Title: TugraCyber
Author: skromets
Published: <strong>miz Here 1, 2026</strong>
Last modified: miz Here 1, 2026

---

Search plugins

![](https://ps.w.org/tugracyber/assets/banner-772x250.png?rev=3722655)

![](https://ps.w.org/tugracyber/assets/icon-256x256.png?rev=3722655)

# TugraCyber

 By [skromets](https://profiles.wordpress.org/skromets/)

[Download](https://downloads.wordpress.org/plugin/tugracyber.0.1.0.zip)

 * [Details](https://bre.wordpress.org/plugins/tugracyber/#description)
 * [Reviews](https://bre.wordpress.org/plugins/tugracyber/#reviews)
 *  [Installation](https://bre.wordpress.org/plugins/tugracyber/#installation)
 * [Development](https://bre.wordpress.org/plugins/tugracyber/#developers)

 [Support](https://wordpress.org/support/plugin/tugracyber/)

## Description

TugraCyber keeps an inventory of every script running on your checkout page and 
alerts you when a script’s content changes silently, which is the signature of Magecart-
style card skimming attacks.

 * **Runs only on the checkout page.** This is exactly the scope of PCI DSS 4.0.1
   requirements 6.4.3 and 11.6.1.
 * **Script inventory.** A SHA-256 hash of each script’s content is recorded, so
   silent changes are caught immediately.
 * **Removed and returning script detection.** You get an alert when a known script
   disappears from the page, or reappears after being marked as removed.
 * **PCI DSS 6.4.3/11.6.1 report.** Available from the dashboard in your TugraCyber
   account.

This plugin only adds the monitoring agent to your checkout page. The dashboard,
alerts and reports live in your [TugraCyber](https://tugracyber.com) account. Setup
requires an account and a collector address.

#### Requirements

 * WooCommerce must be active (monitoring runs only on the WooCommerce checkout 
   page).
 * A TugraCyber account and a collector address.

### External Services

Through the monitoring script (agent) it places on your checkout page, this plugin
sends data to the **Collector Endpoint** address you enter on the settings page.
This address is empty by default: the plugin can be installed, but no data is sent
anywhere until you enter an address.

For each script loaded on the checkout page, the data sent is:

 * the script’s URL (src),
 * the SHA-256 hash of the script’s content (not the content itself; the hash is
   an irreversible digest),
 * the script type (inline or external) and your site ID.

Page content, customer data, payment information and card numbers are **never** 
collected or sent.

If you enter the TugraCyber hosted service at https://tugracyber.com as the Collector
Endpoint, data is sent to that service and the following apply:

 * Terms of Service: https://tugracyber.com/terms
 * Privacy Policy: https://tugracyber.com/privacy

Alternatively, you can enter the address of a TugraCyber collector instance running
on your own server. In that case data goes only to a server under your control and
nothing is sent to any third party.

## Installation

 1. Upload and activate the plugin.
 2. Go to Settings > TugraCyber.
 3. Enter the collector endpoint of your TugraCyber account and save.
 4. Visit your checkout page once. The first script inventory is sent automatically.

## FAQ

### Which pages does this plugin run on?

Only the WooCommerce checkout page. It does nothing on other pages.

### I don’t have a TugraCyber account. Can I still install it?

Yes, but monitoring does not start until a collector address is entered.

### What data does the plugin send?

Only the URL and SHA-256 content hash of the scripts on the checkout page. See the“
External Services” section above. Page content and customer or payment data are 
never sent.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“TugraCyber” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ skromets ](https://profiles.wordpress.org/skromets/)

[Translate “TugraCyber” into your language.](https://translate.wordpress.org/projects/wp-plugins/tugracyber)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/tugracyber/), check
out the [SVN repository](https://plugins.svn.wordpress.org/tugracyber/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/tugracyber/) by 
[RSS](https://plugins.trac.wordpress.org/log/tugracyber/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.1.0

 * Initial release: agent injection on the checkout page, settings page, automatic
   site ID and write key generation.

## Meta

 *  Version **0.1.0**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.8 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.2 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/tugracyber/)
 * Tags
 * [checkout](https://bre.wordpress.org/plugins/tags/checkout/)[magecart](https://bre.wordpress.org/plugins/tags/magecart/)
   [pci-dss](https://bre.wordpress.org/plugins/tags/pci-dss/)[security](https://bre.wordpress.org/plugins/tags/security/)
   [woocommerce](https://bre.wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://bre.wordpress.org/plugins/tugracyber/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/tugracyber/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/tugracyber/reviews/)

## Contributors

 *   [ skromets ](https://profiles.wordpress.org/skromets/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/tugracyber/)