, and a notice suggests deactivating it.
 * Transient names now use the plugin prefix.

#### 0.25.0

 * Removed: installing, updating, activating and deleting plugins and themes, updating
   WordPress core, restoring a full backup, managing users, opening the dashboard
   from the Hub and renaming this plugin in the plugin list. The connector now reports
   and applies configuration fixes only; updates are applied by an administrator
   of the site.
 * Security hardening toggles are applied by the connector itself with filters instead
   of writing a must-use plugin. The file left by earlier versions is removed the
   next time a toggle changes, or on uninstall.

#### 0.24.4

 * Fixed: a one-off fatal from replacing the plugin ZIP kept showing as a critical
   finding. Updating clears the connector’s own fatals, and fatals older than 7 
   days are no longer reported.

#### 0.24.3

 * Settings  Tendrix Connector has a Test connection now button: it checks pairing,
   the five-minute cycle, the heartbeat (HTTP status, response and clock difference
   with the Hub), the inventory, the Chat and Consent report and the job queue, 
   and shows the result step by step.
 * A PHP fatal error in the middle of a cycle is now recorded as the last error,
   with file and line.

#### 0.24.2

 * Fixed: after moving from the old tendrix-conector folder to tendrix-connector,
   deactivating the old copy removed the five-minute cycle of the new one. The heartbeat
   stopped without logging any error and the site showed as offline while audits
   still worked. The cycle is now rescheduled automatically whenever it is missing.

#### 0.24.1

 * Fixed: a site could stay offline forever. The heartbeat carried the full inventory,
   so when sending the inventory failed (a hosting firewall, a size limit, a timeout)
   the heartbeat failed too, the inventory stayed pending for the next one and the
   connector ended up paused. The heartbeat is now sent on its own first and the
   inventory goes separately.
 * A connector paused after repeated failures retries once an hour and resumes by
   itself when the Hub answers. A revoked credential still stops it.
 * The last error (step, HTTP status and message) is shown under Settings  Tendrix
   Connector and reported to the Hub’s activity log.

#### 0.24.0

 * Text domain is now `tendrix-connector`, matching the plugin slug.
 * Plugins and themes are installed only from the wordpress.org directory. Installing
   a zip uploaded to the Hub is removed.
 * The plugin row can no longer be hidden from the plugin list.
 * Tested with WordPress 7.1.

#### 0.23.0

 * **Full backup and restore**: wp-content and the database in one zip, kept on 
   the site with web access closed. Restoring backs up the current database first
   and keeps the connection to the Hub.
 * **Users**: create, change role, send a password reset and delete (content goes
   to the site administrator). The Hub only ever sees masked usernames (`a***n`)
   and roles.
 * **Plugins uploaded to the Hub**: installed only from the paired Hub’s address
   and only if the file matches its hash.
 * **WordPress settings in bulk** from a closed list of options, reporting the previous
   value of each.
 * **Purge cache** of the common caching plugins, and **WooCommerce and Elementor
   database updates**.
 * **WooCommerce summary**: daily orders and sales in the heartbeat, as counts and
   totals only.
 * Reads the last UpdraftPlus backup and open Wordfence issues, and can start either.

#### 0.22.0

 * The heartbeat carries the daily counts of Tendrix Chat and Tendrix Consent. The
   connector keeps only whole numbers and short keys from them, whatever those plugins
   send.
 * Two more commands, only when their plugin is active: chat.configure and consent.
   configure. The list stays closed: no other name can be added.

#### 0.21.0

 * The Hub can send an image into this site’s media library. It never pushes the
   file: it sends an address on the Hub and the sha256 of what will be found there,
   this plugin downloads it over its usual outbound channel and checks the hash 
   before touching anything. The address must be on the Hub this site is paired 
   with, the content must really be a JPEG, PNG or WebP, and WordPress does the 
   rest through its own sideload. Undoing it deletes that attachment and only that
   one.
 * Optimising raises its own time limit before starting, and batches are of ten:
   a job that dies halfway leaves files written and the Hub with no answer.

#### 0.20.0

 * Media library: the Hub can ask for it, heaviest first, and recompress and resize
   the images it picks in place, through the WordPress image editor (Imagick, or
   GD where Imagick is missing). The original file is copied first, so every optimisation
   can be undone; file names never change; an image that comes back heavier is put
   back as it was and reported as already optimal, which is an answer and not a 
   failure. How much each image lost is recorded on this site, so the panel can 
   show it even if the job that did it never reported back.

#### 0.19.0

 * Updates are checked before being kept: four numbers per sampled page, read before
   and after, and a rollback when a page comes back broken. The Hub is told which
   pages, not only that something failed.
 * New file integrity audit: core and plugin files against the official wordpress.
   org checksums, and executable PHP inside uploads.
 * A failed job can now carry a short detail alongside its error code, so the Hub
   can say where it failed and not only what failed.

#### 0.18.0

 * Every disk write now goes through the WordPress filesystem API, so nothing is
   written behind WordPress’s back on hosts where the web process does not own the
   files.
 * Browser input goes through one typed helper that unslashes and then sanitises.
 * English is now the source language, with a Spanish catalogue.

#### 0.17.0

 * Database maintenance: revisions, spam, trash, expired transients, orphaned metadata
   and table optimisation, in batches so a shared host stays up.
 * Database backup, written to a temporary name and only renamed when complete.
 * Single-use link to open this site’s dashboard from the Hub, with its own off 
   switch.
 * Optional renaming of this plugin’s row in the plugin list.

#### 0.16.1

 * Fatal error and outgoing mail diagnostics.
 * Configuration fixes: robots.txt, indexing, permalinks and hardening through a
   mu-plugin.

## Meta

 *  Version **0.26.1**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 8.1 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/tendrix-connector/)
 * Tags
 * [agency](https://mfe.wordpress.org/plugins/tags/agency/)[audit](https://mfe.wordpress.org/plugins/tags/audit/)
   [maintenance](https://mfe.wordpress.org/plugins/tags/maintenance/)[monitoring](https://mfe.wordpress.org/plugins/tags/monitoring/)
   [site health](https://mfe.wordpress.org/plugins/tags/site-health/)
 *  [Advanced View](https://mfe.wordpress.org/plugins/tendrix-connector/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/tendrix-connector/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/tendrix-connector/reviews/)

## Contributors

 *   [ tendrixplatform ](https://profiles.wordpress.org/tendrixplatform/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/tendrix-connector/)