Read before downloading
Know what you are opening.
Every public package has an indexed filename, size, format, and SHA-256 integrity value. The limits of that evidence are stated plainly.
01See how it works
Use a public demo or project overview first when one is available. Confirm that the result fits your need before downloading.
02Review requirements
Open the package README. Use only the named runtime or WordPress installation path, and add your own credentials locally only when required.
03Verify integrity
Compare the downloaded file against the published size and SHA-256 value. A mismatch means the file should not be opened.
Release guardrails
What the checks cover
- All homepage download paths must exist in the public release directory.
- The release inventory records file size, format, and SHA-256.
- Known credential, authentication-state, personal-path, database, and cache patterns are excluded during packaging.
- Downloads remain same-origin and require an explicit user action.
Keep your own setup private
- Never paste credentials into a public repository or support message.
- Do not upload browser profiles, authentication state, private databases, or personal exports.
- Use example environment files as templates; never overwrite them with a real secret and commit the result.
- Stop installation if a package asks for access unrelated to its stated function.