{"id":358959,"date":"2026-09-07T10:32:49","date_gmt":"2026-09-07T10:32:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/nimble-security\/"},"modified":"2026-09-07T10:32:12","modified_gmt":"2026-09-07T10:32:12","slug":"nimble-security","status":"publish","type":"plugin","link":"https:\/\/te.wordpress.org\/plugins\/nimble-security\/","author":23555215,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.12","stable_tag":"1.1.12","tested":"7.1","requires":"6.6","requires_php":"8.1","requires_plugins":null,"header_name":"Nimble Security","header_author":"NimblePlugins","header_description":"High-end WordPress security with identity, integrity, firewall, malware detection, vulnerability inventory, quarantine, active containment, Emergency Lockdown, privacy-safe Operations telemetry and a modular Free\/Pro architecture.","assets_banners_color":"061527","last_updated":"2026-09-07 10:32:12","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/nimbleplugins.com\/nimble-security\/","header_author_uri":"https:\/\/nimbleplugins.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":44,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.12":{"tag":"1.1.12","author":"nimbleplugin","date":"2026-09-07 10:32:12","revision":3684666}},"upgrade_notice":{"1.1.12":"<p>Quarantine storage moves into the uploads directory and is migrated automatically. Extended Protection moves to the Pro add-on; if you use it, see the changelog before updating.<\/p>","1.1.11":"<p>Removes the licence client entirely. Every protection engine is unchanged.<\/p>","1.1.10":"<p>Licence screen wording and visibility only. No behaviour change; safe to update.<\/p>","1.1.9":"<p>Wording only on the licence screen. No behaviour change; safe to update.<\/p>","1.1.8":"<p>Documentation and packaging only. No behaviour change; safe to update.<\/p>","1.1.6":"<p>Declares compatibility with WordPress 7.1 and hardens the uninstall queries. No behaviour change; safe to update.<\/p>","1.1.4":"<p>Adds opt-in Smart 404 blocking and file permission auditing. Both are off or report-only until you enable them, so updating changes nothing on its own.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3684665,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3684665,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3684665,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3684665,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.12"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3684665,"resolution":"1","location":"assets","locale":"","width":2369,"height":1271},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3684665,"resolution":"10","location":"assets","locale":"","width":2362,"height":1265},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3684665,"resolution":"2","location":"assets","locale":"","width":2363,"height":1267},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3684665,"resolution":"3","location":"assets","locale":"","width":2365,"height":1268},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3684665,"resolution":"4","location":"assets","locale":"","width":2370,"height":1268},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3684665,"resolution":"5","location":"assets","locale":"","width":2359,"height":1270},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3684665,"resolution":"6","location":"assets","locale":"","width":2365,"height":1264},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3684665,"resolution":"7","location":"assets","locale":"","width":2367,"height":1267},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3684665,"resolution":"8","location":"assets","locale":"","width":2360,"height":1269},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3684665,"resolution":"9","location":"assets","locale":"","width":2365,"height":1256}},"screenshots":{"1":"Overview: Security Score, open incidents and the state of every protection engine on one screen.","2":"The same Overview in light mode. Appearance is per-user, so it follows whoever is signed in.","3":"Easy Setup applies a recommended local protection profile without asking you to understand every switch first.","4":"Identity Protection: brute-force lockouts, two-factor enrolment, sessions and Application Passwords. Credentials and raw IP addresses never leave the site.","5":"Integrity Protection verifies WordPress core against the official checksums and keeps SHA-256 baselines for plugins, themes, must-use plugins and drop-ins.","6":"The firewall evaluates requests against local high-confidence rules, in Protect, Learning or Off mode.","7":"The malware scanner reads files locally and resumes after a timeout. File contents never leave the server.","8":"Vulnerability inventory: what is actually installed, so you can judge what is exposed.","9":"Diagnostics are read-only. They verify the runtime, storage and security boundaries without changing any configuration.","10":"Settings: every engine is configurable, and the defaults are safe on their own."}},"plugin_section":[],"plugin_tags":[1174,173015,55021,600,9217],"plugin_category":[54],"plugin_contributors":[279560],"plugin_business_model":[],"class_list":["post-358959","plugin","type-plugin","status-publish","hentry","plugin_tags-firewall","plugin_tags-integrity","plugin_tags-malware-scanner","plugin_tags-security","plugin_tags-two-factor","plugin_category-security-and-spam-protection","plugin_contributors-nimbleplugin","plugin_committers-nimbleplugin"],"banners":{"banner":"https:\/\/ps.w.org\/nimble-security\/assets\/banner-772x250.png?rev=3684665","banner_2x":"https:\/\/ps.w.org\/nimble-security\/assets\/banner-1544x500.png?rev=3684665","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/nimble-security\/assets\/icon-128x128.png?rev=3684665","icon_2x":"https:\/\/ps.w.org\/nimble-security\/assets\/icon-256x256.png?rev=3684665","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-1.png?rev=3684665","caption":"Overview: Security Score, open incidents and the state of every protection engine on one screen."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-2.png?rev=3684665","caption":"The same Overview in light mode. Appearance is per-user, so it follows whoever is signed in."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-3.png?rev=3684665","caption":"Easy Setup applies a recommended local protection profile without asking you to understand every switch first."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-4.png?rev=3684665","caption":"Identity Protection: brute-force lockouts, two-factor enrolment, sessions and Application Passwords. Credentials and raw IP addresses never leave the site."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-5.png?rev=3684665","caption":"Integrity Protection verifies WordPress core against the official checksums and keeps SHA-256 baselines for plugins, themes, must-use plugins and drop-ins."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-6.png?rev=3684665","caption":"The firewall evaluates requests against local high-confidence rules, in Protect, Learning or Off mode."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-7.png?rev=3684665","caption":"The malware scanner reads files locally and resumes after a timeout. File contents never leave the server."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-8.png?rev=3684665","caption":"Vulnerability inventory: what is actually installed, so you can judge what is exposed."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-9.png?rev=3684665","caption":"Diagnostics are read-only. They verify the runtime, storage and security boundaries without changing any configuration."},{"src":"https:\/\/ps.w.org\/nimble-security\/assets\/screenshot-10.png?rev=3684665","caption":"Settings: every engine is configurable, and the defaults are safe on their own."}],"raw_content":"<!--section=description-->\n<p>Nimble Security protects a WordPress site from the login screen down to the files on disk, and it does all of it on your own server.<\/p>\n\n<p>There is no account to create, no cloud service to connect and no data leaving your site. The only outbound request the free version ever makes is to the official WordPress.org checksum API, and only when an integrity scan runs.<\/p>\n\n<p>Everything listed below is in the free version. It is not a trial, nothing here is time-limited, and no engine is held back.<\/p>\n\n<h4>Stop attackers at the door<\/h4>\n\n<ul>\n<li>Brute-force lockouts with generic login errors, so an attacker cannot tell a wrong username from a wrong password.<\/li>\n<li>Two-factor authentication with encrypted secrets, local QR enrolment, ten single-use recovery codes and replay protection.<\/li>\n<li>Session control, Application Password auditing and revocation, and optional XML-RPC authentication protection.<\/li>\n<li>Author-enumeration blocking.<\/li>\n<\/ul>\n\n<h4>Know when your files change<\/h4>\n\n<ul>\n<li>WordPress core verified against the official checksums.<\/li>\n<li>SHA-256 baselines for plugins, themes, must-use plugins, drop-ins and selected configuration files.<\/li>\n<li>Plugin and theme updates are recognised as maintenance, so a routine update does not turn into a false alarm.<\/li>\n<li>Optional permission auditing reports paths writable by group or others and tightens them only when you ask. It never loosens a permission, never acts on its own and never touches anything outside the WordPress installation.<\/li>\n<\/ul>\n\n<h4>Block bad requests<\/h4>\n\n<ul>\n<li>A web application firewall with Protect, Learning and Off modes.<\/li>\n<li>Rate limiting, plus correct client-IP handling behind a proxy or CDN.<\/li>\n<li>Optional Smart 404 blocking, disabled by default.<\/li>\n<\/ul>\n\n<h4>Find and contain what got in<\/h4>\n\n<ul>\n<li>A local malware scanner that streams files in the background and resumes after a timeout. Nothing is uploaded for analysis.<\/li>\n<li>An inventory of installed components, ready to be matched against advisory data.<\/li>\n<li>Incidents, encrypted quarantine and restore, plugin component containment, privileged-session containment and Emergency Lockdown.<\/li>\n<\/ul>\n\n<h4>Know where you stand<\/h4>\n\n<p>Security Score rates your posture out of 100 across hardening, identity, integrity, firewall, malware detection, software updates and recovery readiness. An open high or critical incident caps the score, so a site with an active serious problem cannot display a healthy number.<\/p>\n\n<h4>What it deliberately does not do<\/h4>\n\n<p>Nimble Security does not upload your files, does not phone home, does not write executable code anywhere and does not replace backups. It protects, detects and responds; recovery comes from a backup. That is why recovery readiness counts towards the score, because remediation is far safer when a verified restore point exists.<\/p>\n\n<h3>External services<\/h3>\n\n<p>Nimble Security relies on exactly one external service, and on nothing else.<\/p>\n\n<p><strong>WordPress.org Core Checksums API<\/strong><\/p>\n\n<ul>\n<li><strong>What it is:<\/strong> the official checksum service operated by WordPress.org at <code>https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/code>. It returns the authoritative MD5 checksum set for a given WordPress release.<\/li>\n<li><strong>What it is used for:<\/strong> verifying that the WordPress core files on your server match the files that were published for your version. Without it, core integrity cannot be established, because the reference checksums only exist on WordPress.org.<\/li>\n<li><strong>What is sent, and when:<\/strong> the installed WordPress core version and the site locale, over HTTPS. Nothing else. The request is made only when a core integrity scan runs: manually when an administrator starts one, or on the daily schedule if an administrator has enabled automatic scans. Automatic scans are off by default. No request is made if integrity scanning is never used.<\/li>\n<li><strong>What is never sent:<\/strong> plugin or theme file contents, local file hashes, file paths, credentials, cookies, request bodies, user or customer data, security findings and quarantine payloads.<\/li>\n<li><strong>Terms of Service:<\/strong> https:\/\/wordpress.org\/about\/terms\/<\/li>\n<li><strong>Privacy Policy:<\/strong> https:\/\/wordpress.org\/about\/privacy\/<\/li>\n<\/ul>\n\n<p>Nimble Security does not contact NimblePlugins, sends no telemetry and has no account, licence or activation requirement of any kind.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Security events are minimized. Raw request bodies, cookies and credentials are not stored by the event engine, and network actors are represented with keyed hashes rather than raw IP addresses in Security events.<\/p>\n\n<p>TOTP secrets are encrypted at rest and recovery codes are stored as one-way hashes in WordPress user metadata. Authentication secrets are never included in the WordPress personal-data export. The privacy eraser anonymizes Security event references and removes the per-user appearance preference; active 2FA material is retained while the account remains active because it is required for authentication.<\/p>\n\n<p>Quarantine payloads stay local and are encrypted with AES-256-GCM. Operations receives aggregate technical status only, not file contents, raw IP addresses, credentials, request bodies or quarantine data.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload and activate Nimble Security.<\/li>\n<li>On a new installation, choose <strong>Start Easy Setup<\/strong> or <strong>Skip for now<\/strong>.<\/li>\n<li>Easy Setup can apply the recommended local protection profile and start the first checks automatically.<\/li>\n<li>Enroll administrator 2FA when prompted.<\/li>\n<li>Review Identity, Integrity, Firewall, Scanner and Recovery status from Nimble Security &gt; Overview.<\/li>\n<\/ol>\n\n<p>Easy Setup never requires a Nimble account or Threat Cloud connection and can be run again later from the Nimble Security menu.<\/p>\n\n<p>If using Nimble Security Pro, install\/upgrade Free first, then Pro.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20licence%20key%20or%20an%20account%3F\"><h3>Do I need a licence key or an account?<\/h3><\/dt>\n<dd><p>No. Nimble Security is complete on its own. It contains no licence check, no account requirement and no time limit, and it does not contact NimblePlugins.<\/p><\/dd>\n<dt id=\"does%20free%20work%20without%20pro%3F\"><h3>Does Free work without Pro?<\/h3><\/dt>\n<dd><p>Yes. Free owns the local identity, integrity, firewall, malware, vulnerability-inventory and manual response engines.<\/p><\/dd>\n<dt id=\"does%20a%20changed%20plugin%20file%20mean%20malware%3F\"><h3>Does a changed plugin file mean malware?<\/h3><\/dt>\n<dd><p>No. Integrity findings are interpreted in context. Known WordPress maintenance can be correlated automatically; unexplained file changes are presented for review rather than being labelled malware by file type alone.<\/p><\/dd>\n<dt id=\"why%20can%20wp-config.php%20still%20require%20review%20after%20wordpress%20is%20reinstalled%3F\"><h3>Why can wp-config.php still require review after WordPress is reinstalled?<\/h3><\/dt>\n<dd><p>WordPress normally preserves wp-config.php. Site-specific cron, proxy, database or debug configuration can therefore legitimately differ from a previous baseline. Nimble Security lets an administrator explicitly mark the current recognized configuration as intentional without storing its contents.<\/p><\/dd>\n<dt id=\"does%20nimble%20security%20upload%20files%20for%20malware%20scanning%3F\"><h3>Does Nimble Security upload files for malware scanning?<\/h3><\/dt>\n<dd><p>No. The Free malware scanner runs locally.<\/p><\/dd>\n<dt id=\"can%20security%20delete%20malware%20automatically%3F\"><h3>Can Security delete malware automatically?<\/h3><\/dt>\n<dd><p>Free response is manual-first. Pro contains conservative recovery-gated automation, but destructive actions remain bounded by the Free enforcement and recovery contracts.<\/p><\/dd>\n<dt id=\"does%20nimble%20security%20replace%20backups%3F\"><h3>Does Nimble Security replace backups?<\/h3><\/dt>\n<dd><p>No. Security protects\/detects\/responds; backup provides recovery. Recovery readiness is intentionally part of Security Score because remediation is safer when a verified recovery point is available.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.12<\/h4>\n\n<ul>\n<li>Quarantine payloads now live in a protected folder inside the uploads directory, resolved at runtime with wp_upload_dir() instead of a hard-coded wp-content path. Existing payloads are moved there automatically on update, and the folder is still closed to direct access.<\/li>\n<li>Extended Protection has been moved to the Nimble Security Pro add-on. It was the only part of the plugin that generated a PHP file, and generated PHP does not belong in a plugin hosted here. Every rule it enforced is still enforced by the built-in firewall through WordPress; nothing is left unprotected.<\/li>\n<li>If Extended Protection was prepared on your site, remove the auto_prepend_file directive you added, or install the Pro add-on to keep managing it.<\/li>\n<li>Removes two core-file includes that were not needed: wp-admin\/includes\/plugin.php in the quarantine policy check and wp-admin\/includes\/update.php in the update-status refresh.<\/li>\n<li>Documents the WordPress.org checksum API in full, including what is sent, when, and links to its Terms of Service and Privacy Policy.<\/li>\n<\/ul>\n\n<h4>1.1.11<\/h4>\n\n<ul>\n<li>Removes the Nimble Security Pro licence client, the licence screen and all licence storage from the free plugin. Licensing now lives entirely in the commercial Pro package; nothing in the free plugin is gated, checked or limited.<\/li>\n<li>The two-factor login screen loads its styling from a stylesheet, and the interim-login handoff script is registered through the script API instead of being printed inline.<\/li>\n<li>Uninstall still clears any licence options left behind by an earlier version.<\/li>\n<\/ul>\n\n<h4>1.1.10<\/h4>\n\n<ul>\n<li>The licence key field is hidden until Nimble Security Pro is actually installed, so the free plugin never asks for a key that cannot be obtained yet. A filter, nimble_security_license_entry_visible, can reveal it early.<\/li>\n<li>No behaviour change.<\/li>\n<\/ul>\n\n<h4>1.1.9<\/h4>\n\n<ul>\n<li>The licence screen no longer presents an unreleased product as a missing one. With no key stored it reads \"coming soon\" instead of \"not activated\", and the key field is labelled for the few who already hold one rather than shown as a call to action.<\/li>\n<li>Pro capabilities are described in the future tense throughout, because Pro is not released yet.<\/li>\n<li>No behaviour change.<\/li>\n<\/ul>\n\n<h4>1.1.8<\/h4>\n\n<ul>\n<li>Rewrites the plugin description for the directory and removes internal release wording.<\/li>\n<li>Corrects the Contributors username.<\/li>\n<li>Documents why the quarantine and scanner paths use direct filesystem calls instead of WP_Filesystem.<\/li>\n<li>No behaviour change.<\/li>\n<\/ul>\n\n<h4>1.1.7<\/h4>\n\n<ul>\n<li>Replaces the placeholder brand mark with the real Nimble logo in the admin menu, the plugin header, the licence screen, the two-factor login screen and both request-blocked pages.<\/li>\n<li>No behaviour change.<\/li>\n<\/ul>\n\n<h4>1.1.6<\/h4>\n\n<ul>\n<li>Declares Tested up to 7.1.<\/li>\n<li>Uninstall passes plugin-owned table names through prepared %i identifiers instead of interpolating them. No behaviour change.<\/li>\n<\/ul>\n\n<h4>1.1.5<\/h4>\n\n<ul>\n<li>Plugin Check compliance: aligns a phpcs suppression with the sniff names used elsewhere in the package. No behaviour change.<\/li>\n<\/ul>\n\n<h4>1.1.4<\/h4>\n\n<ul>\n<li>Adds Smart 404 blocking (opt-in, disabled by default). Administrators and allowlisted paths are never counted; blocking is Protect-mode only.<\/li>\n<li>Adds file permission auditing with bounded, opt-in hardening. Tightens only, never loosens, and only inside the install.<\/li>\n<li>New settings and events for both.<\/li>\n<li>No licensing, Easy Setup, malware scanner, integrity, Threat Cloud, Operations or Backup contract changes.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Streams eligible script-bearing files from 5\u201350 MiB in bounded 1 MiB chunks instead of marking every file above 5 MiB as unscanned.<\/li>\n<li>Keeps a 16 KiB overlap between stream windows so bounded signatures split across a chunk boundary remain detectable.<\/li>\n<li>Only unreadable eligible files or files above the 50 MiB safety ceiling now make malware coverage incomplete.<\/li>\n<li>Incomplete-scan notices show the actual counts and a bounded list of affected relative paths.<\/li>\n<li>No licensing, Easy Setup, firewall, integrity, Threat Cloud, Operations or Backup\/Recovery contract changes.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Fixes horizontal admin-page overflow by sizing the main Security canvas inside the WordPress viewport.<\/li>\n<li>Makes dashboard and Easy Setup grid columns shrink safely without forcing side-scrolling.<\/li>\n<li>No security, licensing, Easy Setup, Threat Cloud, Operations or Backup\/Recovery behavior changes.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Adds first-run Easy Setup with a clear Skip option for non-technical site owners.<\/li>\n<li>Recommended setup enables compatibility-safe local defaults, starts the first integrity check and queues malware\/software monitoring.<\/li>\n<li>Keeps XML-RPC changes, proxy trust, global per-IP rate limiting and Extended Protection as explicit advanced choices.<\/li>\n<li>Preserves the 1.0.1 Free-owned Nimble Security Pro licensing client and the Pro response-automation admin hook.<\/li>\n<li>Fixes inline Pro\/licence notice contrast inside Nimble Security pages in both dark and light modes.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fixes the Response admin page never firing <code>nimble_security_response_automation_panel<\/code>. Nimble Security Pro attaches its recovery-gated automation policy form to that hook, so with Pro active the automation panel could not render and the policy could not be moved off its default Off state.<\/li>\n<li>No security policy, schema, Threat Cloud, Operations or Backup contract changes.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First stable release. Clean version number replaces the 1.0.0-rc release-candidate series.<\/li>\n<li>Adds the NimblePlugins signed licensing client, owned by Free, with an RSA-SHA256 verified verdict, encrypted local key storage, a 7-day offline grace period and a daily background validation.<\/li>\n<li>Adds a Licence admin page for activating, checking and deactivating a Nimble Security Pro licence.<\/li>\n<li>Fixes a corrupted uninstall.php that had lost its opening PHP tag, which prevented all uninstall cleanup from running and prevented the fail-open disabling of a generated Extended Protection auto_prepend_file policy.<\/li>\n<li>Uninstall now also clears licence state and the licence validation schedule.<\/li>\n<li>No security policy, schema, Threat Cloud, Operations or Backup contract changes.<\/li>\n<\/ul>","raw_excerpt":"Local WordPress security with 2FA, integrity monitoring, firewall, malware scanning, quarantine, incident response and recovery readiness.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/358959","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=358959"}],"author":[{"embeddable":true,"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/nimbleplugin"}],"wp:attachment":[{"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=358959"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=358959"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=358959"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=358959"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=358959"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/te.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=358959"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}