RUNTIME · WORDPRESS

The WordPress Runtime.

A small plugin that enrols a site, reports what the application is, and tells the console what changed. It observes and reports; the console is where the work happens.

INSTALLATION · ENROLMENT

Install the plugin, enrol the site, done.

Enrolment takes a one-time token from the console operator. The Runtime identifies itself, sends its first heartbeat and reconciles inventory. From then on it reports on its own schedule.

ENROLMENT · FOUR STEPS

  1. Install plugin ruddiment-runtime.zipUpload the Runtime package in WordPress admin.
  2. Activate Plugins → ActivateThe Runtime generates its own signing identity on activation.
  3. Enrol with token Ruddiment → Enrol this sitePaste the one-time enrolment token issued by the console operator. It is used once and never stored.
  4. First heartbeat then inventory reconciliationThe Runtime reports on its own schedule from here on.
Enrolment has four steps; the site says so.

WHAT IT OBSERVES

Environment, components, changes, identities, heartbeat.

  • Environment — WordPress, PHP, host
  • Components — core, plugins, themes, must-use plugins, versions
  • Changes — component, version and environment changes between reconciliations
  • Privileged identities — administrators and capability changes
  • Heartbeat · inventory reconciliation · connection state
Ruddiment Runtime for WordPress admin page showing Connected, last heartbeat, last inventory reconciliation, runtime version, findings and contextual vulnerabilities, with an Open Ruddiment action.
Runtime for WordPress admin page over fixture data.

LIGHTWEIGHT OPERATION

Designed to observe, not to interfere.

The Runtime reads state and reports it. It does not proxy traffic and it does not change the site. If the control plane cannot be reached, observation continues locally and nothing is lost.

Performance figures will be published from measurement, not estimated. None are claimed in the Developer Preview.

SECURITY MODEL

Identified, signed, minimal.

Each Runtime holds its own cryptographic identity, signs its telemetry to the control plane, and minimises data by default — the console receives what it needs to assess the application, not the application's content.

See the Security route for the full architecture description.

Security →

SUPPORTED VERSIONS

Developer Preview targets current WordPress.

Supported WordPress and PHP versions are confirmed per release from the compatibility matrix that runs in CI: WordPress 6.5.10, 6.7.7 and 7.0.1 on PHP 8.1 to 8.4.

The matrix is the source of truth; this line changes only when it does.

OPEN IN RUDDIMENT

One click from the plugin to the application in the console.

The plugin page shows connection, last heartbeat, last reconciliation, findings and contextual vulnerabilities — and one primary action: Open Ruddiment.

Ruddiment console: Application Security Overview for app.example.com showing a high contextual risk card with evidence checklist, runtime, inventory, privileged identities, findings, vulnerabilities and activity.
The console as it is in development. Fixture data — RFC 2606 example domains, no customer data.

DEVELOPER PREVIEW · WORDPRESS FIRST RUNTIME

See what your application is actually doing.

Ruddiment is being built with a small number of design partners. You will see the product as it is — no counters, no claims.

Early-access requests open with the first design partners. Until an intake route exists, this page does not pretend to have one.