Plugin info

Total downloads: 1,092
Active installs: 10
Total reviews: 0
Average rating: 0
Support threads opened: 0
Support threads resolved: 0 (0%)
Available in: 2 language(s)
Contributors: 2
Last updated: 3/3/2018 (2860 days ago)
Added to WordPress: 2/24/2018 (7 years old)
Minimum WordPress version: 4.2.0
Tested up to WordPress version: 4.9.26
Minimum PHP version: f

Maintenance & Compatibility

Maintenance score

Possibly abandoned • Last updated 2860 days ago

20/100

Is DGXPCO abandoned?

Possibly abandoned (last update 2860 days ago).

Compatibility

Requires WordPress: 4.2.0
Tested up to: 4.9.26
Requires PHP: f

Similar & Alternatives

Explore plugins with similar tags, and compare key metrics like downloads, ratings, updates, support, and WP/PHP compatibility.

Disable Admin Notices individually
Rating 4.7/5 (347 reviews)Active installs 100,000
Easy Theme and Plugin Upgrades
Rating 4.7/5 (117 reviews)Active installs 80,000
WP Updates Notifier
Rating 4.2/5 (35 reviews)Active installs 30,000
Update Theme and Plugins from Zip File
Rating 4.9/5 (37 reviews)Active installs 10,000
Core Rollback
Rating 4.6/5 (13 reviews)Active installs 10,000
Auto Updater
Rating 5.0/5 (2 reviews)Active installs 3,000

Description

DGXPCO (Digital Guarantees for eXplicitly Permitted Core Operations) is a proof-of-concept cryptographic signature verification utility for WordPress software updates. The plugin will source manual (offline) signatures for WordPress core updates and prevent the application from updating unless the contents of the update payload are verified with a remote signature.

This provides a second source of truth for the integrity of WordPress updates beyond the MD5 content hash supplied in the header from the WordPress update server. If that server were ever breached, it’s unlikely the server hosting the signatures of the files was also breached. If the signatures ever fail to validate, you can know your site was protected from an attack.

Installation

Manual Installation

  1. Upload the entire /dgxpco directory to the /wp-content/plugins/ directory.
  2. Activate DGXPCO through the ‘Plugins’ menu in WordPress.

Frequently Asked Questions

Installation Instructions

Manual Installation

  1. Upload the entire /dgxpco directory to the /wp-content/plugins/ directory.
  2. Activate DGXPCO through the ‘Plugins’ menu in WordPress.

Who is responsible for the signatures

At the moment, Eric Mann will personally verify and sign every new update payload once it’s released by the core team. The signatures of each core file are hosted in a separate GitHub repository, with every commit signed by Eric’s GPG private key for redundant verification.

Review feed

No reviews available

Screenshots

No screenshots available

Changelog

1.2.0

  • Filter the upgrade cache to avoid prompting core upgrades with missing signatures.

1.1.0

  • Introduce integration test for full core compatibility guarantees.

1.0.0

  • First release