Title: Kistn API Client
Author: Christian Doebler
Published: <strong>1 juli 2026</strong>
Last modified: 12 juli 2026

---

Sök tillägg

![](https://s.w.org/plugins/geopattern-icon/kistn.svg)

# Kistn API Client

 Av [Christian Doebler](https://profiles.wordpress.org/grissi/)

[Ladda ner](https://downloads.wordpress.org/plugin/kistn.1.0.2.zip)

 * [Detaljer](https://sv.wordpress.org/plugins/kistn/#description)
 * [Recensioner](https://sv.wordpress.org/plugins/kistn/#reviews)
 *  [Installation](https://sv.wordpress.org/plugins/kistn/#installation)
 * [Utveckling](https://sv.wordpress.org/plugins/kistn/#developers)

 [Support](https://wordpress.org/support/plugin/kistn/)

## Beskrivning

Collects installed plugins, themes, and WordPress core, then pushes inventory to
your Kistn server for centralized vulnerability monitoring.

**Push flow:**

 1. Preflight — asks the server which slugs need a fresh advisory check and which are
    known-private.
 2. Hash check — skips push if inventory unchanged.
 3. WPScan lookup — queries the WPScan vulnerability database only for stale, non-private
    slugs.
 4. Push — sends packages, vulnerability findings, advisory snapshots, and any newly-
    discovered private slugs.

Private packages (those absent from the WPScan database) are tracked server-side
so subsequent runs never waste WPScan quota on them. When the server later confirms
a package is public, the project owner is notified.

**Configuration** via Settings  Kistn, or via constants in wp-config.php:

define( ’KISTN_BASE_URL’, ’https://your-server.example.com’ );
 define( ’KISTN_PROJECT_ID’,’
your-project-uuid’ ); define( ’KISTN_TOKEN’, ’your-api-token’ ); define( ’KISTN_WPSCAN_TOKEN’,’
your-wpscan-api-token’ ); // optional, enables vulnerability lookups

### External services

This plugin can connect to WPScan API to obtain latest security information about
your installation. Use of this feature is optional. To use this feature, you need
a WPScan account and your own API token.

When the feature is used, this plugin sends information about installed WordPress
core, plugins and themes to retrieve latest security advisories about your installed
components. The service is provided by ”WPScan”: https://wpscan.com/terms/, https://
automattic.com/privacy/.

## Installation

 1. In your WordPress admin, go to Plugins  Add New, search for ”Kistn API Client”,
    install and activate.
 2. Alternatively, upload the plugin ZIP via Plugins  Add New  Upload Plugin, then 
    activate.
 3. Alternatively, via Composer: `composer require kistn/wp-client`, then activate 
    as usual.
 4. Go to Settings  Kistn and configure your API credentials.

## Recensioner

Detta tillägg har inga recensioner.

## Bidragsgivare och utvecklare

”Kistn API Client” är programvara med öppen källkod. Följande personer har bidragit
till detta tillägg.

Bidragande personer

 *   [ Christian Doebler ](https://profiles.wordpress.org/grissi/)

[Översätt ”Kistn API Client” till ditt språk.](https://translate.wordpress.org/projects/wp-plugins/kistn)

### Intresserad av programutveckling?

[Läs programkoden](https://plugins.trac.wordpress.org/browser/kistn/), kika på [SVN-filförvaret](https://plugins.svn.wordpress.org/kistn/)
eller prenumerera på [utvecklarloggen](https://plugins.trac.wordpress.org/log/kistn/)
via [RSS](https://plugins.trac.wordpress.org/log/kistn/?limit=100&mode=stop_on_copy&format=rss).

## Ändringslogg

#### 1.0.2

 * Fix: The settings page no longer shows ”Configuration incomplete” after saving
   valid settings with the (optional) WPScan API Token left empty — the completeness
   notice now reflects the just-saved state.
 * Fix: Public plugins/themes hosted on wordpress.org are no longer mislabelled 
   as private. Public/private is now determined from wordpress.org directory membership(
   via WP’s own update transient) instead of the presence of a `PluginURI` header
   or a WPScan entry — a public plugin can lack both.
 * Change: The inventory payload now reports confirmed-public slugs in a new `public_packages`
   field so the server can display them with their public registry information.

#### 1.0.1

 * Fix: WPScan requests now pause until the next day (site timezone) after hitting
   the 429 rate limit, instead of retrying every remaining slug in the same run.
 * Change: The Push Interval field is now hidden when Schedule Mode is set to WP-
   CLI only (it doesn’t apply to that mode).
 * Change: Renamed the WP-CLI command from `wp inventory push` to `wp kistn push`.
 * Change: Added an example placeholder to the API Base URL field.
 * Docs: Documented WordPress-plugin-repository installation as the primary install
   method.
 * Change: The server-crontab hint under Settings  Kistn now toggles live when Schedule
   Mode is switched, instead of only appearing after a save.
 * Docs: Documented Composer installation option (`composer require kistn/wp-client`)
   in README.md and readme.txt.

#### 1.0.0

 * Initial release.

## Meta

 *  Version **1.0.2**
 *  Senast uppdaterat **1 månad sedan**
 *  Aktiva installationer **Färre än 10**
 *  WordPress-version ** 6.0 eller senare **
 *  Testat upp till **7.0.4**
 *  PHP-version ** 8.3 eller senare **
 *  Språk
 * [English (US)](https://wordpress.org/plugins/kistn/)
 * Etiketter
 * [inventory](https://sv.wordpress.org/plugins/tags/inventory/)[monitoring](https://sv.wordpress.org/plugins/tags/monitoring/)
   [security](https://sv.wordpress.org/plugins/tags/security/)[vulnerability](https://sv.wordpress.org/plugins/tags/vulnerability/)
 *  [Avancerad vy](https://sv.wordpress.org/plugins/kistn/advanced/)

## Betyg

Än så länge har inga recensioner skickats in.

[Your review](https://wordpress.org/support/plugin/kistn/reviews/#new-post)

[Visa alla recensioner](https://wordpress.org/support/plugin/kistn/reviews/)

## Bidragande personer

 *   [ Christian Doebler ](https://profiles.wordpress.org/grissi/)

## Support

Har du något att säga? Behöver du hjälp?

 [Visa supportforum](https://wordpress.org/support/plugin/kistn/)