Security

Who can use the plugin, how API keys are encrypted, and exactly what is sent to providers.

Version: 1.0.1Last updated
On this page

This page explains how the plugin protects your keys and your site, and what you should do on your side.

Who can use it

  • Only users with the manage_options capability (administrators). Developers can change this with the ocat_capability filter.
  • Every request is checked with a WordPress nonce and the capability.
  • Nothing is loaded for site visitors. There are no cron jobs and no tracking.

How keys are stored

  • Keys belong to the user who saved them. Other administrators cannot see or use them; each person adds their own.
  • They are encrypted with libsodium, using your site's secret keys and the user ID, and stored in your user profile data.
  • Keys are never sent to the browser. Only a four character hint is shown.
  • If you change your site secret keys (AUTH_KEY, AUTH_SALT), saved keys must be entered again.

For stronger protection, define the key in wp-config.php instead. It then applies to every administrator on the site:

define( 'OCAT_GEMINI_KEY', '...' );

The other names are OCAT_ANTHROPIC_KEY, OCAT_OPENAI_KEY and OCAT_GROQ_KEY. A server environment variable with the same name also works.

What leaves your site

Only when an administrator clicks Translate page or Test connection, the plugin sends the provider: the untranslated text strings of the page, the language names, and your optional tone and glossary text. No visitor data is sent. Nothing is sent to MeloTools.

With Free basic, nothing leaves your computer.

Provider addresses are fixed in the code, so the plugin cannot be pointed at other servers. Page text is treated as content to translate: instructions hidden in your text are translated, not followed.

The plugin adds a suggested paragraph to Settings > Privacy > Policy Guide that you can copy into your privacy policy.

What you should do

  1. Create a separate API key for each site, with a clear name.
  2. Set a spending limit in the provider console.
  3. Keep administrator accounts to people you trust, with strong passwords and two-factor authentication.
  4. Never share your key in support requests, screenshots or chat.
  5. If a key may have leaked, delete it in the provider console, then save a new one.
  6. Keep WordPress, TranslatePress and this plugin updated.

Report a security issue

Please report security problems privately through the contact page, not in the public support forum.