- Add a site in the dashboard (CLEAN+). Default transport is connector.
- Download
wp-cleanr-connector.zipfrom the account (authenticated). Install it on the WordPress site. - Paste site id and the secret from the site page (visible until Pair). Pair over HMAC v1.
From 1.4, WordPress auto-updates the plugin from /connector/v1/update.json. Sites still on 1.3 need one manual install of the new zip.
Reads are jailed with realpath under ABSPATH. Files larger than 2 MiB are skipped. Clean and harden still require SSH. GET of the sites API does not return the secret.