Plain English
Compact messages can hide risk, so every public demo keeps warnings visible.
Technical summary
The WordPress surface sanitizes input, escapes output, rejects public mutation, validates nonces on admin package actions, and refuses vectors, embeddings, private corpora, hidden codebooks, SQL Server fields, and LM Studio fields in public projections.
Deep spec
Security notes support review; they are not a guarantee of prevention, certification, or third-party endorsement.
Default blocks
- No execution of pasted HTML.
- No public registry mutation endpoints.
- No live SQL Server vectors, LM Studio calls, private embeddings, or private semantic corpora.
- No hidden bilingual tables or unexplained codebooks as semantic authority.