# Translation of Plugins - CMS ADMINS Security Check Report - Stable (latest release) in Spanish (Spain)
# This file is distributed under the same license as the Plugins - CMS ADMINS Security Check Report - Stable (latest release) package.
msgid ""
msgstr ""
"PO-Revision-Date: +0000\n"
"MIME-Version: 1.0\n"
"Content-Type: text/plain; charset=UTF-8\n"
"Content-Transfer-Encoding: 8bit\n"
"Plural-Forms: nplurals=2; plural=n != 1;\n"
"X-Generator: GlotPress/4.1.0\n"
"Language: es\n"
"Project-Id-Version: Plugins - CMS ADMINS Security Check Report - Stable (latest release)\n"

#. translators: 1: grade letter, 2: number of findings.
#: includes/class-cascr-scoring.php:145
msgid "Today: grade %1$s with %2$d finding."
msgid_plural "Today: grade %1$s with %2$d findings."
msgstr[0] ""
msgstr[1] ""

#: includes/class-cascr-rest.php:208
msgid "There is no stored report to update. Run all checks once first."
msgstr ""

#: includes/class-cascr-registry.php:679
msgid "AI content disclosure"
msgstr ""

#: includes/class-cascr-registry.php:185
msgid "Transparency and disclosure"
msgstr ""

#: includes/class-cascr-nudges.php:233
msgid "You are not allowed to do that."
msgstr ""

#: includes/class-cascr-nudges.php:197
msgid "Stop reminding me"
msgstr ""

#. translators: %s: length of time, for example "2 months".
#: includes/class-cascr-nudges.php:190
msgid "The last full security check on this site ran %s ago."
msgstr ""

#: includes/class-cascr-nudges.php:162 includes/class-cascr-nudges.php:195
msgid "Open the report"
msgstr ""

#. translators: %s: length of time, for example "2 weeks".
#: includes/class-cascr-nudges.php:152
msgid "Last full check %s ago."
msgstr ""

#. translators: %d: number of findings still open.
#: includes/class-cascr-nudges.php:138
msgid "%d open task"
msgid_plural "%d open tasks"
msgstr[0] ""
msgstr[1] ""

#: includes/class-cascr-nudges.php:118
msgid "Run the first check"
msgstr ""

#: includes/class-cascr-nudges.php:113
msgid "This site has not been checked yet."
msgstr ""

#. translators: %s: number of failed checks.
#: includes/class-cascr-nudges.php:76
msgid "%s failed check"
msgid_plural "%s failed checks"
msgstr[0] ""
msgstr[1] ""

#: includes/class-cascr-admin.php:432
msgid "No check matches that filter."
msgstr ""

#: includes/class-cascr-admin.php:301
msgid "I understand."
msgstr ""

#: includes/class-cascr-admin.php:133
msgid "Checking again"
msgstr ""

#. translators: 1: number of passed checks, 2: number of checks in the
#. category.
#: includes/class-cascr-admin-dashboard.php:591
msgid "%1$d of %2$d passed"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:568
msgid "By category"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:549
msgid "after a re-check"
msgstr ""

#. translators: %d: number of checks that were a finding once and pass now.
#: includes/class-cascr-admin-dashboard.php:537
msgid "Resolved (%d)"
msgstr ""

#. translators: %d: number of findings that are not on the short list.
#: includes/class-cascr-admin-dashboard.php:464
msgid "Still open (%d)"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:421
msgid "later"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:418
msgid "Done, check it now"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:371
msgid "Your next five"
msgstr ""

#. translators: %d: number of recorded runs.
#: includes/class-cascr-admin-dashboard.php:354
msgid "%d recorded run. A taller bar is a better run."
msgid_plural "%d recorded runs, the oldest on the left. A taller bar is a better run."
msgstr[0] ""
msgstr[1] ""

#. translators: 1: date of the run, 2: grade letter.
#: includes/class-cascr-admin-dashboard.php:337
msgid "%1$s: grade %2$s"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:313
msgid "How the site scored across the recorded runs, oldest on the left. A taller bar is a better run."
msgstr ""

#: includes/class-cascr-admin-dashboard.php:304
msgid "Your progress"
msgstr ""

#. translators: %s: name of the check.
#: includes/class-cascr-admin-dashboard.php:275
msgid "%s is still open after the re-check."
msgstr ""

#. translators: %s: name of the check.
#: includes/class-cascr-admin-dashboard.php:272
msgid "%s passed the re-check."
msgstr ""

#. translators: 1: number of checks re-checked on their own, 2: date of the
#. last full pass.
#: includes/class-cascr-admin-dashboard.php:200
msgid "%1$d check has been re-checked on its own since the full pass on %2$s."
msgid_plural "%1$d checks have been re-checked on their own since the full pass on %2$s."
msgstr[0] ""
msgstr[1] ""

#. translators: 1: date of the first recorded run, 2: grade letter, 3: number
#. of findings.
#: includes/class-cascr-admin-dashboard.php:133
msgid "Started on %1$s: grade %2$s with %3$d finding."
msgid_plural "Started on %1$s: grade %2$s with %3$d findings."
msgstr[0] ""
msgstr[1] ""

#: includes/class-cascr-admin-dashboard.php:100
msgid "Re-check everything"
msgstr ""

#: includes/checks/class-cascr-checks-transparency.php:84
msgid "TransparAI, our own plugin for AI content disclosure"
msgstr ""

#: includes/checks/class-cascr-checks-transparency.php:68
msgid "If the site publishes AI-generated text, images or video, or runs a chatbot, install one of the disclosure plugins from the directory and switch the labelling on. EU AI Label and EU AI Act Ready are free and cover media labels and a visitor notice. TransparAI, which we build ourselves, puts media labels, text marking and chatbot disclosure in one place; it is named here because it fits, not because you need it."
msgstr ""

#: includes/checks/class-cascr-checks-transparency.php:65
msgid "Since 2 August 2026, Article 50 of the EU AI Act asks for a machine-readable label on AI-generated content and for a notice when visitors are talking to an AI system. No solution for that is active on this installation."
msgstr ""

#: includes/checks/class-cascr-checks-transparency.php:59
msgid "Open the plugin settings and switch the labelling on. Until that is saved the plugin changes nothing a visitor can see."
msgstr ""

#: includes/checks/class-cascr-checks-transparency.php:56
msgid "A disclosure plugin is active but was never set up, so nothing is labelled yet."
msgstr ""

#: includes/checks/class-cascr-checks-transparency.php:49
msgid "AI-generated content is labelled and visitors are told when they reach an AI system."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:1057
msgid "If nothing sits in front of the site, have the security plugins read REMOTE_ADDR. If a proxy does, make sure it overwrites these headers rather than passing on whatever arrived."
msgstr ""

#. translators: 1: comma separated list of forwarded address headers, 2: remote
#. IP address of the current request.
#: includes/checks/class-cascr-checks-network.php:1053
msgid "Forwarded address headers arrive (%1$s) from %2$s, and a header written by a proxy looks the same from here as one a visitor sent along."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:1014
msgid "Open the report in the browser to have it checked."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:1013
msgid "This check reads the headers of the current request, and this run has none."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:970
msgid "Some routes are open on purpose and check the request inside the callback, a contact form or a shop cart for instance. Ask the plugin that registered the route whether this one is meant to be open, and remove the plugin until it is fixed if it is not."
msgstr ""

#. translators: %d: number of write routes that are open on purpose.
#: includes/checks/class-cascr-checks-network.php:960
msgid "%d REST route accepts changes from anyone who asks."
msgid_plural "%d REST routes accept changes from anyone who asks."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-network.php:953
msgid "Since WordPress 5.5 every route has to name one. The route belongs to whichever plugin registered it, so report it to the author and remove the plugin until it is fixed."
msgstr ""

#. translators: %d: number of write routes without a permission callback.
#: includes/checks/class-cascr-checks-network.php:943
msgid "%d REST route accepts changes without naming a permission callback."
msgid_plural "%d REST routes accept changes without naming a permission callback."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-network.php:933
msgid "Every REST route that changes data decides who may call it."
msgstr ""

#. translators: 1: REST route, 2: comma separated HTTP methods.
#: includes/checks/class-cascr-checks-network.php:921
msgid "%1$s is registered as open to anyone for %2$s"
msgstr ""

#. translators: 1: REST route, 2: comma separated HTTP methods.
#: includes/checks/class-cascr-checks-network.php:914
msgid "%1$s accepts %2$s and names no permission callback at all"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:878
msgid "Require authentication on the users endpoint and stop the ?author redirect. A different display name changes nothing here: the author slug keeps the login name it was generated from, and that is what the redirect and the REST answer carry."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:834
msgid "the ?author=N parameter answers with an author archive, which confirms which account IDs exist"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:832
msgid "the ?author=N parameter redirects to the author archive and gives the login name away"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:780
msgid "If nothing uses XML-RPC, block xmlrpc.php in the web server, which is the only place that stops the requests before WordPress handles them. The xmlrpc_enabled filter only turns away the methods that need a login. Jetpack and the mobile apps are the usual reasons to leave it open."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:768
msgid "system.multicall bundles many calls into one request. Since WordPress 4.4 the first failed login ends the rest, so it no longer multiplies password guesses, but one request still does the work of many"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:764
msgid "the xmlrpc_enabled filter refuses every method that needs a login, but the endpoint keeps answering"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:597
msgid "Set HttpOnly, SameSite=Lax and, on an HTTPS site, Secure at the server. The session cookies appear only after a successful sign-in and are not part of this measurement."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:594
msgid "The login page hands out cookies without the attributes that limit where a browser will send them back."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:590
msgid "The cookies the login page hands out before sign-in carry the right attributes."
msgstr ""

#. translators: %s: cookie name.
#: includes/checks/class-cascr-checks-network.php:575
msgid "%s is readable from JavaScript, it has no HttpOnly attribute"
msgstr ""

#. translators: %s: comma separated list of the weak parts of the policy.
#: includes/checks/class-cascr-checks-network.php:509
msgid "A Content Security Policy is enforced but leaves openings: %s."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:497
msgid "no fallback directive"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:492
msgid "a wildcard script source"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:487
msgid "eval ('unsafe-eval')"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:482
msgid "inline scripts ('unsafe-inline')"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:407
msgid "Use max-age=31536000; includeSubDomains, which is one year. Anything shorter than six months counts as weak here. Add preload only when every subdomain is on HTTPS for good."
msgstr ""

#. translators: %s: comma separated list of what the header is missing.
#: includes/checks/class-cascr-checks-network.php:402
msgid "The HSTS header is present but weak: %s."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:390
msgid "no includeSubDomains"
msgstr ""

#. translators: %s: current max-age as a duration.
#: includes/checks/class-cascr-checks-network.php:383
msgid "a max-age of only %s"
msgstr ""

#. translators: 1: current max-age as a duration, 2: recommended minimum as a
#. duration.
#: includes/checks/class-cascr-checks-network.php:376
msgid "max-age lasts %1$s, the recommendation is at least %2$s"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:372
msgid "no usable max-age"
msgstr ""

#. translators: %s: recommended minimum lifetime, already formatted.
#: includes/checks/class-cascr-checks-network.php:368
msgid "the header carries no usable max-age, so it expires immediately instead of lasting at least %s"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:239
msgid "The TLS certificate is within its validity period and not about to expire."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:221
msgid "Renew it and let the renewal run automatically. Certificate lifetimes drop to 100 days in March 2027 and to 47 days in 2029, so a manual renewal will get tight."
msgstr ""

#. translators: %s: human readable time until expiry.
#: includes/checks/class-cascr-checks-network.php:216
msgid "The TLS certificate expires in %s, which leaves little room if a renewal fails."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:183
msgid "the trust chain and the host name are not checked here"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:75
msgid "The http address does not redirect permanently to https, so a visitor who types the bare domain can still be served over http."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:63
msgid "The site is served over HTTPS, but the dashboard can still be reached over http: FORCE_SSL_ADMIN is not set."
msgstr ""

#. translators: %s: comma separated file names, for example ".user.ini,
#. .htpasswd".
#: includes/checks/class-cascr-checks-files.php:1038
msgid "Keep %s: those are running configuration, not leftovers. Deny access to them at the server instead of deleting them."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:1020
msgid "On Apache and LiteSpeed an .htaccess in that directory does it, as long as AllowOverride allows the rule; on nginx and Caddy it belongs in the server configuration."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:831
msgid "Move the files somewhere outside the web root rather than waiting for the answer."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:830
msgid "A database dump or archive lies in the web root, and whether the server hands it out could not be verified."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:625
msgid "Deny access to .php files in the uploads directory instead of only switching the interpreter off for them."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:622
msgid "The server does not run PHP files in the uploads directory but hands them out as text, so anything uploaded there can be read back line by line."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:616
msgid "Deny .php files in the uploads directory."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:524
msgid "it prints output of its own"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:512
msgid "it calls a function held in a variable"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:487
msgid "it builds a variable name at runtime"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:483
msgid "it runs a shell command"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:428
msgid "it could not be read"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:422
msgid "it is too large to be a guard"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:418
msgid "its size could not be read"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:412
msgid "the tokeniser is unavailable"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:387
msgid "Installers and scripts handed out through the media library are downloads, not code this site runs. Check that each one is meant to be there."
msgstr ""

#. translators: %d: number of files in uploads that the web server does not
#. run.
#: includes/checks/class-cascr-checks-files.php:377
msgid "%d file that the web server does not run sits in the uploads directory."
msgid_plural "%d files that the web server does not run sit in the uploads directory."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:238
msgid "Set files to 644 and directories to 755. Nothing needs to be world-writable. wp-config.php, the core directories and the uploads folder are not listed here, they have a check of their own."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:222
msgid "Nothing below the web root is writable by everyone, leaving aside the paths that have a check of their own."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:1148
msgid "The plugin directory returned no usable answer."
msgstr ""

#. translators: %d: number of other WordPress installations found.
#: includes/checks/class-cascr-checks-core.php:1029
msgid "%d other WordPress installation sits in the directory above this one."
msgid_plural "%d other WordPress installations sit in the directory above this one."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:781
msgid "Run the report again once api.wordpress.org can be reached from this server."
msgstr ""

#. translators: %d: number of plugins whose listing could not be retrieved.
#: includes/checks/class-cascr-checks-core.php:773
msgid "The listing of %d active plugin could not be retrieved, so the directory status is open."
msgid_plural "The listings of %d active plugins could not be retrieved, so the directory status is open."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:446
msgid "Nothing unexpected turned up in the part that was read. Compare the remaining files with a fresh copy of this WordPress release."
msgstr ""

#. translators: %d: number of executable files that were compared before the
#. scan stopped.
#: includes/checks/class-cascr-checks-core.php:443
msgid "The scan stopped after %d executable files, so the core directories were only compared in part."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:272
msgid "Re-enable automatic updates for maintenance and security releases under Dashboard, Updates."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:269
msgid "Automatic minor and security updates are switched off for this site."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:232
msgid "Allow file modifications again, or install core updates another way, for example over WP-CLI or the hosting platform."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:229
msgid "The automatic updater cannot run, so security releases are not installed on their own."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:705
msgid "Enforce a minimum strength for accounts that can publish or administer. If that already happens outside WordPress, mute this check."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:702
msgid "No password policy plugin is active. This check can only see plugins, so a rule enforced in a theme, in an identity provider or by a hosting platform does not show up here. On its own, WordPress warns about weak passwords and then accepts them."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:682
msgid "Install a login limiter, or rate limit wp-login.php and the XML-RPC endpoint at the server. If a limit is already in place outside WordPress, mute this check."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:679
msgid "No plugin that limits repeated login attempts is active. This check can only see plugins, so a limit in the web server or in front of the site does not show up here."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:605
msgid "No option contains a code fragment or loads a script from another host."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:601
msgid "Analytics and consent tools store script tags this way on purpose. Go through the list once and check that every host is one you chose."
msgstr ""

#. translators: %d: number of option entries loading a script from another
#. host.
#: includes/checks/class-cascr-checks-config.php:591
msgid "%d option entry loads a script from another host."
msgid_plural "%d option entries load a script from another host."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-config.php:583
msgid "Look at each entry before removing it. An option that stores PHP is worth tracing back to the plugin that wrote it."
msgstr ""

#. translators: %d: number of option entries containing code fragments.
#: includes/checks/class-cascr-checks-config.php:573
msgid "%d option entry contains a code fragment."
msgid_plural "%d option entries contain code fragments."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-config.php:443
msgid "WordPress ships no screen for scheduled events. List them with wp cron event list on the command line, or install a scheduler plugin to see them in the dashboard."
msgstr ""

#. translators: %d: number of scheduled hooks with no listener.
#: includes/checks/class-cascr-checks-config.php:419
msgid "%d scheduled hook has no listener in this request."
msgid_plural "%d scheduled hooks have no listener in this request."
msgstr[0] ""
msgstr[1] ""

#. translators: %s: name of a scheduled hook with no listener in this request.
#: includes/checks/class-cascr-checks-config.php:412
msgid "scheduled hook with no listener registered in this request: %s"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:402
msgid "ALTERNATE_WP_CRON is enabled: it schedules through a redirect that carries doing_wp_cron in the address, which defeats page caching for that request and leaves the parameter in access logs and in referrers sent to other sites"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:401
msgid "ALTERNATE_WP_CRON is enabled."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:312
msgid "may grant privileges on every database to other accounts"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:241
msgid "Generate a fresh set at api.wordpress.org/secret-key/1.1/salt/ and replace the block in wp-config.php. Rotating invalidates every stored session, which is the fastest way to lock out a stolen cookie. Everyone gets logged out once."
msgstr ""

#. translators: %s: human readable time difference, for instance "14 months".
#: includes/checks/class-cascr-checks-config.php:237
msgid "wp-config.php was last modified %s ago; this is the age of the file, not of the keys"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:232
msgid "The authentication keys are set correctly. wp-config.php has not been changed in over a year, which usually means the keys have not been rotated either."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:131
msgid "DISALLOW_FILE_MODS closes the editor, DISALLOW_FILE_EDIT is not set"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:84
msgid "A debug log exists, but it sits outside everything the web server hands out."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:812
msgid "If the network does not need public sign-ups, choose \"Registration is disabled\" under Network Admin, Settings, Registration Settings."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:800
msgid "Under Network Admin, Settings, Registration Settings, choose \"Registration is disabled\", or lower the default role of this site."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:679
msgid "Serve the site over HTTPS and run the check again. Until then, review the existing application passwords in each user profile."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:678
msgid "Application passwords are unavailable here. WordPress requires HTTPS for them, so whether they were switched off deliberately cannot be told apart from that, and passwords issued earlier are not listed."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:655
msgid "ReportedIP Hive, our own plugin: TOTP, email and passkeys are in the Full Edition"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:622
msgid "Finish the setup for every administrator and require the second factor for the role. ReportedIP Hive, which we build ourselves, enforces it per role in its Full Edition; the copy in the plugin directory is Hive Light and brings login protection only."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:576
msgid "Install a two-factor plugin and require it at least for administrators. Two Factor is a widely used free plugin kept up by WordPress contributors and is a solid choice. ReportedIP Hive, which we build ourselves, covers TOTP, email and passkeys in its Full Edition; the copy in the plugin directory is Hive Light and brings login protection only."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:485
msgid "Plugins add and adjust roles when they are installed. Match the list against what was installed, and remove what nobody asked for."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:482
msgid "The role definitions changed since the first scan, but no role below administrator gained administrator-level capabilities."
msgstr ""

#. translators: %d: number of administrator accounts that have not signed in
#. for over a year.
#: includes/checks/class-cascr-checks-accounts.php:363
msgid "%d administrator has not signed in for over a year."
msgid_plural "%d administrators have not signed in for over a year."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-accounts.php:341
msgid "The account with ID 1 is an administrator, and that is the first ID anyone tries."
msgstr ""

#. translators: %d: maximum number of accounts a single query returns.
#: includes/checks/class-cascr-checks-accounts.php:140
msgid "This site has more privileged accounts than one query returns, so only the first %d were looked at."
msgstr ""

#: config/docs.php:365
msgid "If the site publishes AI-generated content or runs a chatbot, install one of the disclosure plugins from the directory and switch the labelling on. EU AI Label and EU AI Act Ready are free and cover media labels and a visitor notice. TransparAI, which we build ourselves, puts media labels, text marking and chatbot disclosure in one place; it is named here because it fits, not because you need it. An installed plugin whose settings were never saved counts as nothing, so the check reads those settings rather than trusting the folder on disk."
msgstr ""

#: config/docs.php:364
msgid "Since 2 August 2026, Article 50 of the EU AI Act asks for a machine-readable label on AI-generated text, images, audio and video, and for a notice when a visitor is talking to an AI system. A site that publishes no AI output has nothing to label, and this check cannot tell those sites apart from the rest, which is why it only ever warns and carries a fraction of the usual weight."
msgstr ""

#: config/docs.php:363
msgid "Whether a plugin that labels AI-generated content and discloses AI systems to visitors is active, and whether its settings have actually been saved. Only local state is read; nothing is sent anywhere."
msgstr ""

#: config/docs.php:357
msgid "If nothing sits in front of the site, have the security plugins read REMOTE_ADDR. If a proxy does, make sure it overwrites these headers rather than passing on whatever arrived. Running the report in the browser rather than on the command line is what gives this check a request to look at."
msgstr ""

#: config/docs.php:356
msgid "Anything that trusts a forwarded header for rate limiting or blocking can be walked past by changing one header, unless a proxy overwrites it. From inside PHP a header written by an edge server and one a visitor sent along look exactly alike, so this check says so rather than guessing: a private REMOTE_ADDR or a Cloudflare edge that identifies itself counts as confirmed, everything else stays undecided."
msgstr ""

#: config/docs.php:355
msgid "Whether forwarded address headers arrive with the current request, and whether anything can confirm that a proxy in front of the site wrote them."
msgstr ""

#: config/docs.php:352
msgid "The route belongs to whichever plugin registered it. Ask the author whether it is meant to be open, and remove the plugin until it is fixed if it is not. If it is meant to be public, mute the finding."
msgstr ""

#: config/docs.php:351
msgid "A route with no permission callback is a mistake WordPress itself complains about since 5.5. A route registered with __return_true is the spelling the handbook prescribes for a route that is meant to be public, so it is listed as a question: a shop cart or a contact form belongs there and authorises inside the callback. The WordPress batch endpoint and the WooCommerce Store API work exactly that way and are left out entirely."
msgstr ""

#: config/docs.php:350
msgid "REST routes that accept POST, PUT, PATCH or DELETE without a permission check: either with no permission callback at all, or registered as open to everyone. A REST route is an address under /wp-json/ that a plugin registers so that programs can read or change something."
msgstr ""

#: config/docs.php:347
msgid "Require authentication on the users endpoint and stop the author redirect. A different display name changes nothing: the author slug keeps the login name it was generated from, and that is what the redirect and the REST answer carry. Change user_nicename itself if the name must not be public."
msgstr ""

#: config/docs.php:346
msgid "Guessing a password needs a name and a password. Readable names turn that into one unknown instead of two. With pretty permalinks the ?author redirect hands over the login name itself; without them the author archive still confirms which account IDs exist."
msgstr ""

#: config/docs.php:345
msgid "Three ways of reading out accounts without being logged in: the ?author=N parameter, the REST users endpoint and the oEmbed endpoint. Several accounts are probed, not only the first one."
msgstr ""

#: config/docs.php:342
msgid "If nothing uses XML-RPC, block xmlrpc.php in the web server, which is the only place that stops the requests before WordPress handles them. The xmlrpc_enabled filter, which most security plugins set, only turns away the methods that need a login and leaves the endpoint answering, so this check still reports it. Jetpack and the mobile apps are the usual reasons to keep it."
msgstr ""

#: config/docs.php:341
msgid "system.multicall bundles many calls into a single request. Since WordPress 4.4 the first failed login ends the rest of the batch, so it no longer multiplies password guesses, but one request still does the work of many. pingback.ping lets the site be used to probe other hosts."
msgstr ""

#: config/docs.php:340
msgid "Whether the XML-RPC endpoint answers method calls, and whether system.multicall and pingback.ping are among them. XML-RPC is the old remote interface at xmlrpc.php, which desktop and mobile clients used before the REST API existed."
msgstr ""

#: config/docs.php:325
msgid "Whether the site tells browsers that any origin may read its responses. Cross-origin resource sharing, CORS, is the rule set that decides which other websites may read what this one answers."
msgstr ""

#: config/docs.php:322
msgid "Set HttpOnly and SameSite=Lax at the web server, and Secure on every cookie once the site is on HTTPS. WordPress sets HttpOnly on its authentication cookies itself but does not set SameSite."
msgstr ""

#: config/docs.php:321
msgid "Without SameSite, a browser sends cookies along with requests started by other sites, which is the ingredient a cross-site request forgery needs. Without HttpOnly, any script on the page can read them. A server that drops the attributes on the cookie measured here usually drops them on the session cookies too."
msgstr ""

#: config/docs.php:320
msgid "The attributes on the cookies the login page hands out to a visitor who is not signed in: Secure, HttpOnly and SameSite. The session cookies themselves appear only after a successful sign-in and are out of reach of this check."
msgstr ""

#: config/docs.php:317
msgid "Start with Content-Security-Policy-Report-Only, watch the reports until they are quiet, then send the same policy as the enforcing header. Give the inline scripts a per-request nonce in the script tag, a random value the policy names, instead of allowing them all. That nonce is a different thing from the nonce WordPress puts into its forms."
msgstr ""

#: config/docs.php:316
msgid "A policy that allows inline scripts with nothing else in the directive permits exactly what a policy exists to prevent. Report-only mode blocks nothing at all. 'unsafe-inline' next to a nonce or 'strict-dynamic' is a different matter: browsers that understand either one ignore it, so the strict policy keeps it as a fallback for older browsers and is not reported here."
msgstr ""

#: config/docs.php:315
msgid "Whether a Content Security Policy is enforced, and whether a directive allows 'unsafe-inline' with no nonce beside it, allows 'unsafe-eval', or opens script loading to every host. A Content Security Policy, CSP for short, is a header that names which scripts a page is allowed to run."
msgstr ""

#: config/docs.php:310
msgid "Not just whether the HSTS header exists, but whether its max-age reaches the six months this check asks for and whether it covers subdomains. HSTS is the header that tells a browser to use https for this site from now on, without trying http first."
msgstr ""

#: config/docs.php:307
msgid "Send them from the web server so static files are covered too. Working starting values are X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, X-Frame-Options: SAMEORIGIN, Permissions-Policy: geolocation=(), camera=(), microphone=() and Strict-Transport-Security: max-age=31536000; includeSubDomains. The first two match what browsers already do and change nothing on an ordinary site. A Content Security Policy needs to be written for the site and has its own entry. The cross-origin isolation headers are treated as optional here because they break embeds on ordinary sites."
msgstr ""

#: config/docs.php:305
msgid "Which of the recommended response headers the site sends. A response header is a line the server sends along with a page that tells the browser how to treat it. Each missing header counts separately, except that X-Frame-Options is not asked for once the Content Security Policy sets frame-ancestors, which does the same job."
msgstr ""

#: config/docs.php:302
msgid "Renew it and then check that the renewal job actually ran, rather than assuming it will. Use a browser or an external test when you want the trust chain checked as well. A connection negotiated over TLS 1.0 or 1.1 is reported too; ask the host to allow 1.2 and 1.3 only."
msgstr ""

#: config/docs.php:301
msgid "An expired certificate replaces the site with a browser warning. Automatic renewal fails quietly more often than anyone expects, and the maximum certificate lifetime drops to 100 days in March 2027 and to 47 days in 2029."
msgstr ""

#: config/docs.php:300
msgid "How long the certificate is still valid and which protocol version the connection negotiates. TLS is the encryption behind the s in https. The trust chain and the host name are not verified, so this is a date, not a statement that browsers accept the certificate."
msgstr ""

#: config/docs.php:289
msgid "Revoke what is no longer in use, under Users, Profile. Each one is a standing credential. WordPress only offers application passwords over HTTPS. On a site without it, this check cannot tell a deliberate switch-off from the missing certificate and says so; passwords issued earlier stay in the database and are not listed."
msgstr ""

#: config/docs.php:288
msgid "Application passwords bypass the second factor by design. That makes a forgotten one the quietest way to keep access to a site, and an unused one from two years ago is worth more attention than the feature being switched on. WordPress records the last use at most once a day, and behind a content delivery network the address is the proxy address, not the caller."
msgstr ""

#: config/docs.php:287
msgid "Which application passwords exist for privileged accounts, when they were created, when they were last used and from which address, as far as the server sees it. An application password is a separate credential issued to a program rather than to a person."
msgstr ""

#: config/docs.php:284
msgid "Set it up for the accounts that are missing it, or require it for the administrator role. Two Factor is a widely used free plugin kept up by WordPress contributors and is a solid option. ReportedIP Hive, which we build ourselves, covers TOTP, email and passkeys in its Full Edition; the copy in the plugin directory is Hive Light and brings login protection only. It is named here because it fits, not because you need it. Coverage can only be read for the more common plugins; for others this check says so rather than guessing."
msgstr ""

#: config/docs.php:283
msgid "Whether the feature exists matters far less than who uses it. One administrator without a second factor is the account that will be targeted. A plugin that is installed and that nobody finished setting up is the same exposure as having no second factor at all."
msgstr ""

#: config/docs.php:279
msgid "Under Settings, General, set the default role to Subscriber, or switch registration off if the site does not need accounts. On a network the same switch sits under Network Admin, Settings, Registration Settings."
msgstr ""

#: config/docs.php:277
msgid "Whether anyone can register, and which role new accounts receive. On a network the registration setting of the network is read, because multisite ignores the per-site one."
msgstr ""

#: config/docs.php:274
msgid "Some plugins add capabilities on purpose, shop and membership plugins in particular. For anything else: unfiltered_html lets an account save raw HTML and JavaScript into posts, pages and widgets, which is stored cross-site scripting against every visitor and against the next administrator who opens the editor. WordPress has no screen for taking a capability back, so this needs a role editor plugin or one line of code in a plugin, remove_cap on the role. Deactivating the plugin that added it does not undo it, the capability stays in the database. A role that changed for a known reason keeps being reported: the comparison baseline is written once and not updated, so muting the check is the only way to acknowledge it, and it hides the capability findings along with it."
msgstr ""

#: config/docs.php:273
msgid "A subscriber with install_plugins is an administrator with a friendlier label. Compromised plugins add capabilities like this because it survives a password reset. A role that merely appeared since the first scan is reported apart from an escalation, because installing a shop or membership plugin does exactly that."
msgstr ""

#: config/docs.php:272
msgid "Whether any role below administrator holds capabilities such as install_plugins, edit_files or manage_options, and whether the role definitions changed since the first scan. A capability is one single permission; a role is a named bundle of them."
msgstr ""

#: config/docs.php:262
msgid "Whether an administrator uses a predictable login name such as admin, administrator, root, test or wordpress."
msgstr ""

#: config/docs.php:259
msgid "Reset those passwords now, then look at what the accounts did recently. Comparing hashes leaves no entry in the login log and triggers no lockout, so this check is safe to run repeatedly. Only accounts that can publish or administer are looked at, and on a site with hundreds of them the check says how many it got through."
msgstr ""

#: config/docs.php:251
msgid "Save the permalink settings once and WordPress writes a basic file. On nginx, Caddy and IIS there is no .htaccess, and this check says so instead of judging: the rules live in the server configuration and cannot be read from here."
msgstr ""

#: config/docs.php:249
msgid "Whether an .htaccess file exists, on servers that use one. That file is where Apache takes per-directory rules from."
msgstr ""

#: config/docs.php:244
msgid "Whether the server lists the contents of wp-content, the plugin folder, the uploads folder, the upgrade folder and wp-includes instead of refusing the request."
msgstr ""

#: config/docs.php:236
msgid "Delete phpinfo.php, info.php and test.php first. The rest can go too, but keep composer.json and package.json if the site is deployed with Composer or npm. WordPress restores readme.html, license.txt and wp-config-sample.php on every core update."
msgstr ""

#: config/docs.php:235
msgid "Most of them are only information: which WordPress version, which build tooling, which dependencies. phpinfo.php, info.php and test.php are different, they print the full PHP environment including paths and environment variables, and on installations that pass credentials through the environment that means the database password."
msgstr ""

#: config/docs.php:231
msgid "Delete it. If it was reachable, rotate the database password and the authentication keys, and treat the user data as disclosed. When the request for the file fails, the check says so instead of calling the file safe."
msgstr ""

#: config/docs.php:224
msgid "Whether .git, .svn or .hg directories are readable over HTTP. Those are the working folders of a version control system, the tool developers use to keep a history of every change."
msgstr ""

#: config/docs.php:221
msgid "Delete the files. If one was reachable, assume its contents are known: rotate the database password and the authentication keys. Two on the list are exceptions: .user.ini is the per-directory PHP configuration of the CGI and FastCGI builds and .htpasswd holds the credentials of a running HTTP authentication. Deny access to those at the server instead of deleting them."
msgstr ""

#: config/docs.php:216
msgid "Deny .php files in the uploads directory. On Apache and LiteSpeed an .htaccess in that directory does it, as long as AllowOverride allows the rule; on nginx and Caddy it belongs in the server configuration. Where the file comes back as text, deny access to it rather than only switching the interpreter off."
msgstr ""

#: config/docs.php:215
msgid "A server that runs PHP here turns a file upload flaw into code execution. A server that hands the file out as text instead runs nothing, but lets anyone read back what was uploaded, and that is a different fix."
msgstr ""

#: config/docs.php:211
msgid "Open each file before deleting it, and check the upload date against the server log. A hardening .htaccess in this directory is not a finding and is not reported here. Small index.php files that only stop the folder from being listed are read and waved through; when one is reported anyway, the finding names what it does that a placeholder would not, for instance reading request data or calling another file."
msgstr ""

#: config/docs.php:209
msgid "Executable files sitting among the media uploads, separated by whether the web server would run them. A .php or .cgi file is code this site executes; an installer or a shell script is a download."
msgstr ""

#: config/docs.php:206
msgid "Set files to 644 and directories to 755. wp-config.php is the exception, it belongs at 640 or 440. If something only works at 777, the ownership is wrong and that is the thing to fix."
msgstr ""

#: config/docs.php:204
msgid "Files and folders that carry the world-writable bit. Four places are looked at, one level deep each: the web root, wp-content, the plugin folder and the theme folder. wp-config.php, wp-admin, wp-includes, wp-content and the uploads folder are left out: they have a check of their own, and counting them twice would let one chmod lower the grade twice."
msgstr ""

#: config/docs.php:201
msgid "Set the directories to 755, or 750 where the group is right. Apply it to the directory itself, not recursively to everything inside, otherwise the files below end up executable too. Where the permissions cannot be read at all the check says so rather than reporting them as fine."
msgstr ""

#: config/docs.php:200
msgid "A world-writable core directory lets any account on the server drop a file that WordPress will then execute. On shared hosting that is not a theoretical neighbour, it is every other customer on the same machine."
msgstr ""

#: config/docs.php:196
msgid "Set it to 755, or 750 where the group is right. This check deliberately accepts anything that is not world-writable, so 755 is enough to clear it."
msgstr ""

#: config/docs.php:191
msgid "Take the read right away from everyone else: 640 keeps it readable for the owner and the group, 440 does the same without owner write. Both only work while PHP runs as the owning account or in the owning group, which is the normal setup with suEXEC or a per-account PHP-FPM pool. If the site goes blank after the change, PHP runs as a different account and the group ownership is what needs fixing, not the mode. Never 777."
msgstr ""

#: config/docs.php:190
msgid "The file holds the database credentials and the authentication keys. On shared hosting, world-readable means readable by every other account on the machine, and a writable wp-config.php means somebody else can add code that runs before WordPress does."
msgstr ""

#: config/docs.php:189
msgid "The permission bits on wp-config.php: whether every account on the server may write to it, and whether every account may read it."
msgstr ""

#: config/docs.php:183
msgid "Enforce a minimum strength at least for accounts that can publish or administer. A password manager and a long passphrase beat any complexity rule, so aim for length rather than for symbols. This check only sees plugins, so a rule enforced by a theme, an identity provider or the hosting platform is invisible to it and the finding can be muted."
msgstr ""

#: config/docs.php:182
msgid "WordPress warns about a weak password, asks for a confirming tick and then accepts it anyway. A warning is not a policy, and the accounts that pick a weak password are rarely the ones reading the warning."
msgstr ""

#: config/docs.php:181
msgid "Whether a plugin enforces a minimum password strength when an account sets or changes its password."
msgstr ""

#: config/docs.php:178
msgid "Install a login limiter, or rate limit wp-login.php and xmlrpc.php at the web server, which is cheaper and harder to bypass. This check only sees plugins, so if the limit already sits in the server or in front of the site, mute it."
msgstr ""

#: config/docs.php:168
msgid "A backup needs three things to count: it holds the database as well as the files, it is stored somewhere the site itself cannot write to, and it has been restored at least once so you know it works. A backup taken by the host counts just as much, and so does one from a plugin this check does not know. If the backup lives outside WordPress, mute this check so it stops asking."
msgstr ""

#: config/docs.php:166
msgid "Whether a known backup plugin is active. Only plugins are visible from here, not what the host does behind the scenes."
msgstr ""

#: config/docs.php:163
msgid "Trace a code fragment back to the plugin that wrote it before deleting anything. For script tags, go through the list once and check that every host is one you chose."
msgstr ""

#: config/docs.php:162
msgid "Search engine spam is written into the options table far more often than into files, because it survives a plugin reinstall and never shows up in a file comparison. A code fragment in an option is the strong signal. A foreign script tag is the weak one, since analytics and consent tools store theirs the same way."
msgstr ""

#: config/docs.php:161
msgid "Option values that contain code fragments, and option values that load a script from another host."
msgstr ""

#: config/docs.php:158
msgid "Look at what the largest entries contain before deleting anything. Some plugins legitimately store a lot. WordPress itself starts warning at roughly 800 KB of autoloaded options, and this check uses the same mark."
msgstr ""

#: config/docs.php:156
msgid "How much option data WordPress loads on every single request. Options marked to autoload are read before anything else happens, whether the page needs them or not."
msgstr ""

#: config/docs.php:153
msgid "If DISABLE_WP_CRON is set, make sure a server cron job triggers wp-cron.php. Otherwise remove the constant. WordPress has no screen that lists scheduled events, so use wp cron event list or a scheduler plugin to look at them. A hook listed here as having no listener was simply not registered during this request, which happens with plugins that only hook up in the front end."
msgstr ""

#: config/docs.php:148
msgid "Create a dedicated account limited to this database and update wp-config.php. Most hosting panels have a form for exactly that under the database section."
msgstr ""

#: config/docs.php:147
msgid "Full rights on the site database are normal, including the right to pass those same rights on. Full rights on every database, or the right to hand out rights on every database, means one injection reaches past this site."
msgstr ""

#: config/docs.php:146
msgid "Whether the database account WordPress uses holds rights beyond its own database. An account that is not allowed to look at its own rights is reported as undetermined."
msgstr ""

#: config/docs.php:143
msgid "Change it during a migration rather than as a standalone step on a live site. Renaming the tables is not enough: the prefix also appears in the option name wp_user_roles and in the user meta keys wp_capabilities and wp_user_level, and missing those leaves every account without its role."
msgstr ""

#: config/docs.php:141
msgid "Whether the database still uses the default table prefix wp_. On a network the base prefix is what is looked at, since every subsite adds its own number to it."
msgstr ""

#: config/docs.php:138
msgid "Generate a fresh set at api.wordpress.org/secret-key/1.1/salt/ and paste it over the block in wp-config.php. Everyone is logged out once, which is also how you evict a stolen session. Nothing records when the keys last changed, so the age reported here is the age of wp-config.php, which any unrelated edit resets."
msgstr ""

#: config/docs.php:137
msgid "These values sign every login cookie and every nonce, the one-time token WordPress puts into its forms and links so that another site cannot submit them on your behalf. Weak or duplicated values make a stolen cookie easier to forge and harder to invalidate."
msgstr ""

#: config/docs.php:136
msgid "Whether all eight authentication keys and salts are defined, long enough, not placeholders and not repeated. They are the random values in wp-config.php that WordPress mixes into everything it signs."
msgstr ""

#: config/docs.php:128
msgid "Add define( 'DISALLOW_FILE_EDIT', true ); to wp-config.php. Nobody edits production code in a browser textarea anyway. Either constant closes it: DISALLOW_FILE_EDIT does it directly, DISALLOW_FILE_MODS does it as a side effect of blocking installs."
msgstr ""

#: config/docs.php:127
msgid "The editor turns one stolen administrator password into arbitrary code execution, with no upload and no vulnerability required. That is the shortest path there is from a stolen login to running code."
msgstr ""

#: config/docs.php:123
msgid "Delete the file and keep the log outside the web root by setting WP_DEBUG_LOG to a path above it. A log that exists but is not served is still worth deleting once the problem is solved."
msgstr ""

#: config/docs.php:121
msgid "Whether a debug log exists and whether the web server hands it out. For a log at a path of your own choosing the check works out where that path sits: above the web root it is out of reach and the check passes, below it the same download test runs as for the default location."
msgstr ""

#: config/docs.php:118
msgid "Set WP_DEBUG to false in production and do the debugging on a staging copy. If debug mode has to stay on for a while, at least set WP_DEBUG_DISPLAY to false so nothing reaches the page."
msgstr ""

#: config/docs.php:117
msgid "Error output names file paths, database details and plugin internals. It is a free map of the installation for whoever triggers an error on purpose. Debug mode with the output switched off is the milder case and is reported as such."
msgstr ""

#: config/docs.php:116
msgid "Whether debug output is switched on, and whether errors are printed into the page. SCRIPT_DEBUG and SAVEQUERIES are listed along with it when they are set."
msgstr ""

#: config/docs.php:110
msgid "Keep every installation updated, or delete the ones nobody uses. The check only sees what is next to this installation, not the rest of the hosting account."
msgstr ""

#: config/docs.php:108
msgid "Whether other WordPress installations sit in the directory above this one, down to two levels."
msgstr ""

#: config/docs.php:105
msgid "The first run records what is present and lists it for information. Only something that appears afterwards is reported as a finding, and that is what to open first. Managed hosts legitimately place their own caching drop-ins here."
msgstr ""

#: config/docs.php:103
msgid "Must-use plugins, which are files in wp-content/mu-plugins that WordPress loads without anyone activating them, and drop-ins such as object-cache.php, advanced-cache.php and db.php, which replace a piece of WordPress itself. Both are compared against what was there at the first scan."
msgstr ""

#: config/docs.php:98
msgid "Whether the author line of an installed plugin changed since the first scan. The first run only records the authors, so changes are reported from the second run on."
msgstr ""

#: config/docs.php:93
msgid "Whether any active plugin has had its listing closed in the WordPress plugin directory. Plugins that were never listed there are left out, and a listing the site could not retrieve is reported as undetermined rather than as fine."
msgstr ""

#: config/docs.php:88
msgid "How long ago each active plugin was last released, and which WordPress version its author last tested against. Only plugins the WordPress directory knows are asked about; a commercial or in-house plugin is skipped rather than guessed at."
msgstr ""

#: config/docs.php:80
msgid "Install the updates under Appearance, Themes, and delete the ones the site does not use. Keep one unmodified default theme so a broken theme can be switched out, and switch automatic updates on for it. A theme bought outside the directory updates only when its licence key is entered, so check that too."
msgstr ""

#: config/docs.php:79
msgid "Themes get less attention than plugins and ship the same kind of code. The active theme runs on every page load, and an inactive one still sits on disk where a direct request can reach its files."
msgstr ""

#: config/docs.php:78
msgid "Whether any installed theme has an update waiting. Inactive themes count too, because the update is what they are missing either way."
msgstr ""

#: config/docs.php:75
msgid "Install the updates. Turn on automatic updates for the plugins you have no reason to hold back. When WordPress holds no update information at all, this is reported as undetermined instead of as up to date."
msgstr ""

#: config/docs.php:70
msgid "Open each file before deleting it. Note that a few hosts do drop their own helper files into these directories. On very large installations the scan stops after a set number of files and says so; that result is not an all clear."
msgstr ""

#: config/docs.php:65
msgid "Reinstall WordPress from Dashboard, Updates. If the same files change again afterwards, treat the site as compromised and rebuild it. Fingerprints are only published for release builds, so a nightly or a patched build is reported as undetermined rather than as clean."
msgstr ""

#: config/docs.php:63
msgid "Every core file against the checksums WordPress.org publishes for this exact release. A checksum is a short fingerprint of a file: two files with the same fingerprint have the same contents."
msgstr ""

#: config/docs.php:60
msgid "Leave the default in place, or set WP_AUTO_UPDATE_CORE to minor. Setting it to true is fine too and covers more. Where DISALLOW_FILE_MODS has to stay, the deployment has to install core updates instead, because that constant stops the updater as well."
msgstr ""

#: config/docs.php:58
msgid "Whether WordPress may install its own security releases, across all four switches: the WP_AUTO_UPDATE_CORE constant, AUTOMATIC_UPDATER_DISABLED, the ban on file modifications and the site setting for minor releases. A pre-release channel is reported as well, because it installs unfinished code on a production site."
msgstr ""

#: config/docs.php:55
msgid "Ask the host to move the site to a supported branch. Test on a staging copy first: a PHP jump is the one upgrade that reliably breaks old plugins. A warning six months ahead of the date is there so the move can be planned rather than rushed."
msgstr ""

#: config/docs.php:53
msgid "Whether the PHP branch this site runs on still receives security fixes, measured against the published end-of-life dates. The last six months before that date and the phase in which a branch only gets security fixes and no more bug fixes are reported separately."
msgstr ""

#: config/docs.php:50
msgid "Install the update. Leave automatic minor updates switched on so security releases arrive without anyone having to notice them. If the site cannot reach api.wordpress.org, the check says the version could not be determined rather than calling the site current."
msgstr ""

#: config/docs.php:48
msgid "Whether the installed WordPress release is the current one, read from the update information WordPress already holds."
msgstr ""

#: config/docs.php:29
msgid "No shell needed: every hosting panel has a file manager, and every FTP client has a permissions dialog. Look for \"Change permissions\", \"CHMOD\" or \"File attributes\" and enter the number there. The three digits are owner, group and everyone, in that order."
msgstr ""

#. translators: %s: name of a PHP function, for example base64_decode.
#: includes/checks/class-cascr-checks-files.php:518
msgid "it calls %s"
msgstr ""

#. translators: %s: name of a PHP superglobal, for example $_GET.
#: includes/checks/class-cascr-checks-files.php:505
msgid "it reads %s"
msgstr ""

#. translators: %s: a PHP keyword such as require or eval.
#: includes/checks/class-cascr-checks-files.php:496
msgid "it uses %s"
msgstr ""

#. translators: %s: reason the file was reported, for example "it reads
#. $_SERVER".
#: includes/checks/class-cascr-checks-files.php:340
msgid ", reported because %s"
msgstr ""

#. translators: 1: file path, 2: file size, already formatted, 3: why the file
#. was reported, or an empty string.
#: includes/checks/class-cascr-checks-files.php:335
msgid "%1$s (%2$s)%3$s"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:619
msgid "A two-factor plugin is active, but no administrator has set the second factor up."
msgstr ""

#. translators: %d: number of checks that could not be completed.
#: includes/class-cascr-scoring.php:202
msgid "%d check could not be completed and is not counted."
msgid_plural "%d checks could not be completed and are not counted."
msgstr[0] ""
msgstr[1] ""

#. translators: %d: number of warnings.
#: includes/class-cascr-scoring.php:185
msgid "%d more is worth improving."
msgid_plural "%d more are worth improving."
msgstr[0] ""
msgstr[1] ""

#. translators: %d: number of failed checks.
#: includes/class-cascr-scoring.php:172
msgid "%d finding needs your attention now."
msgid_plural "%d findings need your attention now."
msgstr[0] ""
msgstr[1] ""

#: includes/class-cascr-admin.php:269
msgid "Every check with its detail, filterable, and the report to take away."
msgstr ""

#: includes/class-cascr-admin.php:267
msgid "Go through everything else"
msgstr ""

#: includes/class-cascr-admin.php:266
msgid "Step 3:"
msgstr ""

#: includes/class-cascr-admin.php:257 includes/class-cascr-admin.php:274
msgid "Appears once the check has run."
msgstr ""

#: includes/class-cascr-admin.php:252
msgid "A grade, what it means, and the short list to work through."
msgstr ""

#: includes/class-cascr-admin.php:250
msgid "Your result"
msgstr ""

#: includes/class-cascr-admin.php:249
msgid "Step 2:"
msgstr ""

#: includes/class-cascr-admin.php:319
msgid "Tick the box above to start."
msgstr ""

#: includes/class-cascr-admin.php:238
msgid "Start the security check"
msgstr ""

#. translators: %d: number of checks the plugin runs.
#: includes/class-cascr-admin.php:227
msgid "%d checks, about a minute. Nothing on your site is changed."
msgstr ""

#: includes/class-cascr-admin.php:221
msgid "Start the check"
msgstr ""

#: includes/class-cascr-admin.php:220
msgid "Step 1:"
msgstr ""

#: includes/class-cascr-admin.php:514
msgid "Take the report with you"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:372
msgid "Work through these in order. Everything else can wait."
msgstr ""

#: includes/class-cascr-admin.php:114
msgid "Your to-do list"
msgstr ""

#: includes/class-cascr-scoring.php:242
msgid "Poor"
msgstr ""

#: includes/class-cascr-scoring.php:241
msgid "Moderate"
msgstr ""

#: includes/class-cascr-scoring.php:240
msgid "Good"
msgstr ""

#: includes/class-cascr-scoring.php:239
msgid "Excellent"
msgstr ""

#: includes/class-cascr-runner.php:37
msgid "The check could not be completed on this server."
msgstr ""

#: includes/class-cascr-result.php:115
msgid "The check returned an unexpected result."
msgstr ""

#: includes/class-cascr-rest.php:173 includes/class-cascr-rest.php:198
msgid "There is no check with that identifier."
msgstr ""

#: includes/class-cascr-rest.php:141
msgid "You are not allowed to run security checks on this site."
msgstr ""

#: includes/class-cascr-registry.php:663
msgid "Client IP detection"
msgstr ""

#: includes/class-cascr-registry.php:651
msgid "Unauthenticated REST routes"
msgstr ""

#: includes/class-cascr-registry.php:633
msgid "Legacy discovery tags"
msgstr ""

#: includes/class-cascr-registry.php:627
msgid "PHP version in response headers"
msgstr ""

#: includes/class-cascr-registry.php:615
msgid "Cookie flags"
msgstr ""

#: includes/class-cascr-registry.php:609
msgid "Content Security Policy"
msgstr ""

#: includes/class-cascr-registry.php:603
msgid "HSTS configuration"
msgstr ""

#: includes/class-cascr-registry.php:597
msgid "Security headers"
msgstr ""

#: includes/class-cascr-registry.php:591
msgid "TLS certificate"
msgstr ""

#: includes/class-cascr-registry.php:585
msgid "HTTPS"
msgstr ""

#: includes/class-cascr-registry.php:563
msgid "Two-factor coverage"
msgstr ""

#: includes/class-cascr-registry.php:557
msgid "Open registration"
msgstr ""

#: includes/class-cascr-registry.php:551
msgid "Role and capability changes"
msgstr ""

#: includes/class-cascr-registry.php:545
msgid "Administrator accounts"
msgstr ""

#: includes/class-cascr-registry.php:539
msgid "Predictable administrator name"
msgstr ""

#: includes/class-cascr-registry.php:533
msgid "Weak passwords"
msgstr ""

#: includes/class-cascr-registry.php:517
msgid "Server rule file"
msgstr ""

#: includes/class-cascr-registry.php:511
msgid "Directory listing"
msgstr ""

#: includes/class-cascr-registry.php:505
msgid "Leftovers from interrupted updates"
msgstr ""

#: includes/class-cascr-registry.php:499
msgid "Leftover files in the web root"
msgstr ""

#: includes/class-cascr-registry.php:493
msgid "Publicly readable database dumps"
msgstr ""

#: includes/class-cascr-registry.php:487
msgid "Publicly readable repository folders"
msgstr ""

#: includes/class-cascr-registry.php:481
msgid "Publicly readable configuration files"
msgstr ""

#: includes/class-cascr-registry.php:469
msgid "Executable files in uploads"
msgstr ""

#: includes/class-cascr-registry.php:463
msgid "World-writable files and folders"
msgstr ""

#: includes/class-cascr-registry.php:457
msgid "Core directory permissions"
msgstr ""

#: includes/class-cascr-registry.php:429
msgid "Password policy"
msgstr ""

#: includes/class-cascr-registry.php:423
msgid "Login protection"
msgstr ""

#: includes/class-cascr-registry.php:416
msgid "Installed security plugins"
msgstr ""

#: includes/class-cascr-registry.php:410
msgid "Backups"
msgstr ""

#: includes/class-cascr-registry.php:404
msgid "Injected content in options"
msgstr ""

#: includes/class-cascr-registry.php:398
msgid "Autoloaded options size"
msgstr ""

#: includes/class-cascr-registry.php:392
msgid "WP-Cron health"
msgstr ""

#: includes/class-cascr-registry.php:380
msgid "Database table prefix"
msgstr ""

#: includes/class-cascr-registry.php:368
msgid "Installing code from the dashboard"
msgstr ""

#: includes/class-cascr-registry.php:362
msgid "Theme and plugin editor"
msgstr ""

#: includes/class-cascr-registry.php:350
msgid "Debug mode"
msgstr ""

#: includes/class-cascr-registry.php:328
msgid "Must-use plugins and drop-ins"
msgstr ""

#: includes/class-cascr-registry.php:322
msgid "Plugin ownership changes"
msgstr ""

#: includes/class-cascr-registry.php:316
msgid "Plugins removed from the directory"
msgstr ""

#: includes/class-cascr-registry.php:310
msgid "Abandoned plugins"
msgstr ""

#: includes/class-cascr-registry.php:304
msgid "Unused plugins and themes"
msgstr ""

#: includes/class-cascr-registry.php:298
msgid "Theme updates"
msgstr ""

#: includes/class-cascr-registry.php:292
msgid "Plugin updates"
msgstr ""

#: includes/class-cascr-registry.php:286
msgid "Unknown files in core directories"
msgstr ""

#: includes/class-cascr-registry.php:268
msgid "PHP version"
msgstr ""

#: includes/class-cascr-registry.php:184
msgid "Network and transport"
msgstr ""

#: includes/class-cascr-registry.php:183
msgid "Accounts and access"
msgstr ""

#: includes/class-cascr-registry.php:182
msgid "Files and permissions"
msgstr ""

#: includes/class-cascr-registry.php:181
msgid "Configuration"
msgstr ""

#: includes/class-cascr-registry.php:180
msgid "Core, plugins and themes"
msgstr ""

#: includes/class-cascr-cli.php:111
msgid "Nothing needs your attention."
msgstr ""

#: includes/class-cascr-cli.php:74
msgid "risk score"
msgstr ""

#: includes/class-cascr-admin.php:575
msgid "Low"
msgstr ""

#: includes/class-cascr-admin.php:574
msgid "Medium"
msgstr ""

#: includes/class-cascr-admin.php:573
msgid "High"
msgstr ""

#: includes/class-cascr-admin.php:572 includes/class-cascr-scoring.php:243
msgid "Critical"
msgstr ""

#: includes/class-cascr-admin.php:200
msgid "Report a false positive"
msgstr ""

#: includes/class-cascr-admin.php:196
msgid "WordPress security"
msgstr ""

#: includes/class-cascr-admin.php:188
msgid "No check matches that search."
msgstr ""

#: includes/class-cascr-admin.php:177 includes/class-cascr-admin.php:182
msgid "Search the checks"
msgstr ""

#: includes/class-cascr-admin.php:173
msgid "What each check looks at"
msgstr ""

#: includes/class-cascr-admin.php:290
msgid "These checks read the site, write one temporary file to the uploads folder and delete it again. The result is an assessment rather than a guarantee."
msgstr ""

#. translators: %d: number of checks the plugin runs.
#: includes/class-cascr-admin.php:156
msgid "%d check across your WordPress installation."
msgid_plural "%d checks across your WordPress installation."
msgstr[0] ""
msgstr[1] ""

#: includes/class-cascr-admin.php:134
msgid "The security check finished."
msgstr ""

#: includes/class-cascr-admin.php:128
msgid "Severity"
msgstr ""

#: includes/class-cascr-admin.php:127
msgid "Category"
msgstr ""

#: includes/class-cascr-admin.php:126
msgid "Check"
msgstr ""

#: includes/class-cascr-admin.php:122
msgid "Checks"
msgstr ""

#: includes/class-cascr-admin.php:121
msgid "Summary"
msgstr ""

#: includes/class-cascr-admin.php:120 includes/class-cascr-cli.php:71
msgid "Grade"
msgstr ""

#: includes/class-cascr-admin.php:119
msgid "Generated"
msgstr ""

#: includes/class-cascr-admin.php:117
msgid "The report could not be copied."
msgstr ""

#: includes/class-cascr-admin.php:116
msgid "The report was copied to the clipboard."
msgstr ""

#: includes/class-cascr-admin.php:510
msgid "Copy report"
msgstr ""

#: includes/class-cascr-admin.php:509
msgid "Download as CSV"
msgstr ""

#: includes/class-cascr-admin.php:508
msgid "Download as JSON"
msgstr ""

#: includes/class-cascr-admin.php:507
msgid "Download as text"
msgstr ""

#: includes/class-cascr-admin.php:494
msgid "Muted until the finding changes."
msgstr ""

#: includes/class-cascr-admin.php:491
msgid "Unmute"
msgstr ""

#: includes/class-cascr-admin.php:491
msgid "Mute this finding"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:424
#: includes/class-cascr-admin.php:488
msgid "Read more about this check"
msgstr ""

#: includes/class-cascr-admin.php:467
msgid "Details"
msgstr ""

#: includes/class-cascr-admin.php:383
msgid "All checks"
msgstr ""

#: includes/class-cascr-admin-dashboard.php:383
#: includes/class-cascr-scoring.php:196
msgid "Nothing needs your attention right now."
msgstr ""

#: includes/class-cascr-admin-dashboard.php:91
#: includes/class-cascr-admin.php:113
msgid "Risk score"
msgstr ""

#: includes/class-cascr-admin.php:374
msgid "All"
msgstr ""

#: includes/class-cascr-admin.php:112 includes/class-cascr-admin.php:379
msgid "Muted"
msgstr ""

#: includes/class-cascr-admin.php:108 includes/class-cascr-admin.php:378
#: includes/class-cascr-admin.php:592
msgid "Not determined"
msgstr ""

#: includes/class-cascr-admin.php:107 includes/class-cascr-admin.php:375
#: includes/class-cascr-admin.php:591
msgid "Failed"
msgstr ""

#: includes/class-cascr-admin.php:106 includes/class-cascr-admin.php:376
#: includes/class-cascr-admin.php:590
msgid "Warning"
msgstr ""

#: includes/class-cascr-admin.php:105 includes/class-cascr-admin.php:377
#: includes/class-cascr-admin.php:589
msgid "Passed"
msgstr ""

#: includes/class-cascr-admin.php:104
msgid "This check could not be completed."
msgstr ""

#. translators: 1: number of the check being run, 2: total number of checks.
#: includes/class-cascr-admin.php:103
msgid "Check %1$d of %2$d"
msgstr ""

#: includes/class-cascr-admin.php:24 includes/class-cascr-nudges.php:99
msgid "Security Check"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:1095
msgid "Send the headers from the web server so they cover static files too. Start with X-Content-Type-Options and Referrer-Policy, they never break anything."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:1045
msgid "Forwarded address headers arrive from a proxy in front of the site, which is the expected setup."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:1028
msgid "No forwarded address headers arrive, so the client address cannot be faked through them."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:889
msgid "The REST API is not available."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:875
msgid "User names can be read without logging in, which turns password guessing from two unknowns into one."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:871
msgid "The usual ways of reading out user names are closed."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:870
msgid "User enumeration could not be checked."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:864
msgid "the oEmbed endpoint reveals the author"
msgstr ""

#. translators: %d: number of user records returned by the REST API.
#: includes/checks/class-cascr-checks-network.php:847
msgid "the REST endpoint /wp/v2/users lists %d account"
msgid_plural "the REST endpoint /wp/v2/users lists %d accounts"
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-network.php:777
msgid "The XML-RPC endpoint answers method calls."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:772
msgid "pingback.ping is available, which lets the site be used to probe other hosts"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:751
msgid "The XML-RPC endpoint does not answer method calls."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:747
msgid "The XML-RPC endpoint is blocked."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:740
msgid "The XML-RPC endpoint could not be reached."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:719
msgid "Remove the generator, wlwmanifest and RSD hooks from wp_head. This is fingerprinting, not a hole in itself."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:716
msgid "The front page emits discovery tags that give away details about the installation."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:712
msgid "The front page emits no legacy discovery tags."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:708
msgid "Really Simple Discovery link"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:704
msgid "Windows Live Writer manifest link"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:700
msgid "generator tag naming WordPress"
msgstr ""

#. translators: %s: WordPress version number.
#: includes/checks/class-cascr-checks-network.php:697
msgid "generator tag naming WordPress %s"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:687
msgid "The front page could not be retrieved."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:671
msgid "The response headers name the exact software versions in use, which saves an attacker the work of finding out."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:667
msgid "The response headers do not name software versions."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:639
msgid "Cross-origin access is limited to a named origin."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:634
msgid "Name the origins that are actually allowed instead of using the wildcard."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:631
msgid "Every origin is allowed to read responses from this site."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:625
msgid "Never combine the two. Name the origins that are actually allowed."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:622
msgid "Every origin is allowed to read responses and to send credentials along."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:617
msgid "No cross-origin headers are sent, which is the right default."
msgstr ""

#. translators: %s: cookie name.
#: includes/checks/class-cascr-checks-network.php:583
msgid "%s has no SameSite attribute"
msgstr ""

#. translators: %s: cookie name.
#: includes/checks/class-cascr-checks-network.php:564
msgid "%s is not marked Secure"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:540
msgid "The login page set no cookies that could be inspected."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:533
msgid "The login page could not be requested."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:514
msgid "Replace unsafe-inline with a nonce or a hash for the scripts the site really needs."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:501
msgid "A Content Security Policy is enforced and contains no obvious escape hatch."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:496
msgid "neither default-src nor object-src is set"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:491
msgid "a wildcard source allows scripts from anywhere"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:486
msgid "'unsafe-eval' allows strings to be executed as code"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:481
msgid "'unsafe-inline' allows injected inline scripts to run"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:440
msgid "Once the reports are quiet, send the same policy as Content-Security-Policy."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:437
msgid "The Content Security Policy is only sent in report-only mode, so nothing is actually blocked."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:431
msgid "Start with Content-Security-Policy-Report-Only, watch the reports for a while, then switch it to the enforcing header."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:428
msgid "No Content Security Policy is sent, so an injected script runs with no restriction."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:394
msgid "The HSTS header is set up properly."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:389
msgid "includeSubDomains is not set"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:351
msgid "Send Strict-Transport-Security: max-age=31536000; includeSubDomains once the whole site is reliably on HTTPS."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:348
msgid "No HSTS header is sent, so the first request of a visit can still be downgraded to http."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:335
msgid "HSTS only applies to sites served over HTTPS."
msgstr ""

#. translators: %d: number of missing security headers.
#: includes/checks/class-cascr-checks-network.php:314
msgid "%d recommended security header is missing."
msgid_plural "%d recommended security headers are missing."
msgstr[0] ""
msgstr[1] ""

#. translators: %s: comma separated list of optional headers.
#: includes/checks/class-cascr-checks-network.php:303
msgid "optional and not set: %s"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:297
msgid "All recommended security headers are present."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:257
#: includes/checks/class-cascr-checks-network.php:341
#: includes/checks/class-cascr-checks-network.php:420
#: includes/checks/class-cascr-checks-network.php:610
#: includes/checks/class-cascr-checks-network.php:653
msgid "The response headers could not be retrieved."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:234
msgid "Ask the host to allow TLS 1.2 and 1.3 only."
msgstr ""

#. translators: %s: negotiated TLS protocol version.
#: includes/checks/class-cascr-checks-network.php:229
msgid "The connection was negotiated over %s, which browsers have retired."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:208
msgid "Renew it and check that automatic renewal runs."
msgstr ""

#. translators: %s: human readable time until expiry.
#: includes/checks/class-cascr-checks-network.php:203
msgid "The TLS certificate expires in %s."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:195
msgid "Renew the certificate now and check that automatic renewal actually runs."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:192
msgid "The TLS certificate has expired. Visitors get a browser warning instead of the site."
msgstr ""

#. translators: %s: certificate expiry date.
#: includes/checks/class-cascr-checks-network.php:180
msgid "valid until %s"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:158
msgid "The certificate could not be parsed."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:152
msgid "The certificate could not be read."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:140
msgid "No TLS connection to the site could be opened from the server itself."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:112
msgid "This server cannot inspect TLS certificates."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:108
msgid "The site does not use HTTPS, so there is no certificate to inspect."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:90
msgid "Add define( 'FORCE_SSL_ADMIN', true ); to wp-config.php and redirect http to https with a 301."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:80
msgid "The site is served over HTTPS and http is redirected."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:74
msgid "the http address does not redirect permanently to https"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:62
msgid "FORCE_SSL_ADMIN is not set"
msgstr ""

#: includes/checks/class-cascr-checks-network.php:55
msgid "Get a certificate, switch the site and home addresses to https and redirect http to https."
msgstr ""

#: includes/checks/class-cascr-checks-network.php:52
msgid "The site address still uses http, so every login and every form submission travels in the clear."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:1006
msgid "Save the permalink settings once. WordPress writes a basic .htaccess by itself."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:1003
msgid "No .htaccess file was found, so none of the usual hardening rules are in place."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:994
msgid "This server does not use .htaccess. Its rules live in the server configuration and cannot be inspected from here."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:977
msgid "The server does not list directory contents."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:974
msgid "Directory listing could not be checked."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:966
msgid "The server lists directory contents, which hands attackers a map of the installation."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:924
msgid "These folders can hold unpacked, outdated copies of plugins that are still reachable. Delete them."
msgstr ""

#. translators: %d: number of leftover directories.
#: includes/checks/class-cascr-checks-files.php:914
msgid "%d leftover from an interrupted update is still on disk."
msgid_plural "%d leftovers from interrupted updates are still on disk."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:908
msgid "No leftovers from interrupted updates were found."
msgstr ""

#. translators: 1: path, 2: human readable age.
#: includes/checks/class-cascr-checks-files.php:900
msgid "%1$s, left behind %2$s ago"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:866
msgid "These files reveal version and tooling details. Deleting them is safe."
msgstr ""

#. translators: %d: number of leftover files.
#: includes/checks/class-cascr-checks-files.php:856
msgid "%d leftover file sits in the web root."
msgid_plural "%d leftover files sit in the web root."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:850
msgid "The web root holds no leftover files."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:825
msgid "Move the files somewhere outside the web root."
msgstr ""

#. translators: %d: number of dumps or archives found.
#: includes/checks/class-cascr-checks-files.php:815
msgid "%d database dump or archive sits in the web root but is not served."
msgid_plural "%d database dumps or archives sit in the web root but are not served."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:807
msgid "Delete the file immediately and assume its contents are known. Then rotate the database password and the authentication keys."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:804
msgid "A database dump or archive can be downloaded from the site."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:773
msgid "No database dumps or archives were found in the web root."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:744
msgid "No version control directory is readable from the web."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:741
msgid "The version control paths could not be checked."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:736
msgid "Block the directory at the server, or deploy without the repository metadata."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:733
msgid "A version control directory is readable from the web, which exposes the full source history and often credentials along with it."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:705
msgid "No configuration or backup files were found in the web root."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:702
msgid "It could not be verified whether these files are publicly readable."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:697
msgid "Move the files out of the web root. A server configuration change is all it takes to expose them."
msgstr ""

#. translators: %d: number of configuration files present but not served.
#: includes/checks/class-cascr-checks-files.php:687
msgid "%d configuration or backup file sits in the web root but is not served."
msgid_plural "%d configuration or backup files sit in the web root but are not served."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:679
msgid "Delete the files. Anything readable here can contain database credentials and API keys."
msgstr ""

#. translators: %d: number of publicly readable configuration files.
#: includes/checks/class-cascr-checks-files.php:669
msgid "%d configuration or backup file is readable from the web."
msgid_plural "%d configuration or backup files are readable from the web."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:629
msgid "PHP files in the uploads directory are not executed."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:613
msgid "The server runs PHP files from the uploads directory, which turns any file upload flaw into code execution."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:602
msgid "PHP files in the uploads directory are not served."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:596
msgid "The test file could not be requested over HTTP."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:578
msgid "A test file could not be written to the uploads directory."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:561
msgid "The filesystem could not be initialised for this check."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:369
msgid "Media uploads never need to be executable. Inspect each file before deleting it."
msgstr ""

#. translators: %d: number of executable files found in uploads.
#: includes/checks/class-cascr-checks-files.php:359
msgid "%d executable file sits in the uploads directory."
msgid_plural "%d executable files sit in the uploads directory."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:391
msgid "The uploads directory holds no executable files."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:352
msgid "The uploads directory could not be scanned completely."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:286
msgid "The uploads directory could not be read."
msgstr ""

#. translators: %d: number of world-writable paths.
#: includes/checks/class-cascr-checks-files.php:228
msgid "%d path is writable by every account on the server."
msgid_plural "%d paths are writable by every account on the server."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:166
msgid "No core directory is writable by everyone."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:163
msgid "The permissions of the core directories could not be read."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:155
msgid "Core directories are writable by everyone on the server."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:117
msgid "The uploads directory is not writable by everyone."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:113
msgid "Set the directory to 755 or 750. It only needs to be writable by the account that runs PHP."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:110
msgid "The uploads directory is writable by everyone on the server."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:98
msgid "The permissions of the uploads directory could not be read."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:92
#: includes/checks/class-cascr-checks-files.php:567
msgid "The uploads directory could not be located."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:80
msgid "The permissions of wp-config.php are restrictive."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:76
msgid "On shared hosting, set the file to 640 or 440."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:73
msgid "wp-config.php is readable by every account on the server."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:67
msgid "Set the file to 640 or 440 and make sure it is owned by the site account."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:64
msgid "wp-config.php is writable by everyone on the server. It holds the database credentials and the authentication keys."
msgstr ""

#. translators: 1: file path, 2: octal permissions.
#. translators: 1: directory path, 2: octal permissions.
#. translators: 1: directory name, 2: octal permissions.
#: includes/checks/class-cascr-checks-files.php:57
#: includes/checks/class-cascr-checks-files.php:103
#: includes/checks/class-cascr-checks-files.php:146
msgid "%1$s has permissions %2$s"
msgstr ""

#: includes/checks/class-cascr-checks-files.php:52
msgid "The permissions of wp-config.php could not be read."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:46
msgid "wp-config.php could not be located."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:1039
msgid "Keep every installation updated. A neglected one next door is an entry point into this one."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:1023
msgid "No other WordPress installation was found next to this one."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:1018
msgid "The scan for other installations could not be completed."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:988
msgid "The parent directory could not be read."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:968
msgid "Open each file. This code runs on every request and cannot be switched off from the dashboard."
msgstr ""

#. translators: %d: number of newly appeared must-use plugins or drop-ins.
#: includes/checks/class-cascr-checks-core.php:958
msgid "%d must-use plugin or drop-in appeared since the first scan."
msgid_plural "%d must-use plugins or drop-ins appeared since the first scan."
msgstr[0] ""
msgstr[1] ""

#. translators: %d: number of must-use plugins and drop-ins.
#: includes/checks/class-cascr-checks-core.php:938
msgid "%d known must-use plugin or drop-in is installed."
msgid_plural "%d known must-use plugins or drop-ins are installed."
msgstr[0] ""
msgstr[1] ""

#. translators: %d: number of must-use plugins and drop-ins.
#: includes/checks/class-cascr-checks-core.php:915
msgid "%d must-use plugin or drop-in is installed and has been recorded."
msgid_plural "%d must-use plugins or drop-ins are installed and have been recorded."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:909
#: includes/checks/class-cascr-checks-core.php:932
msgid "No must-use plugins or drop-ins are installed."
msgstr ""

#. translators: 1: file name, 2: plugin name.
#: includes/checks/class-cascr-checks-core.php:898
msgid "drop-in %1$s (%2$s)"
msgstr ""

#. translators: 1: file name, 2: plugin name.
#: includes/checks/class-cascr-checks-core.php:889
msgid "must-use plugin %1$s (%2$s)"
msgstr ""

#: includes/checks/class-cascr-checks-core.php:869
msgid "Confirm the handover is legitimate and read the changelog of the release that came with it."
msgstr ""

#. translators: %d: number of plugins whose author changed.
#: includes/checks/class-cascr-checks-core.php:859
msgid "%d plugin changed its author."
msgid_plural "%d plugins changed their author."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:853
msgid "No installed plugin changed its author."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:847
#: includes/checks/class-cascr-checks-core.php:848
msgid "(none)"
msgstr ""

#. translators: 1: plugin file, 2: previous author, 3: current author.
#: includes/checks/class-cascr-checks-core.php:845
msgid "%1$s: %2$s became %3$s"
msgstr ""

#: includes/checks/class-cascr-checks-core.php:831
msgid "The plugin authors have been recorded. Changes will be reported from the next scan on."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:808
msgid "Remove the plugin and replace it. A closed listing usually means an unfixed security problem."
msgstr ""

#. translators: %d: number of plugins that were removed from the directory.
#: includes/checks/class-cascr-checks-core.php:798
msgid "%d active plugin has been removed from the WordPress directory."
msgid_plural "%d active plugins have been removed from the WordPress directory."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:792
msgid "No active plugin has been removed from the directory."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:722
msgid "Look for a maintained alternative. Abandoned plugins do not get security fixes."
msgstr ""

#. translators: %d: number of plugins that look abandoned.
#: includes/checks/class-cascr-checks-core.php:712
msgid "%d active plugin looks abandoned."
msgid_plural "%d active plugins look abandoned."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:706
msgid "Every active plugin from the directory is actively maintained."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:701
#: includes/checks/class-cascr-checks-core.php:787
msgid "No plugin information could be retrieved from the directory."
msgstr ""

#. translators: 1: plugin name, 2: comma separated list of reasons.
#: includes/checks/class-cascr-checks-core.php:692
msgid "%1$s: %2$s"
msgstr ""

#. translators: %s: WordPress version the plugin was last tested against.
#: includes/checks/class-cascr-checks-core.php:684
msgid "last tested against WordPress %s"
msgstr ""

#: includes/checks/class-cascr-checks-core.php:674
msgid "no release in over a year"
msgstr ""

#: includes/checks/class-cascr-checks-core.php:672
msgid "no release in over two years"
msgstr ""

#: includes/checks/class-cascr-checks-core.php:636
msgid "Delete what is not needed. Deactivated code still sits on disk and stops receiving attention."
msgstr ""

#. translators: %d: number of inactive plugins and unused themes.
#: includes/checks/class-cascr-checks-core.php:626
msgid "%d inactive plugin or unused theme is installed."
msgid_plural "%d inactive plugins or unused themes are installed."
msgstr[0] ""
msgstr[1] ""

#. translators: %s: theme name.
#: includes/checks/class-cascr-checks-core.php:620
msgid "unused theme: %s"
msgstr ""

#. translators: %s: plugin name.
#: includes/checks/class-cascr-checks-core.php:616
msgid "inactive plugin: %s"
msgstr ""

#: includes/checks/class-cascr-checks-core.php:610
msgid "No inactive plugins or unused themes are installed."
msgstr ""

#. translators: %d: number of themes with a pending update.
#: includes/checks/class-cascr-checks-core.php:569
msgid "%d theme has an update waiting."
msgid_plural "%d themes have updates waiting."
msgstr[0] ""
msgstr[1] ""

#. translators: 1: theme name, 2: available version.
#: includes/checks/class-cascr-checks-core.php:556
msgid "%1$s (update to %2$s)"
msgstr ""

#: includes/checks/class-cascr-checks-core.php:544
msgid "Theme update information is not available."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:525
#: includes/checks/class-cascr-checks-core.php:579
msgid "Install the updates from Dashboard, Updates."
msgstr ""

#. translators: %d: number of active plugins with a pending update.
#: includes/checks/class-cascr-checks-core.php:515
msgid "%d active plugin has an update waiting."
msgid_plural "%d active plugins have updates waiting."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:509
msgid "All active plugins are up to date."
msgstr ""

#. translators: 1: plugin name, 2: installed version, 3: available version.
#: includes/checks/class-cascr-checks-core.php:501
msgid "%1$s (%2$s to %3$s)"
msgstr ""

#: includes/checks/class-cascr-checks-core.php:484
msgid "Plugin update information is not available."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:468
msgid "Inspect each file. Nothing but WordPress itself belongs in wp-admin or wp-includes."
msgstr ""

#. translators: %d: number of unexpected executable files.
#: includes/checks/class-cascr-checks-core.php:458
msgid "%d executable file in the core directories is not part of WordPress."
msgid_plural "%d executable files in the core directories are not part of WordPress."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:451
msgid "The core directories contain no files beyond the official release."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:431
msgid "The core directories could not be read completely."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:381
msgid "No official file list is available for this WordPress version."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:360
msgid "Reinstall WordPress from Dashboard, Updates, Reinstall. If files keep changing, treat the site as compromised."
msgstr ""

#. translators: %d: number of core files that differ from the official release.
#: includes/checks/class-cascr-checks-core.php:350
msgid "%d core file differs from the official release."
msgid_plural "%d core files differ from the official release."
msgstr[0] ""
msgstr[1] ""

#. translators: %s: file path relative to the WordPress root.
#: includes/checks/class-cascr-checks-core.php:341
msgid "missing: %s"
msgstr ""

#. translators: %s: file path relative to the WordPress root.
#: includes/checks/class-cascr-checks-core.php:337
msgid "modified: %s"
msgstr ""

#. translators: %d: number of files verified.
#: includes/checks/class-cascr-checks-core.php:323
msgid "The %d core file matches the official checksums."
msgid_plural "All %d core files match the official checksums."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-core.php:290
msgid "Checksums are only published for release builds. Nightly or patched builds cannot be verified."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:289
msgid "No official checksums are available for this WordPress version."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:248
msgid "Remove the WP_AUTO_UPDATE_CORE constant from wp-config.php or set it to minor."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:245
msgid "Automatic core updates are switched off, so security releases are not installed on their own."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:257
msgid "Set WP_AUTO_UPDATE_CORE to minor on production sites."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:254
msgid "This installation receives pre-release core updates."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:276
msgid "Automatic minor and security updates are enabled."
msgstr ""

#. translators: %s: PHP version number.
#: includes/checks/class-cascr-checks-core.php:187
msgid "PHP %s is fully supported."
msgstr ""

#. translators: 1: PHP version number, 2: end of support date.
#: includes/checks/class-cascr-checks-core.php:176
msgid "PHP %1$s only receives security fixes, no more bug fixes. Support ends on %2$s."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:168
msgid "Plan the upgrade to a newer PHP branch before that date."
msgstr ""

#. translators: 1: PHP version number, 2: end of support date.
#: includes/checks/class-cascr-checks-core.php:162
msgid "PHP %1$s reaches end of security support on %2$s."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:154
msgid "Ask your host to move the site to a supported PHP branch. Test on a staging copy first."
msgstr ""

#. translators: 1: PHP version number, 2: end of support date.
#: includes/checks/class-cascr-checks-core.php:148
msgid "PHP %1$s stopped receiving security fixes on %2$s."
msgstr ""

#. translators: %s: PHP version number.
#: includes/checks/class-cascr-checks-core.php:136
msgid "PHP %s is in use."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:116
msgid "Install the update from Dashboard, Updates. Take a backup first."
msgstr ""

#. translators: 1: installed WordPress version, 2: latest available version.
#: includes/checks/class-cascr-checks-core.php:110
msgid "WordPress %1$s is outdated, %2$s is available."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:85
msgid "Check that the site can reach api.wordpress.org."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:84
msgid "The latest WordPress version could not be determined."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:696
msgid "A password policy is enforced."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:670
msgid "Repeated login attempts are being limited."
msgstr ""

#. translators: %d: number of active security plugins.
#: includes/checks/class-cascr-checks-config.php:646
msgid "%d security plugin is active."
msgid_plural "%d security plugins are active."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-config.php:640
msgid "No security plugin from the known list is active."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:627
msgid "A backup taken by the host also counts. This check can only see plugins."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:624
msgid "No backup plugin was detected. Recovery from a compromise depends on having one."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:618
msgid "A backup plugin is active."
msgstr ""

#. translators: 1: option name, 2: external host name.
#: includes/checks/class-cascr-checks-config.php:556
msgid "option %1$s loads a script from %2$s"
msgstr ""

#. translators: 1: option name, 2: the suspicious code fragment.
#: includes/checks/class-cascr-checks-config.php:543
msgid "option %1$s contains %2$s"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:506
msgid "Look at what the largest entries contain before deleting anything."
msgstr ""

#. translators: %s: human readable size.
#: includes/checks/class-cascr-checks-config.php:501
msgid "%s of options is loaded on every request. Bloated autoloaded options are often forgotten logs or planted payloads."
msgstr ""

#. translators: %s: human readable size.
#: includes/checks/class-cascr-checks-config.php:492
msgid "%s of options is loaded on every request."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:463
msgid "The autoloaded options could not be read."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:442
msgid "DISABLE_WP_CRON is set but nothing is triggering wp-cron.php. Set up a server cron job, or remove the constant."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:437
msgid "WP-Cron runs on page loads and nothing is overdue."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:436
msgid "WP-Cron is handled by a server cron job and nothing is overdue."
msgstr ""

#. translators: 1: number of overdue events, 2: human readable time difference.
#: includes/checks/class-cascr-checks-config.php:387
msgid "%1$d scheduled event is overdue by %2$s."
msgid_plural "%1$d scheduled events are overdue, the oldest by %2$s."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-config.php:336
msgid "Create a dedicated account with rights on this database only and update wp-config.php."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:333
msgid "The database account has more rights than WordPress needs, so an injection reaches further than this site."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:329
msgid "The database account is limited to what WordPress needs."
msgstr ""

#. translators: %s: name of a MySQL privilege.
#: includes/checks/class-cascr-checks-config.php:319
msgid "holds the %s privilege"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:308
msgid "all privileges on every database"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:293
msgid "The database account is not allowed to inspect its own privileges."
msgstr ""

#. translators: %s: database table prefix.
#: includes/checks/class-cascr-checks-config.php:272
msgid "A custom table prefix (%s) is in use."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:265
msgid "Changing the prefix on a live site is risky. Do it during a migration, not as a standalone step."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:262
msgid "The database uses the default table prefix, which makes blind injection attempts easier."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:245
msgid "All eight authentication keys are set, long enough and distinct."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:219
msgid "Generate a fresh set at api.wordpress.org/secret-key/1.1/salt/ and replace the block in wp-config.php. Everyone gets logged out once."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:216
msgid "The authentication keys are not set up correctly, which weakens every login cookie and nonce."
msgstr ""

#. translators: %s: name of the wp-config.php constant.
#: includes/checks/class-cascr-checks-config.php:205
msgid "%s repeats the value of another key"
msgstr ""

#. translators: %s: name of the wp-config.php constant.
#: includes/checks/class-cascr-checks-config.php:196
msgid "%s is a placeholder or too short"
msgstr ""

#. translators: %s: name of the wp-config.php constant.
#: includes/checks/class-cascr-checks-config.php:185
msgid "%s is not defined"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:157
msgid "On sites where code is deployed rather than installed, add define( 'DISALLOW_FILE_MODS', true ); to wp-config.php. Note that this also stops automatic updates."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:154
msgid "Plugins and themes can be installed from the dashboard. That is the shortest path from a stolen login to running code."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:150
msgid "Installing plugins and themes from the dashboard is disabled."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:139
msgid "Add define( 'DISALLOW_FILE_EDIT', true ); to wp-config.php."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:136
msgid "The theme and plugin editor is available, so anyone who reaches an administrator account can run code."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:121
#: includes/checks/class-cascr-checks-config.php:130
msgid "The theme and plugin editor is disabled."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:110
msgid "Delete the file once the problem is solved."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:107
msgid "A debug log exists but is not publicly readable."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:102
msgid "Delete the file and block access to it in the server configuration."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:99
msgid "The debug log is readable from the web and exposes error details, file paths and sometimes credentials."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:93
msgid "A debug log exists, but it could not be checked whether it is publicly readable."
msgstr ""

#. translators: 1: file path, 2: human readable file size.
#. translators: 1: option name, 2: human readable size.
#: includes/checks/class-cascr-checks-config.php:75
#: includes/checks/class-cascr-checks-config.php:482
#: includes/checks/class-cascr-checks-files.php:793
msgid "%1$s (%2$s)"
msgstr ""

#: includes/checks/class-cascr-checks-config.php:69
msgid "No debug log exists."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:52
msgid "Set WP_DEBUG to false in wp-config.php on production sites."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:49
msgid "Debug mode is on."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:46
msgid "Set WP_DEBUG to false in wp-config.php, or at least WP_DEBUG_DISPLAY."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:43
msgid "Debug mode is on and errors are printed into the page."
msgstr ""

#: includes/checks/class-cascr-checks-config.php:24
msgid "Debug mode is switched off."
msgstr ""

#. translators: %s: name of the default role for new accounts.
#: includes/checks/class-cascr-checks-accounts.php:807
msgid "Network registration is open. New accounts receive the role %s on this site."
msgstr ""

#. translators: %s: name of the default role for new accounts.
#: includes/checks/class-cascr-checks-accounts.php:795
msgid "Network registration is open and new accounts receive the role %s on this site, which carries administrator-level capabilities."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:780
msgid "anyone can create an account and a new site"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:779
msgid "existing accounts can create new sites"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:778
msgid "anyone can create an account"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:774
msgid "Network registration is closed."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:761
msgid "Revoke what is no longer needed. These credentials skip the second factor."
msgstr ""

#. translators: %d: number of forgotten application passwords.
#: includes/checks/class-cascr-checks-accounts.php:751
msgid "%d application password has not been used in months."
msgid_plural "%d application passwords have not been used in months."
msgstr[0] ""
msgstr[1] ""

#. translators: %d: number of application passwords in use.
#: includes/checks/class-cascr-checks-accounts.php:736
msgid "%d application password is in use and was used recently."
msgid_plural "%d application passwords are in use and were used recently."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-accounts.php:729
msgid "No application passwords are in use by privileged accounts."
msgstr ""

#. translators: 1: human readable time since last use, 2: IP address.
#: includes/checks/class-cascr-checks-accounts.php:711
msgid "last used %1$s ago from %2$s"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:707
msgid "unknown"
msgstr ""

#. translators: 1: user login, 2: application password name, 3: creation date,
#. 4: last use.
#: includes/checks/class-cascr-checks-accounts.php:704
msgid "%1$s, \"%2$s\", created %3$s, %4$s"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:700
#: includes/checks/class-cascr-checks-accounts.php:715
msgid "never used"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:697
#: includes/checks/class-cascr-checks-core.php:891
#: includes/checks/class-cascr-checks-core.php:900
msgid "no name"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:670
msgid "This WordPress version has no application passwords."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:640
msgid "Set up the second factor for those accounts, or require it for the administrator role."
msgstr ""

#. translators: %d: number of administrators without a second factor.
#: includes/checks/class-cascr-checks-accounts.php:630
msgid "%d administrator has no second factor."
msgid_plural "%d administrators have no second factor."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-accounts.php:611
msgid "Every administrator has a second factor."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:587
msgid "Check the coverage in the plugin itself."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:586
msgid "A two-factor plugin is active, but which accounts use it cannot be read from here."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:573
msgid "No second factor is available, so a stolen password is enough to reach the dashboard."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:550
msgid "If the site does not need public accounts, switch registration off under Settings, General."
msgstr ""

#. translators: %s: name of the default role for new accounts.
#: includes/checks/class-cascr-checks-accounts.php:545
msgid "Registration is open. New accounts receive the role %s."
msgstr ""

#. translators: %s: name of the default role for new accounts.
#: includes/checks/class-cascr-checks-accounts.php:533
msgid "Anyone can register and immediately receives the role %s, which may publish."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:525
#: includes/checks/class-cascr-checks-accounts.php:538
msgid "Set the default role to Subscriber under Settings, General."
msgstr ""

#. translators: %s: name of the default role for new accounts.
#: includes/checks/class-cascr-checks-accounts.php:520
msgid "Anyone can register and immediately receives the role %s, which carries administrator-level capabilities."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:506
msgid "Registration is closed."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:476
msgid "Some plugins add these on purpose. Anything you cannot account for should be removed."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:473
msgid "Roles below administrator hold capabilities that amount to full control."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:489
msgid "No role below administrator holds administrator-level capabilities."
msgstr ""

#. translators: %s: role slug.
#: includes/checks/class-cascr-checks-accounts.php:460
msgid "the capabilities of the role %s changed after the first scan"
msgstr ""

#. translators: %s: role slug.
#: includes/checks/class-cascr-checks-accounts.php:454
msgid "the role %s was added after the first scan"
msgstr ""

#. translators: %s: role name.
#: includes/checks/class-cascr-checks-accounts.php:441
msgid "the role %s may post unfiltered HTML"
msgstr ""

#. translators: 1: role name, 2: comma separated capability names.
#: includes/checks/class-cascr-checks-accounts.php:432
msgid "the role %1$s holds %2$s"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:411
msgid "The role definitions could not be read."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:398
msgid "Give people the lowest role that lets them do their work, and remove accounts that are no longer used."
msgstr ""

#. translators: %d: number of administrator accounts.
#: includes/checks/class-cascr-checks-accounts.php:317
#: includes/checks/class-cascr-checks-accounts.php:380
msgid "%d account holds administrator rights."
msgid_plural "%d accounts hold administrator rights."
msgstr[0] ""
msgstr[1] ""

#. translators: 1: user login, 2: human readable time since the last login.
#: includes/checks/class-cascr-checks-accounts.php:353
msgid "%1$s last signed in %2$s ago"
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:342
msgid "the account with ID 1 is an administrator, which is the first ID anyone tries"
msgstr ""

#. translators: %d: number of administrator accounts.
#: includes/checks/class-cascr-checks-accounts.php:328
msgid "%d account holds administrator rights"
msgid_plural "%d accounts hold administrator rights"
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-accounts.php:297
msgid "Create a new administrator with a different name, move the content over and delete the old account."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:294
msgid "An administrator account uses a name that every password guesser tries first."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:290
msgid "No administrator uses a predictable login name."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:269
msgid "Reset those passwords now and check the account activity afterwards."
msgstr ""

#. translators: %d: number of accounts with a guessable password.
#: includes/checks/class-cascr-checks-accounts.php:259
msgid "%d privileged account uses a guessable password."
msgid_plural "%d privileged accounts use guessable passwords."
msgstr[0] ""
msgstr[1] ""

#. translators: %d: number of accounts checked.
#: includes/checks/class-cascr-checks-accounts.php:243
msgid "The %d privileged account does not use a password from the common list."
msgid_plural "None of the %d privileged accounts uses a password from the common list."
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-accounts.php:215
msgid "No privileged accounts were found."
msgstr ""

#: includes/checks/class-cascr-checks-accounts.php:209
msgid "The password list could not be loaded."
msgstr ""

#: config/docs.php:337
msgid "Remove the corresponding hooks from wp_head. This is fingerprinting rather than a vulnerability, so it is weighted lightly."
msgstr ""

#: config/docs.php:336
msgid "The generator tag publishes the exact WordPress version. The other two point at interfaces from an era when blogging clients were a thing."
msgstr ""

#: config/docs.php:335
msgid "Discovery tags in the front page markup: the generator tag, the Windows Live Writer manifest and the Really Simple Discovery link."
msgstr ""

#: config/docs.php:332 includes/checks/class-cascr-checks-network.php:674
msgid "Set expose_php to Off in php.ini and trim the server token in the web server configuration."
msgstr ""

#: config/docs.php:331
msgid "This is not a hole, it is a shortcut. It tells an attacker which known flaws are worth trying before they try anything."
msgstr ""

#: config/docs.php:330
msgid "Whether the response headers name the exact PHP or server version."
msgstr ""

#: config/docs.php:327
msgid "Name the origins that are actually allowed. Never combine the wildcard with Access-Control-Allow-Credentials."
msgstr ""

#: config/docs.php:326
msgid "A wildcard origin combined with credentials lets any website read logged-in responses from this one. It is a rare misconfiguration and a severe one."
msgstr ""

#: config/docs.php:312
msgid "Use max-age=31536000 with includeSubDomains once the whole site is reliably on HTTPS, which is one year. Add preload only when you are certain, since it is hard to undo."
msgstr ""

#: config/docs.php:311
msgid "A max-age of a few minutes passes an existence check and protects nobody. The header only does its job when a browser remembers it for months."
msgstr ""

#: config/docs.php:306
msgid "These headers are what limits the damage of a flaw elsewhere. They are cheap to add and nothing else on this page substitutes for them."
msgstr ""

#: config/docs.php:297
msgid "Set the site and home addresses to https, add define( 'FORCE_SSL_ADMIN', true ); to wp-config.php and redirect http with a 301."
msgstr ""

#: config/docs.php:296
msgid "A site that merely answers on https while still advertising http lets a login travel in the clear whenever someone types the address without the s."
msgstr ""

#: config/docs.php:295
msgid "Whether the site address uses https, whether the dashboard is forced onto it, and whether the http address redirects permanently."
msgstr ""

#: config/docs.php:282
msgid "Whether a second factor is available at all, and which administrators actually have one set up."
msgstr ""

#: config/docs.php:278
msgid "Open registration is fine. Open registration handing out a role that can publish or install is an open door, and it is a setting that gets changed once and forgotten."
msgstr ""

#: config/docs.php:269
msgid "Give people the lowest role that lets them work, and remove accounts nobody uses. Sign-in times are only known from the moment this plugin was installed, since WordPress keeps no login history of its own."
msgstr ""

#: config/docs.php:268
msgid "Every administrator account is a separate way in. Dormant ones are the most dangerous, because nobody would notice them being used."
msgstr ""

#: config/docs.php:267
msgid "How many accounts hold administrator rights, whether the account with ID 1 is one of them, and which administrators have not signed in for a long time."
msgstr ""

#: config/docs.php:264
msgid "Create a new administrator with a different name, reassign the content, then delete the old account. Renaming in place is not possible from the dashboard."
msgstr ""

#: config/docs.php:263
msgid "Guessing a password needs the name too. A predictable name removes half the problem for the attacker."
msgstr ""

#: config/docs.php:258
msgid "Password guessing is still how most WordPress sites are taken over. One weak administrator password makes every other measure on this page irrelevant."
msgstr ""

#: config/docs.php:257
msgid "Whether any account that can publish or administer uses a password from the common list, or a variation of its own login name. The stored hash is compared, no login is attempted."
msgstr ""

#: config/docs.php:250
msgid "On Apache this file carries the rewrite rules and most hardening directives. Its absence means none of them are in place."
msgstr ""

#: config/docs.php:246 includes/checks/class-cascr-checks-files.php:969
msgid "Switch off autoindex in the server configuration, or add Options -Indexes to .htaccess."
msgstr ""

#: config/docs.php:245
msgid "A listing names every installed plugin and its folder structure, which is a ready-made list of things to look up vulnerabilities for."
msgstr ""

#: config/docs.php:241
msgid "Delete the contents of both folders. WordPress recreates them when it needs them."
msgstr ""

#: config/docs.php:240
msgid "An interrupted update leaves an unpacked copy of a plugin behind, sometimes the old vulnerable version, and it stays reachable by direct request."
msgstr ""

#: config/docs.php:239
msgid "Contents of wp-content/upgrade and upgrade-temp-backup that are more than a day old."
msgstr ""

#: config/docs.php:234
msgid "Files in the web root that give away version and tooling details."
msgstr ""

#: config/docs.php:230
msgid "A downloadable dump is every password hash, every email address and every private post in one file. It is usually left behind after a migration."
msgstr ""

#: config/docs.php:229
msgid "Database dumps and archives in the web root or in wp-content, and whether they can be downloaded."
msgstr ""

#: config/docs.php:226
msgid "Block the directory at the web server, and preferably deploy without the repository metadata in the first place."
msgstr ""

#: config/docs.php:225
msgid "A readable .git directory is the entire source history, including files that were committed once and deleted later. Credentials are found this way regularly."
msgstr ""

#: config/docs.php:220
msgid "A file named wp-config.php.bak is not parsed as PHP, so the server hands out its contents as text, credentials and all. Whether that happens depends on the server, which is why both questions get asked."
msgstr ""

#: config/docs.php:219
msgid "Editor leftovers and backup copies around wp-config.php, plus .env and similar files. Existence is checked first, then whether the web server actually serves them."
msgstr ""

#: config/docs.php:214
msgid "Whether the server actually runs a PHP file placed in the uploads directory. A file is written, requested once and deleted again."
msgstr ""

#: config/docs.php:210
msgid "Media never needs to be executable. A script in this directory is either a leftover or a shell that someone uploaded through a flaw elsewhere."
msgstr ""

#: config/docs.php:205
msgid "Nothing in a WordPress installation needs to be writable by everyone. Where it happens it is nearly always a botched chmod during troubleshooting that was never undone."
msgstr ""

#: includes/checks/class-cascr-checks-files.php:158
msgid "Set the directories to 755 or 750."
msgstr ""

#: config/docs.php:199
msgid "Whether wp-content, wp-includes or wp-admin are writable by everyone on the server."
msgstr ""

#: config/docs.php:195
msgid "The directory has to be writable by PHP. It does not have to be writable by every other account on the machine, and on shared hosting those are not the same thing."
msgstr ""

#: config/docs.php:194
msgid "Whether the uploads directory is writable by everyone on the server."
msgstr ""

#: config/docs.php:177
msgid "Without a limit, passwords can be guessed at whatever rate the server will answer. Combined with readable user names, that is the most common way in."
msgstr ""

#: config/docs.php:176
msgid "Whether anything limits repeated login attempts."
msgstr ""

#: config/docs.php:173
msgid "Nothing to do. If several are active, check that they are not fighting over the same rules."
msgstr ""

#: config/docs.php:172
msgid "Having a security plugin installed says nothing about whether it is configured. It is listed here for context, not as a score."
msgstr ""

#: config/docs.php:171
msgid "Which general security plugins are active. This one is informational and does not affect the grade."
msgstr ""

#: config/docs.php:167
msgid "Every other check on this page is about avoiding a bad day. A backup is what turns a bad day into an afternoon."
msgstr ""

#: config/docs.php:157
msgid "This is usually a performance topic, but a bloated autoload set is also where forgotten logs and planted payloads accumulate, because nobody ever looks at it."
msgstr ""

#: config/docs.php:152
msgid "Update checks, backups and scans all live in the scheduler. A stalled scheduler is silent: everything looks fine and nothing happens. Schedules with no code behind them are usually leftovers from a removed plugin, occasionally something that was planted."
msgstr ""

#: config/docs.php:151
msgid "Whether scheduled events actually run, and whether anything is scheduled that no code listens to."
msgstr ""

#: config/docs.php:142
msgid "A predictable prefix makes blind injection attempts easier, because the attacker does not have to discover the table names first. It is a small hurdle, not a wall."
msgstr ""

#: config/docs.php:133
msgid "On sites where code is deployed rather than clicked in, add define( 'DISALLOW_FILE_MODS', true ); to wp-config.php. Be aware that it also stops automatic updates and closes the editor, so the deployment has to cover the updates."
msgstr ""

#: config/docs.php:132
msgid "Blocking the editor still leaves the installer. Uploading a zip is the other way from a stolen login to running code."
msgstr ""

#: config/docs.php:131
msgid "Whether plugins and themes can be installed from the dashboard."
msgstr ""

#: config/docs.php:126
msgid "Whether the built-in theme and plugin editor is available."
msgstr ""

#: config/docs.php:122
msgid "The log accumulates file paths, query fragments and occasionally credentials. A publicly readable one is a slow leak that nobody watches."
msgstr ""

#: config/docs.php:109
msgid "On most shared hosting, one compromised site can write into its neighbours. A forgotten test installation next door is a way into this one."
msgstr ""

#: config/docs.php:104
msgid "Both load on every single request and neither can be switched off from the dashboard. That combination makes them a favourite hiding place for code that is meant to stay."
msgstr ""

#: config/docs.php:100
msgid "Confirm the handover is genuine and read the changelog of the release that came with it. Most changes are legitimate."
msgstr ""

#: config/docs.php:99
msgid "Buying an established plugin and shipping a malicious update to its existing users has become a common route in. The author line is the earliest thing a site can notice on its own."
msgstr ""

#: config/docs.php:95
msgid "Remove the plugin and replace it. Updates will never arrive for it again."
msgstr ""

#: config/docs.php:94
msgid "A listing is usually closed because of an unfixed security problem. That makes it more serious than a plugin with a known, patched vulnerability, not less."
msgstr ""

#: config/docs.php:90
msgid "Look for a maintained alternative before it becomes urgent. File dates on disk say nothing about this, which is why the directory is asked instead."
msgstr ""

#: config/docs.php:89
msgid "An abandoned plugin has no one left to publish a fix. The code keeps working right up until the day someone finds a hole in it."
msgstr ""

#: config/docs.php:85
msgid "Delete what the site does not use. Keeping one spare default theme for troubleshooting is reasonable."
msgstr ""

#: config/docs.php:84
msgid "Deactivated code still sits on disk and is still reachable by direct request in some setups. It also stops being updated the moment people forget about it."
msgstr ""

#: config/docs.php:83
msgid "Plugins that are installed but not active, and themes that are neither the active theme nor its parent."
msgstr ""

#: config/docs.php:74
msgid "Nine out of ten new vulnerabilities in the WordPress ecosystem are in plugins, and the fix is usually a version bump that was published weeks ago."
msgstr ""

#: config/docs.php:73
msgid "Whether any active plugin has an update waiting, using the update information WordPress already holds."
msgstr ""

#: config/docs.php:69
msgid "Nothing but WordPress itself belongs in those two directories. A file that is not on the official list was put there by something else."
msgstr ""

#: config/docs.php:68
msgid "Executable files inside wp-admin and wp-includes that are not part of the official release."
msgstr ""

#: config/docs.php:64
msgid "A modified core file is either a botched update or someone else editing the site. Both are worth knowing about, and the second one is urgent."
msgstr ""

#: config/docs.php:59
msgid "The window between a security release and the first attempts against it is measured in hours. Nobody updates that fast by hand."
msgstr ""

#: config/docs.php:54
msgid "Once a branch is retired, flaws found in it are never fixed. The site keeps working, which is exactly why this goes unnoticed for years."
msgstr ""

#: config/docs.php:49
msgid "Security releases are published together with a description of what they fix, which tells everyone exactly what to try against sites that have not updated yet."
msgstr ""

#: config/docs.php:17 includes/class-cascr-admin.php:115
#: includes/class-cascr-admin.php:476
msgid "What to do"
msgstr ""

#: config/docs.php:16
msgid "Why it matters"
msgstr ""

#: config/docs.php:15
msgid "What it checks"
msgstr ""

#. Description of the plugin
#: security-check-report.php
msgid "Runs a series of read-only security checks against your WordPress installation and turns the findings into a graded report with a short list of what to fix first."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:264
msgid "All automatic core updates are enabled."
msgstr ""

#. translators: %d: number of further findings that are not listed.
#. translators: %d: number of additional items not listed.
#: includes/checks/class-cascr-checks-base.php:216
#: includes/class-cascr-result.php:214
msgid "and %d more"
msgid_plural "and %d more"
msgstr[0] ""
msgstr[1] ""

#: includes/checks/class-cascr-checks-files.php:999
msgid "An .htaccess file is present."
msgstr ""

#: includes/checks/class-cascr-checks-core.php:563
msgid "All themes are up to date."
msgstr ""

#. translators: %s: WordPress version number.
#: includes/checks/class-cascr-checks-core.php:101
msgid "WordPress %s is up to date."
msgstr ""

#: includes/class-cascr-registry.php:274
msgid "Automatic core updates"
msgstr ""

#: includes/class-cascr-registry.php:475
msgid "PHP execution in uploads"
msgstr ""

#: includes/class-cascr-registry.php:445
msgid "wp-config.php permissions"
msgstr ""

#: includes/class-cascr-admin.php:202
msgid "Support"
msgstr ""

#: includes/class-cascr-admin.php:198
msgid "Documentation"
msgstr ""

#: includes/class-cascr-admin.php:129
msgid "Status"
msgstr ""

#: includes/class-cascr-admin.php:130
msgid "Score"
msgstr ""

#: includes/class-cascr-admin.php:131
msgid "Result"
msgstr ""

#: includes/class-cascr-admin.php:27 includes/class-cascr-admin.php:118
#: includes/class-cascr-admin.php:151
msgid "Security Check Report"
msgstr ""

#: includes/class-cascr-registry.php:280
msgid "Core file integrity"
msgstr ""

#: includes/class-cascr-registry.php:621
msgid "CORS configuration"
msgstr ""

#: includes/class-cascr-registry.php:356
msgid "Debug log exposure"
msgstr ""

#: includes/class-cascr-registry.php:569
msgid "Application passwords"
msgstr ""

#: includes/class-cascr-registry.php:645
msgid "User enumeration"
msgstr ""

#: includes/class-cascr-registry.php:386
msgid "Database user privileges"
msgstr ""

#: includes/class-cascr-registry.php:374
msgid "Security keys and salts"
msgstr ""

#: includes/class-cascr-registry.php:334
msgid "Other WordPress installations"
msgstr ""

#: includes/class-cascr-registry.php:639
msgid "XML-RPC interface"
msgstr ""

#: includes/class-cascr-registry.php:451
msgid "Uploads directory permissions"
msgstr ""

#: includes/class-cascr-registry.php:262
msgid "WordPress version"
msgstr ""

#. Author URI of the plugin
#: security-check-report.php
msgid "https://www.cms-admins.de/"
msgstr ""

#. Author of the plugin
#: security-check-report.php
msgid "Patrick Schlesinger"
msgstr ""

#. Plugin URI of the plugin
#: security-check-report.php
msgid "https://wordpress.org/plugins/security-check-report"
msgstr ""

#. Plugin Name of the plugin
#: security-check-report.php
msgid "CMS ADMINS Security Check Report"
msgstr ""